Chinese-speaking cybercrime group targets Brazilian government sites for SEO manipulation and phishing.

Published:

Research by: Amit Yardeni

A New Threat Landscape: Gambling Goblin Targets Brazil

In a significant shift in the cyber threat landscape, Check Point Research has identified a Chinese-speaking cybercrime group, dubbed Gambling Goblin, that has been actively targeting Brazilian organizations since mid-2025. This group is linked to Earth Berberoka, a previously documented actor known for its attacks on gambling sites across Asia. The emergence of Gambling Goblin marks a departure from Brazil’s typical home-grown banking trojan threats, indicating a new wave of foreign cybercriminal activity in the region. The full details of this operation can be explored further in the research published by Check Point.

Technical Insights into the Operation

The attackers have employed a sophisticated approach, compromising web servers and transforming them into stealthy proxies. By installing malicious Apache modules, they redirect legitimate traffic to phishing pages that masquerade as trusted app stores, including Google Play and the Microsoft Store. This tactic not only facilitates large-scale SEO manipulation but also allows the group to hijack traffic from high-reputation domains, many of which belong to Brazilian government sites.

Once inside a victim’s network, the group deploys a broad and heavily obfuscated Linux toolkit. This includes a custom downloader known as DownPro, multiple backdoors such as AlphaAgent and oRAT, and various reconnaissance tools. The obfuscation techniques employed are designed to slow down analysis and evade detection, making it challenging for security teams to respond effectively.

The Scale of the Operation

The operation’s reach extends beyond Brazil, with parallel phishing networks identified in Vietnamese, Spanish, and English. This suggests that the model is not only scalable but also adaptable to different regions. The infrastructure is capable of generating fresh domains daily, allowing the group to maintain a persistent presence and evade detection by security measures.

One of the most alarming aspects of this operation is its potential for escalation. The phishing pages already mimic legitimate app-download destinations, meaning that with a single configuration change, the same infrastructure could be used to deliver malware directly to victims. This latent risk highlights the need for heightened vigilance among organizations, particularly those in the public sector.

Conclusion: A Call to Action

The emergence of Gambling Goblin underscores a critical evolution in the cyber threat landscape, particularly in Brazil, which has become a lucrative target for cybercriminals due to its rapidly growing online betting market. The combination of a vast mobile user base and a plethora of under-secured web servers creates an ideal environment for such operations. As this group continues to exploit trusted infrastructure, it is imperative for organizations to bolster their defenses by patching exposed services, auditing configurations, and actively monitoring for rogue modules and processes.

Failure to address these vulnerabilities could result in further exploitation, not only of individual users but also of government institutions that lend credibility to these malicious operations. The time for action is now, as the line between cybercrime and advanced persistent threats continues to blur.

Read more about this research by Check Point.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

16 malicious Firefox extensions impersonate Rabby and OKX wallets to steal cryptocurrency recovery phrases

Cybersecurity researchers have identified 16 malicious Mozilla Firefox extensions designed to impersonate popular cryptocurrency wallets, specifically Rabby and OKX, with the intent to steal...

US withdrawal of B-1 bombers from RAF Fairford highlights need for enhanced base defenses against drone threats

In a significant operational shift, the United States has withdrawn a dozen B-1 Lancer bombers from RAF Fairford in southern England, a move prompted...

Web3 command-and-control evolution enhances cloud supply chain attack strategies, reveals Unit 42 analysis

Recent analysis by Unit 42 reveals a significant evolution in the command-and-control (C2) strategies employed by threat actors, particularly in the context of cloud...

Cybersecurity leaders in the UAE urged to secure machine identities amid cloud expansion

As the adoption of cloud services and automation accelerates in the UAE, cybersecurity leaders are increasingly urged to focus on securing machine identities. Justin...