Check Point Research reported that the Chinese-speaking Gambling Goblin cybercrime cluster has compromised Brazilian government, educational, and commercial Linux web servers since mid-2025. The operators install malicious Apache modules that covertly reverse-proxy traffic from trusted victim domains to fake Google Play, Microsoft Store, and Amazon-branded gambling and betting pages, abusing the victims’ reputations to manipulate search-engine rankings at scale.
The group uses an obfuscated Linux toolkit including DownPro, ChUser, PasswordHarvester, AlphaAgent, oRAT, an SSH brute-forcer, and reconnaissance utilities to steal credentials, maintain persistence, move laterally, and remotely administer compromised hosts. Researchers assess with medium-to-high confidence that Gambling Goblin is linked to Earth Berberoka, citing shared oRAT code, Chinese-language artifacts, gambling-focused operations, lookalike-domain techniques, and overlapping Amazon-hosted infrastructure; associated systems also host Vietnamese, Spanish, and English phishing content and generate domains daily, creating capacity to expand internationally or distribute malware.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A Chinese-speaking cybercrime cluster tracked as Gambling Goblin began compromising internet-facing Linux web servers at Brazilian government, educational, and commercial organizations for gambling-focused SEO fraud and phishing. The operators used malicious Apache modules to reverse-proxy victim-domain traffic to fake Google Play, Microsoft Store, and Amazon-themed betting pages.
ESET assessed that the previously unknown, China-aligned GhostRedirector actor had been active since at least August 2024, compromising Windows servers primarily in Brazil, Thailand, and Vietnam. The group deployed the Rungan backdoor and Gamshen IIS module to manipulate Googlebot-facing responses and promote gambling sites through SEO fraud.
Gurucul published named attacker-controlled domains, SHA-256 hashes, and detection queries associated with Gambling Goblin activity to support threat hunting. The report also characterized the campaign as high severity.
Ctrl-Alt-Intel published a browser-based checker for domains and IPs appearing in preserved evidence from a campaign in which a Chinese actor compromised thousands of WordPress sites. The tool classifies evidence from Targeted through Confirmed and includes web-shell, directory, vulnerable-endpoint, and admin-ajax.php hunting indicators.
Check Point disclosed that Gambling Goblin uses malicious Apache modules that remove security headers while reverse-proxying traffic, alongside DownPro, AlphaAgent, oRAT, a 3snake-derived credential stealer, an SSH brute-forcer, and reconnaissance tooling. The researchers also identified parallel Vietnamese, Spanish, and English phishing networks and infrastructure capable of generating new domains daily.
Check Point Research assessed with medium-to-high confidence that Gambling Goblin is connected to the Chinese-speaking Earth Berberoka cluster. The assessment cited overlaps including oRAT, Chinese-language strings, and infrastructure and domains resembling trusted technology brands.
Hunt.io reported that more than 630,000 URLs on gov.br subdomains were leveraged for black-hat SEO redirect activity. This provides a quantified scale for abuse affecting Brazilian government domains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 126 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
11 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecysecurity.news
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourceresearch.checkpoint.com
Open sourcectrlaltintel.com
Open sourcewelivesecurity.com
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.