Gambling Goblin Brazilian SEO fraud campaign
Campaign
Summary
Hide ▲
Show ▼
Check Point Research says Gambling Goblin is a Chinese-speaking cybercrime cluster running a sustained SEO fraud operation against Brazilian government and educational websites since mid-2025. The group installs malicious Apache modules on compromised web servers, uses them as a reverse proxy, strips Content-Security-Policy headers, and redirects visitors to phishing pages posing as Google Play, Microsoft Store, and Amazon. Those pages promote online gambling and sports betting, with the activity tied by Check Point to Earth Berberoka. The campaign also uses localized phishing pages and churned domains to keep the redirection infrastructure in play.
Related Happenings
BengalSEO SEO poisoning campaign
Campaign
H score12
First: 08.09.2026 11:43
Last: 08.09.2026 11:43
Sources 1
About this happening:
The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Dis...
BengalSEO SEO poisoning campaign
CampaignAbout this happening: The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Dis...
CPR Apache and SSH compromise hunt guidance
Advisory/Mitigation
H score14
First: 02.09.2026 17:00
Last: 02.09.2026 17:00
Sources 1
How related:
CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
About this happening:
CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromise...
CPR Apache and SSH compromise hunt guidance
Advisory/MitigationHow related: CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
About this happening: CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromise...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Brazilian government websites hit by network compromise
Incident
H score28
First: 16.07.2026 14:58
Last: 16.07.2026 14:58
Sources 1
About this happening:
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...
Brazilian government websites hit by network compromise
IncidentAbout this happening: More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Timeline
-
02.09.2026 17:00 3 articles · 13d ago
Check Point Research links Gambling Goblin to Brazilian SEO fraud campaign
Initial DisclosureCheck Point Research linked the Chinese-speaking Gambling Goblin cluster, assessed with medium-to-high confidence as connected to Earth Berberoka, to a sustained SEO fraud operation using compromised Brazilian government and education websites since mid-2025. The operators installed custom Apache modules that acted as a reverse proxy, stripped Content-Security-Policy headers, and redirected selected visitors to phishing pages impersonating Google Play, the Microsoft Store and Amazon.
Show sources
- Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons — www.infosecurity-magazine.com — 02.09.2026 17:00
- Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons — www.infosecurity-magazine.com — 02.09.2026 17:00
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages — thehackernews.com — 02.09.2026 16:44