Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
September 3, 2026
Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
September 3, 2026
Critical Cisco Nexus 9000 Switches Flaw Lets Remote Attackers Run Code
September 3, 2026
Home/Threats/Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
Threats

Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users

Key Takeaways A Chinese-speaking cybercrime group, “Gambling Goblin,” has compromised numerous Brazilian government and education websites since mid-2025. The attackers are using...

Jennifer sherman
Jennifer sherman
September 3, 2026 5 Min Read
3 0

Key Takeaways

  • A Chinese-speaking cybercrime group, “Gambling Goblin,” has compromised numerous Brazilian government and education websites since mid-2025.
  • The attackers are using malicious Apache modules to host stealthy phishing pages on trusted domains, making fraudulent content appear legitimate.
  • The campaign aims to promote illegal gambling sites disguised as legitimate app download services, leveraging the high trust associated with official government and education domains.
  • The threat actor employs a sophisticated Linux toolkit, including a custom Apache module, a scanning agent (cam-agent), and various backdoors (ChUser, AlphaAgent, oRAT) for reconnaissance, persistence, and credential theft.
  • The operation shows signs of potential expansion, with similar phishing templates identified in Vietnamese, Spanish, and English.

Brazilian government and educational institutions have been targeted by a sophisticated phishing operation, where trusted public sector websites are secretly converted into platforms for fraudulent content. Instead of redirecting victims to suspicious, unfamiliar sites, the attackers leverage compromised web servers to embed deceptive material directly onto legitimate domains, thereby enhancing the credibility of their scams.

Table Of Content

  • Key Takeaways
  • Malicious Apache Modules
  • A Toolkit Built for Reach and Evasion
  • What You Should Do

This ongoing campaign, active since mid-2025, involves the deployment of a specialized Linux toolkit by the attackers once they gain unauthorized access to the web servers. The hijacked sites are then utilized to promote illicit gambling platforms, cleverly disguised as reputable application download services.

Researchers at Check Point have attributed this activity to a Chinese-speaking cybercrime group dubbed “Gambling Goblin,” which they assess with medium-to-high confidence to be linked with the broader threat actor known as Earth Berberoka. This discovery signifies a notable shift in Brazil’s cybersecurity landscape, traditionally dominated by domestic banking trojans, towards exploitation by foreign entities capitalizing on public trust, as Check Point said in a report.

By exploiting trusted government and education domains, the attackers can manipulate search engine rankings, directing unsuspecting users to fake online stores and making their fraudulent schemes appear official and safe. The investigation also revealed similar phishing templates in multiple languages, including Vietnamese, Spanish, and English, suggesting an intent to scale the operation beyond Brazil.

Malicious Apache Modules

A core component of the attackers’ arsenal is a custom Apache module, which is compiled directly on compromised servers. A Bash installer script automates this process by first identifying the operating system, then installing necessary Apache development packages, retrieving the C source code, and finally building and activating the malicious module using Apache’s native tools.

To evade detection, the installer script meticulously removes all source code and build files post-deployment. Furthermore, it alters the timestamps of the malicious shared object and configuration files to mimic those of legitimate Apache components, making it more challenging for quick server audits to uncover the intrusion.

One of these modules is designed to monitor specific request paths, stealthily proxying them to the attacker’s infrastructure. This allows visitors to remain on a seemingly genuine government domain while unknowingly interacting with remotely hosted phishing content. Crucially, this module also strips away browser content-security restrictions, enabling the successful loading of injected scripts and external assets.

A second Apache module provides advanced control, capable of analyzing various client attributes such as the request path, referrer, browser details, and IP address to dynamically decide which content to serve. This module can insert remote content into web responses, facilitating selective cloaking and sophisticated search engine manipulation. Such misuse of official domains mirrors tactics seen in other government website phishing campaigns, where the inherent reputation of official domains is exploited to lend an air of legitimacy to criminal content.

The phishing pages deployed in this campaign are designed to mimic popular download platforms like Google Play, Microsoft Store, and Amazon. They feature fabricated ratings and deceptive page data to appear convincing. However, their true purpose is to promote gambling, indicating a financial motive behind the operation.

A Toolkit Built for Reach and Evasion

While the initial compromise method remains unconfirmed, researchers identified a scanning agent named “cam-agent” on compromised infrastructure. This agent uses reconnaissance tools to map internet-facing systems, likely to pinpoint high-value web properties suitable for exploitation and abuse.

Once inside a network, the group utilizes “DownPro” to retrieve additional malicious payloads. These include the “ChUser” backdoor, a tool for harvesting passwords, “AlphaAgent,” “oRAT,” and a utility designed for testing SSH credentials. Several of these tools employ advanced evasion techniques such as obfuscation, encryption, and memory-only unpacking, tactics reminiscent of sophisticated Linux RAT attacks targeting developers.

AlphaAgent offers extensive capabilities, including command execution, file manipulation, tunnel creation, and the collection of SSH keys and shell history. It also attempts to conceal its presence by masquerading as legitimate system services. Similarly, oRAT achieves persistence by establishing itself as a service that mimics a firewall component. These functionalities collectively enable credential theft, lateral movement within compromised networks, and sustained unauthorized access. The attackers’ infrastructure also generates new domains daily to circumvent blacklisting efforts.

The report links the toolkit, the presence of Chinese-language artifacts, the focus on gambling, and the use of lookalike domains to the Earth Berberoka group. This pattern of activity can be compared with other instances of Brazilian government malware delivery and AI-driven phishing site cloning.

What You Should Do

  • Patch Exposed Services: Urgently apply all available security patches to web servers and associated services, especially Apache HTTP Server.
  • Review Apache Modules and Configurations: Conduct thorough audits of all loaded Apache modules and configuration files for any unauthorized or suspicious changes.
  • Audit SSH Access: Regularly review SSH access logs for unusual login attempts, weak credentials, or newly added keys. Implement strong, unique passwords and multi-factor authentication (MFA) for all SSH access.
  • Investigate Suspicious Files: Look for unfamiliar libraries, altered file timestamps, new proxy rules, and processes disguised as legitimate system components.
  • Baseline and Monitor: Establish a baseline of approved Apache modules and reverse-proxy rules. Continuously monitor for any deviations from this baseline.
  • Preserve Logs: Before any cleanup or remediation, ensure all relevant logs are preserved for forensic analysis.
  • Reset Credentials: Immediately reset all exposed credentials and enforce a mandatory password change across the affected environment.
  • Inspect Adjacent Systems: Conduct a comprehensive inspection of all systems within the network for signs of lateral movement or the presence of related malicious tools.
  • Rethink Trust: Recognize that a trusted domain does not automatically guarantee a page’s safety. Implement robust monitoring and security checks for all public-facing servers.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 Malware sample hash
SHA-256 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 Malware sample hash
SHA-256 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 Malware sample hash
SHA-256 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb Malware sample hash
SHA-256 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 Malware sample hash
SHA-256 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d Malware sample hash
SHA-256 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 Malware sample hash
SHA-256 e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 Malware sample hash
SHA-256 fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d Malware sample hash
SHA-256 c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f Malware sample hash
SHA-256 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 Malware sample hash
SHA-256 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a Malware sample hash
SHA-256 f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf Malware sample hash
SHA-256 5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8 Malware sample hash
SHA-256 0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7 Malware sample hash
SHA-256 5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710 Malware sample hash
SHA-256 c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchphishingSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Cisco Nexus 9000 Switches Flaw Lets Remote Attackers Run Code

Next Post

Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic Claude AI Can Control macOS and Windows Systems
September 3, 2026
WhatsApp Android Flaw Lets Attackers Bypass Lock Screen During Video Calls
September 2, 2026
Firefox for iOS Adds Native Ad and Tracker Blocking
September 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us