Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
Key Takeaways A Chinese-speaking cybercrime group, “Gambling Goblin,” has compromised numerous Brazilian government and education websites since mid-2025. The attackers are using...
Key Takeaways
- A Chinese-speaking cybercrime group, “Gambling Goblin,” has compromised numerous Brazilian government and education websites since mid-2025.
- The attackers are using malicious Apache modules to host stealthy phishing pages on trusted domains, making fraudulent content appear legitimate.
- The campaign aims to promote illegal gambling sites disguised as legitimate app download services, leveraging the high trust associated with official government and education domains.
- The threat actor employs a sophisticated Linux toolkit, including a custom Apache module, a scanning agent (cam-agent), and various backdoors (ChUser, AlphaAgent, oRAT) for reconnaissance, persistence, and credential theft.
- The operation shows signs of potential expansion, with similar phishing templates identified in Vietnamese, Spanish, and English.
Brazilian government and educational institutions have been targeted by a sophisticated phishing operation, where trusted public sector websites are secretly converted into platforms for fraudulent content. Instead of redirecting victims to suspicious, unfamiliar sites, the attackers leverage compromised web servers to embed deceptive material directly onto legitimate domains, thereby enhancing the credibility of their scams.
Table Of Content
This ongoing campaign, active since mid-2025, involves the deployment of a specialized Linux toolkit by the attackers once they gain unauthorized access to the web servers. The hijacked sites are then utilized to promote illicit gambling platforms, cleverly disguised as reputable application download services.
Researchers at Check Point have attributed this activity to a Chinese-speaking cybercrime group dubbed “Gambling Goblin,” which they assess with medium-to-high confidence to be linked with the broader threat actor known as Earth Berberoka. This discovery signifies a notable shift in Brazil’s cybersecurity landscape, traditionally dominated by domestic banking trojans, towards exploitation by foreign entities capitalizing on public trust, as Check Point said in a report.
By exploiting trusted government and education domains, the attackers can manipulate search engine rankings, directing unsuspecting users to fake online stores and making their fraudulent schemes appear official and safe. The investigation also revealed similar phishing templates in multiple languages, including Vietnamese, Spanish, and English, suggesting an intent to scale the operation beyond Brazil.
Malicious Apache Modules
A core component of the attackers’ arsenal is a custom Apache module, which is compiled directly on compromised servers. A Bash installer script automates this process by first identifying the operating system, then installing necessary Apache development packages, retrieving the C source code, and finally building and activating the malicious module using Apache’s native tools.
To evade detection, the installer script meticulously removes all source code and build files post-deployment. Furthermore, it alters the timestamps of the malicious shared object and configuration files to mimic those of legitimate Apache components, making it more challenging for quick server audits to uncover the intrusion.
One of these modules is designed to monitor specific request paths, stealthily proxying them to the attacker’s infrastructure. This allows visitors to remain on a seemingly genuine government domain while unknowingly interacting with remotely hosted phishing content. Crucially, this module also strips away browser content-security restrictions, enabling the successful loading of injected scripts and external assets.
A second Apache module provides advanced control, capable of analyzing various client attributes such as the request path, referrer, browser details, and IP address to dynamically decide which content to serve. This module can insert remote content into web responses, facilitating selective cloaking and sophisticated search engine manipulation. Such misuse of official domains mirrors tactics seen in other government website phishing campaigns, where the inherent reputation of official domains is exploited to lend an air of legitimacy to criminal content.
The phishing pages deployed in this campaign are designed to mimic popular download platforms like Google Play, Microsoft Store, and Amazon. They feature fabricated ratings and deceptive page data to appear convincing. However, their true purpose is to promote gambling, indicating a financial motive behind the operation.
A Toolkit Built for Reach and Evasion
While the initial compromise method remains unconfirmed, researchers identified a scanning agent named “cam-agent” on compromised infrastructure. This agent uses reconnaissance tools to map internet-facing systems, likely to pinpoint high-value web properties suitable for exploitation and abuse.
Once inside a network, the group utilizes “DownPro” to retrieve additional malicious payloads. These include the “ChUser” backdoor, a tool for harvesting passwords, “AlphaAgent,” “oRAT,” and a utility designed for testing SSH credentials. Several of these tools employ advanced evasion techniques such as obfuscation, encryption, and memory-only unpacking, tactics reminiscent of sophisticated Linux RAT attacks targeting developers.
AlphaAgent offers extensive capabilities, including command execution, file manipulation, tunnel creation, and the collection of SSH keys and shell history. It also attempts to conceal its presence by masquerading as legitimate system services. Similarly, oRAT achieves persistence by establishing itself as a service that mimics a firewall component. These functionalities collectively enable credential theft, lateral movement within compromised networks, and sustained unauthorized access. The attackers’ infrastructure also generates new domains daily to circumvent blacklisting efforts.
The report links the toolkit, the presence of Chinese-language artifacts, the focus on gambling, and the use of lookalike domains to the Earth Berberoka group. This pattern of activity can be compared with other instances of Brazilian government malware delivery and AI-driven phishing site cloning.
What You Should Do
- Patch Exposed Services: Urgently apply all available security patches to web servers and associated services, especially Apache HTTP Server.
- Review Apache Modules and Configurations: Conduct thorough audits of all loaded Apache modules and configuration files for any unauthorized or suspicious changes.
- Audit SSH Access: Regularly review SSH access logs for unusual login attempts, weak credentials, or newly added keys. Implement strong, unique passwords and multi-factor authentication (MFA) for all SSH access.
- Investigate Suspicious Files: Look for unfamiliar libraries, altered file timestamps, new proxy rules, and processes disguised as legitimate system components.
- Baseline and Monitor: Establish a baseline of approved Apache modules and reverse-proxy rules. Continuously monitor for any deviations from this baseline.
- Preserve Logs: Before any cleanup or remediation, ensure all relevant logs are preserved for forensic analysis.
- Reset Credentials: Immediately reset all exposed credentials and enforce a mandatory password change across the affected environment.
- Inspect Adjacent Systems: Conduct a comprehensive inspection of all systems within the network for signs of lateral movement or the presence of related malicious tools.
- Rethink Trust: Recognize that a trusted domain does not automatically guarantee a page’s safety. Implement robust monitoring and security checks for all public-facing servers.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 |
Malware sample hash |
| SHA-256 | 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 |
Malware sample hash |
| SHA-256 | 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 |
Malware sample hash |
| SHA-256 | 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb |
Malware sample hash |
| SHA-256 | 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 |
Malware sample hash |
| SHA-256 | 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d |
Malware sample hash |
| SHA-256 | 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 |
Malware sample hash |
| SHA-256 | e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 |
Malware sample hash |
| SHA-256 | fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d |
Malware sample hash |
| SHA-256 | c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f |
Malware sample hash |
| SHA-256 | 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 |
Malware sample hash |
| SHA-256 | 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a |
Malware sample hash |
| SHA-256 | f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf |
Malware sample hash |
| SHA-256 | 5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8 |
Malware sample hash |
| SHA-256 | 0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7 |
Malware sample hash |
| SHA-256 | 5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710 |
Malware sample hash |
| SHA-256 | c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d
|



No Comment! Be the first one.