Toggle light / dark theme

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.

Check Point Research said it has tracked the campaign since mid-2025.

The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site’s own security headers are stripped, allowing the injected content to run freely.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */