Actor Profile
Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educational institution web servers. Check Point assesses Gambling Goblin is linked to Earth Berberoka, a threat actor documented by Trend Micro in 2022 targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals. The actor's primary motivation is financial gain through traffic redirection to attacker-controlled online gambling and sports betting pages, exploiting Brazil's newly licensed fixed-odds betting market that began January 1, 2025.
TTPs (Tactics, Techniques, Procedures)
The group installs malicious Apache modules on compromised web servers to reverse-proxy visitors to phishing pages while preserving the appearance of legitimate domain traffic. Security headers are stripped to allow injected content execution. The actor deploys a custom toolset including DownPro (custom downloader), AlphaAgent (modular backdoor), oRAT (remote access trojan), a 3snake-based credential stealer that uses ptrace to extract credentials from sshd and sudo processes on rooted servers, an SSH brute-forcer, and a plugin-driven reconnaissance agent written in Go. The phishing pages masquerade as trusted app stores (Google Play, Microsoft Store, Amazon) to promote gambling sites. The campaign employs cloaking techniques, serving keyword-stuffed content to Googlebot while redirecting human visitors to betting sites. Infrastructure generates new domains daily across multiple languages (Vietnamese, Spanish, English). Hunt.io identified over 630,000 URLs on hijacked gov.br subdomains. The reverse-proxy technique mirrors GhostRedirector's Gamshen IIS module documented by ESET in June 2025.
Targets & Patterns
Primary targets are Brazilian government (.gov.br and .jus.br) and educational institution web servers. At least 20 .gov.br portals belonging to Brazilian municipalities and police forces were compromised. The actor specifically targets high-reputation domains to manipulate search engine rankings and leverage trusted infrastructure for traffic distribution. The timing aligns with Brazil's legalization of fixed-odds betting under Law 14,790/2023, creating a lucrative market for illicit gambling promotion. Compromised government systems serve as delivery chain infrastructure rather than end targets. The pattern extends beyond Brazil, with ESET documenting at least 65 compromised Windows servers mainly in Brazil, Thailand, and Vietnam in related GhostRedirector activity. The choice of government and educational targets provides both high domain authority for SEO manipulation and trusted appearance to victims.
Historical Context
Gambling Goblin is assessed by Check Point as linked to Earth Berberoka, documented by Trend Micro in 2022 targeting gambling websites across Asia. oRAT, deployed in this campaign, was documented by Trend Micro in April 2022 as Earth Berberoka malware in Windows and macOS samples (version 0.5.1). Xnote, a Linux backdoor tied to the group, was reported in March 2025 during attacks on critical infrastructure in Asia. The campaign shows tactical overlap with GhostRedirector, a China-aligned actor documented by ESET in June 2025 that compromised at least 65 Windows servers using the Gamshen IIS module for SEO fraud targeting gambling promotion. Palo Alto Networks Unit 42 documented similar reverse-proxy techniques on IIS servers in September 2025. Hunt.io reported in July 2025 finding over 630,000 URLs on hijacked gov.br subdomains. ANY.RUN has tracked related activity as the PhantomEnigma campaign since at least July 2025. The consistent focus on gambling-related SEO manipulation and infrastructure in Brazil, Thailand, and Vietnam suggests sustained Chinese-speaking cybercrime operations targeting the online gambling ecosystem.
Defensive Recommendations
- Audit all loaded Apache and IIS modules for unauthorized additions; verify module filenames, paths, and hashes against known-good baselines and remove any unrecognized native web server modules
- Monitor for credential theft via ptrace attachment to sshd and sudo processes on Linux servers, particularly those with root access; implement process monitoring to detect unauthorized ptrace system calls
- Implement differential response monitoring to detect cloaking: compare server responses to Googlebot user-agents versus standard browsers to identify SEO manipulation attempts
- Block SSH brute-force attempts through rate limiting, enforce key-based authentication over password authentication, and monitor for unusual SSH login patterns from Chinese IP ranges
- Deploy web application firewalls (WAF) to detect reverse-proxy behavior and stripped security headers; alert on responses missing expected Content-Security-Policy, X-Frame-Options, and other protective headers
- Coordinate with Brazil's CTIR before blocking compromised .gov.br and .jus.br domains to avoid disrupting legitimate government services; implement selective URL-level blocking rather than domain-wide blocks
---
# Geopolitical Context
Geopolitical Context
A Chinese-speaking cybercrime cluster designated Gambling Goblin has compromised web servers belonging to Brazilian government agencies and educational institutions since mid-2025, installing malicious Apache modules to redirect traffic toward gambling and sports betting pages. The campaign exploits Brazil's newly regulated betting market, which began licensing fixed-odds operations in January 2025 under Law 14,790/2023. Check Point Research assesses the primary objective as search engine optimization (SEO) manipulation at scale, leveraging the high domain reputation of .gov.br and .edu.br hosts to inflate search rankings for illicit gambling platforms. The operation mirrors tactics documented by ESET in June 2025 under the GhostRedirector cluster, which targeted IIS servers in Brazil, Thailand, and Vietnam using similar reverse-proxy techniques. Check Point links Gambling Goblin to Earth Berberoka, a threat actor Trend Micro associated in 2022 with attacks on gambling websites across Asia using malware families historically attributed to Chinese-speaking developers. The campaign's toolset—including the AlphaAgent backdoor, oRAT remote access trojan, and a 3snake-based credential stealer—indicates a persistent-access posture that extends beyond SEO fraud, positioning the operators to deploy additional payloads. Hunt.io reported in July 2025 that over 630,000 URLs had been generated on hijacked .gov.br subdomains, serving keyword-stuffed content to Googlebot while redirecting human visitors to betting sites. Brazil's CTIR has been coordinating remediation, though the published research does not confirm whether compromised servers have been cleaned or how many remain affected.
State Actor Alignment
Gambling Goblin is assessed as a financially motivated cybercrime cluster rather than a state-sponsored actor. Check Point and Trend Micro attribute the group's tooling and operational patterns to Chinese-speaking individuals, consistent with malware families and infrastructure historically linked to cybercriminal ecosystems in China. ESET assessed with medium confidence that the related GhostRedirector cluster is China-aligned, though the basis for that alignment—whether linguistic, infrastructural, or operational—remains unspecified in open reporting. No evidence has been published linking Gambling Goblin or Earth Berberoka to Chinese state intelligence or military units. The campaign's focus on financial gain through SEO fraud and gambling promotion, rather than espionage or strategic disruption, supports a criminal rather than state-directed assessment. Brazil's government incident response team (CTIR) has coordinated with private-sector researchers to mitigate the compromise of .gov.br domains, and Hunt.io redacted certain indicators at CTIR's request while investigations continued. No public statement from Brazilian or Chinese government authorities regarding attribution or diplomatic response has been reported.
Business Impacty pro region
The compromise of Brazilian government and educational web infrastructure highlights systemic vulnerabilities in public-sector digital hygiene across Latin America, where legacy web servers and limited cybersecurity budgets create attractive targets for financially motivated actors. The campaign's timing coincides with Brazil's formalization of its online betting market in January 2025, creating a lucrative environment for illicit operators to exploit regulatory gaps and consumer demand. The use of high-reputation .gov.br and .jus.br domains for SEO manipulation complicates defensive responses, as broad blocking would disrupt access to legitimate government services—a challenge ANY.RUN flagged in July 2025. The parallel identification of Vietnamese, Spanish, and English phishing networks suggests Gambling Goblin operates a multilingual, geographically distributed infrastructure capable of targeting multiple regions simultaneously. ESET's June 2025 findings that compromised servers spanned Brazil, Thailand, and Vietnam indicate the group prioritizes emerging markets with expanding online gambling sectors and weaker cybersecurity postures. For Europe, the campaign underscores risks associated with cross-border SEO fraud and domain reputation abuse, particularly as EU member states enforce stricter gambling regulations under national and Digital Services Act frameworks. The reverse-proxy technique—serving legitimate content to ordinary visitors while manipulating search engine crawlers—complicates detection and may inform adversary tactics in other regions. The deployment of credential-stealing tools and persistent backdoors on government infrastructure also raises concerns about secondary exploitation, including data exfiltration or use of compromised hosts as staging points for further intrusions.
Forecast
If Brazilian authorities and affected institutions do not systematically audit Apache and IIS server configurations for unauthorized modules, Gambling Goblin is likely to sustain access to compromised infrastructure and continue SEO manipulation campaigns. The group's deployment of credential stealers and modular backdoors suggests that, if financial incentives shift or if the operators diversify revenue streams, compromised government servers could be repurposed for malware distribution, data theft, or ransomware deployment—a risk Check Point noted the group is "one step from" realizing. If Brazil's regulatory enforcement against unlicensed .bet.br operators remains weak, demand for illicit SEO services is likely to persist, sustaining the economic model underpinning Gambling Goblin's operations. Should CTIR and Registro.br implement automated monitoring for anomalous subdomain generation and Googlebot-specific responses, detection of similar campaigns may improve, though remediation will depend on the capacity of municipal and state-level IT teams. If Chinese-speaking cybercrime clusters continue to target emerging online gambling markets in Southeast Asia and Latin America, parallel campaigns exploiting government domain reputation are likely to emerge in Thailand, Vietnam, the Philippines, and other jurisdictions with recent betting legalization. For defenders in Europe and North America, the campaign's reverse-proxy and SEO fraud techniques may inform threat models for protecting high-reputation domains, particularly in public-sector and academic networks where legacy infrastructure and limited security resources create similar exposure.
