Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

0
Medium
Published: 09/02/2026 (09/02/2026, 13:40:05 UTC)
Source: AlienVault OTX General

Description

A Chinese-speaking cybercrime group known as Gambling Goblin has targeted Brazilian government and educational websites since mid-2025 by compromising web servers and installing malicious Apache modules. These modules reverse-proxy visitors to phishing pages impersonating trusted app stores but actually promote online gambling and sports betting. The group manipulates search engine rankings by chaining compromised high-reputation domains, particularly Brazilian government sites, to increase visibility of their phishing content. Their toolkit includes custom Linux malware such as downloaders, backdoors, credential stealers, and reconnaissance tools, heavily obfuscated to evade detection. The campaign also extends beyond Brazil, targeting Vietnamese, Spanish, and English-speaking victims with parallel infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 10:52:15 UTC

Technical Analysis

The Gambling Goblin cybercrime group conducts a sustained campaign against Brazilian government and educational institutions by compromising web servers and deploying malicious Apache modules that silently reverse-proxy visitors to phishing pages promoting gambling and sports betting. This operation leverages SEO manipulation by chaining compromised high-reputation domains to boost phishing page visibility. The attackers use an extensive Linux-based toolkit comprising custom downloaders, backdoors, credential stealers, and reconnaissance tools, employing heavy obfuscation techniques. The campaign infrastructure also targets victims in Vietnam, Spain, and English-speaking regions, indicating a broader geographic scope.

Potential Impact

Compromised government and educational websites serve phishing pages that impersonate trusted app stores, potentially deceiving visitors into engaging with fraudulent gambling and betting services. The manipulation of search engine rankings increases the likelihood of victim exposure. Credential theft and unauthorized access facilitated by the attackers' toolkit can lead to further compromise of affected organizations. The campaign undermines trust in legitimate government domains and poses risks of financial fraud and data theft.

Defensive Guidance

No specific patch or remediation is indicated for this campaign. Organizations should verify the integrity of their web servers and Apache modules to detect unauthorized modifications. Removing malicious modules and restoring legitimate server configurations is essential. Monitoring for unusual reverse-proxy behavior and phishing activity is recommended. Since the campaign uses heavily obfuscated Linux malware, deploying advanced endpoint detection and response tools capable of identifying such threats is advisable. There is no vendor advisory or official fix available; patch status is not yet confirmed—check vendor advisories and threat intelligence sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/"]
Adversary
Gambling Goblin
Pulse Id
6a982735d832e36397a5fad9
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingitlab.bet
domaingithub.wiki
domaindata.windows-update-cdn.com
domaingithub.la
domainkerneltty.com
domainmicrosoft-azure-loadbalance.com
domainplayfootball.info
domain404.443.team
domain80.443.team
domain8yiu.kernel-lib.com
domainapi.gitlab.bet
domainapi.onlinevrgame.com
domainbageyi.kernel-lib.com
domainbr.team-c2.com
domainbr.team-hw.com
domaindata.mirrors-inc.com
domaindevops.aliyuntsl.com
domaindnslog.kernel-lib.com
domainfile.ijjjst23m.com
domainhwlocal.team-hw.com
domainjs.ai-jquery.com
domainrb.aliyuntsl.com
domainup.443.team
domainupdate.aliyun.la
domainupdate.opentls2.com
domainupdate.team-c2.com

Hash

ValueDescriptionCopy
hash0e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133a
hash468e351ba751f0c431e0d14a05fb5714
hash78ef38411156857f4255c14d68abb9ce
hash7ca0c57e583876a52a4d1787320734b1
hash911bd81294fa704fd27ec55d9fc987be
hashb9b32c1354bccde1d0b94dd12c272c98
hashc1350e2a357a1dffa2de3557d0af5a44
hashc6b598aabfcab8c48e981913aeeb4d7e
hashc829548196e0621d4a4e5a7bb2c5127b
hashce77fdfb89848f2542f9761f1532e6b9
hashf36f305ae2a503f9b46ec2c6fc0334a4
hash088eb32b6ce5a1887265445de239b31ec613d1e1
hash1e8c224812a39d2a01ab7c0e98f5763f6c9c852e
hash2e0dcbbaecac8d96de2e2c69d830ee3bc09ce05c
hash8a2d7dd8f50d0ec84870c488728fdafe30135765
hash9cf2ed9f10d0497eea29b69a1e93dfda43cf9f3f
hashc74242abe9a8b79a67c0f11e97bb530387e28c77
hashd2defbaadd731483ea56b3499f997f2bfa6756b6
hashe51b45428e7a26a6db1ad7650bf4d22eb5930d9d
hashec761c824a20f478c2aa81badf4f60165a40bff5
hashf8cddd9c1c1bd063d1665db097ca7fda6621a6ca
hash02f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6
hash0611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03e
hash088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815
hash090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707e
hash0963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013d
hash0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7
hash0f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31e
hash114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0
hash12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d
hash154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40
hash16d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844
hash1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a
hash1eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9c
hash2305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197c
hash232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017
hash24f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12
hash2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91
hash263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31
hash2949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283
hash297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7
hash2de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035
hash3537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820
hash36cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8f
hash3a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdb
hash3ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1
hash44373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459f
hash45b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88
hash52863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611
hash582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9
hash5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8
hash5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611
hash5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710
hash612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4c
hash67ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9b
hash749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52
hash7d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3
hash8495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40c
hash85b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9a
hash88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0
hash8a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1
hash94aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84a
hash96488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148
hash98e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322
hash99b5404df81992cad104dd242bc736d75fd6c58af34dc1a75a8ee3c5e1784fa4
hash9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb
hash9d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fb
hasha71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162
hashab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334e
hashac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248
hashadbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bc
hashb88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877
hashbcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838
hashc3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f
hashc3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882
hashc4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69
hashc59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6
hashcff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109
hashd138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932b
hashd478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4
hashd948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cd
hashe8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052
hashe8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76a
hashf025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf
hashf32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1
hashf4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063
hashfa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3
hashfa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d
hashfc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3

Ip

ValueDescriptionCopy
ip202.146.222.18
ip154.84.62.128
ip154.84.62.145
ip154.84.62.149
ip154.84.62.160
ip192.253.229.23
ip204.16.172.106

Threat ID: 6a9fe8cfacd9273b49814086

Added to database: 09/08/2026, 10:51:59 UTC

Last enriched: 09/08/2026, 10:52:15 UTC

Last updated: 09/08/2026, 11:56:51 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses