Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'apache modules'

View all threats tagged with 'apache modules'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: apache modules

Threats Tagged 'apache modules'

Click on any threat for detailed analysis and mitigation recommendations

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
0

A Chinese-speaking cybercrime group known as Gambling Goblin has targeted Brazilian government and educational websites since mid-2025 by compromising web servers and installing malicious Apache modules. These modules reverse-proxy visitors to phishing pages impersonating trusted app stores but actually promote online gambling and sports betting. The group manipulates search engine rankings by chaining compromised high-reputation domains, particularly Brazilian government sites, to increase visibility of their phishing content. Their toolkit includes custom Linux malware such as downloaders, backdoors, credential stealers, and reconnaissance tools, heavily obfuscated to evade detection. The campaign also extends beyond Brazil, targeting Vietnamese, Spanish, and English-speaking victims with parallel infrastructure.

Join the discussion
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
0

Since mid-2025, a Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign targeting Brazilian organizations, mainly government and educational institutions. The attackers compromise web servers and install malicious Apache modules that stealthily reverse-proxy visitors to phishing pages impersonating trusted app stores. These phishing pages promote online gambling and sports betting while leveraging hijacked high-reputation domains to manipulate search engine rankings and hijack traffic. The group uses a heavily obfuscated Linux toolkit including downloaders, backdoors, credential stealers, and brute-forcers. The infrastructure is scalable and extends beyond Brazil, with parallel phishing networks targeting Vietnamese, Spanish, and English-speaking victims. The phishing infrastructure could be reconfigured to deliver malware directly, posing a latent escalation risk.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: apache modules
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses