Gambling Goblin Hijacks Gov Sites for Phishing

Infosecurity Magazine · High sophistication
Last updated September 3, 2026

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon) and pushed online gambling and sports betting, turning legitimate public websites into traffic funnels for fraud.

How the attack worked

A cybercrime operation researchers call Gambling Goblin compromised Brazilian government and education websites and turned them into infrastructure for an SEO fraud campaign active since mid-2025. Rather than defacing the sites outright, attackers installed custom malicious Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages. Visitors browsing what appeared to be a normal .gov or .edu page could be silently sent to a lookalike destination without any obvious warning.

The phishing pages impersonated well-known app stores, including Google Play, the Microsoft Store, and Amazon. They were localized for Brazilian users and promoted online gambling and sports betting, effectively turning trusted public-sector traffic into a funnel for betting-related fraud. The broader operation also included a Linux toolkit with downloaders, backdoors, a credential stealer, and an SSH brute-forcer, along with scanning and reconnaissance tooling used to identify and compromise vulnerable servers.

Why it succeeded

This attack worked because it exploited trust in the destination rather than trust in a sender or message. Visitors had no reason to suspect a familiar government or education domain would lead anywhere unsafe. Because the redirect happened server-side through custom modules rather than through an obvious link or email, there was little for an ordinary user to notice before landing on the fake app-store page. The use of well-known brand names like Google Play, Microsoft Store, and Amazon added a further layer of apparent legitimacy.

What to watch for

  • An unexpected redirect from a trusted .gov or .edu site to an unfamiliar app-store style page
  • A page that looks like a major app store but promotes gambling or sports betting instead of an app download
  • A browser address bar showing a domain that does not match the real Google Play, Microsoft Store, or Amazon domain
  • Page content that has nothing to do with the reason the site was originally visited

Building resistance

Employees, students, and members of the public who visit government and education sites should be encouraged to pause when a page's content suddenly shifts away from its expected purpose, especially toward app downloads or betting promotions. Verifying the domain before entering credentials or installing anything remains a reliable habit, since brand lookalike pages can convincingly imitate major stores.

For organizations running public-facing websites, especially in government, education, healthcare, and media, the takeaway is different: security teams should audit Apache and SSH configurations and hunt for rogue modules or masqueraded processes that could enable silent redirects like these. Regular integrity checks on web server configurations can help catch this kind of infrastructure abuse before it reaches end users.

Key findings

  • Attackers compromised Brazilian government and education websites and used them as infrastructure for an SEO fraud campaign active since mid-2025.
  • Custom malicious Apache modules acted as a reverse proxy to route selected visitors to attacker-controlled phishing pages.
  • Phishing pages impersonated major brands (Google Play, Microsoft Store, Amazon), were localized for Brazilian users, and promoted gambling/sports betting.
  • Victims included federal/state/municipal government entities, plus Brazilian commercial sites (news, healthcare, business associations).
  • The operation included a wider Linux toolkit (downloaders, backdoors, credential stealer, SSH brute-forcer) and scanning/recon tooling.

Who’s being targeted

  • Commonly targeted roles: All employees, Public-facing web/IT administrators, Communications/Digital teams, Students and staff at education institutions.
  • Affected industries: Government, Education, Utilities, News/Media, Healthcare, Business associations/Nonprofits.
  • Attack channels: website.
  • Impersonated: Google Play / Microsoft Store / Amazon (impersonated app-store destination).

Red flags to watch for

  • Unexpected redirect from a trusted .gov/.edu site to an app-store lookalike
  • Brand lookalike page promoting gambling/betting instead of the expected government service
  • Browser address/domain does not match the real Google Play/Microsoft Store/Amazon domain
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Gambling Goblin campaign?

It's an SEO fraud operation, linked by researchers to Earth Berberoka, that compromised Brazilian government and education websites and used them as trusted entry points to redirect visitors to phishing pages since mid-2025.

How did attackers redirect visitors from legitimate sites?

Attackers installed custom malicious Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages.

What did the phishing pages look like?

The pages impersonated Google Play, the Microsoft Store, and Amazon, were localized for Brazilian users, and promoted online gambling and sports betting apps.

Who was affected by this campaign?

Victims included federal, state, and municipal government entities, as well as Brazilian commercial sites in news, healthcare, and business associations.

Read the video transcript

Imagine you open a Brazilian government site, and two seconds later you’re on a “Google Play” page pushing betting apps. Researchers found a group hijacking Brazilian gov and education servers, using custom Apache modules to quietly proxy visitors to phishing pages that mimic Google Play, Microsoft Store, and Amazon. Here’s the tell: you came for a government service, but you land on a Portuguese app-store page hyping gambling. And the browser’s address bar is not play.google.com, microsoft.com, or amazon.com.br. If a trusted .gov or .edu suddenly dumps you into any app store or betting promo, stop and check the domain, if it’s not the real brand, close the tab and don’t enter a thing.

Similar attacks

Gov Websites Hijacked to Push Fake App Stores

Gov Websites Hijacked to Push Fake App Stores

Check Point Research reports a real campaign where a Chinese-speaking actor compromised Brazilian government and education websites and used them as stealthy “front doors” to redirect visitors to attacker-controlled phishing pages. The fake pages impersonate trusted app stores (Google Play,…

September 2, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026