Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon) and pushed online gambling and sports betting, turning legitimate public websites into traffic funnels for fraud.
How the attack worked
A cybercrime operation researchers call Gambling Goblin compromised Brazilian government and education websites and turned them into infrastructure for an SEO fraud campaign active since mid-2025. Rather than defacing the sites outright, attackers installed custom malicious Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages. Visitors browsing what appeared to be a normal .gov or .edu page could be silently sent to a lookalike destination without any obvious warning.
The phishing pages impersonated well-known app stores, including Google Play, the Microsoft Store, and Amazon. They were localized for Brazilian users and promoted online gambling and sports betting, effectively turning trusted public-sector traffic into a funnel for betting-related fraud. The broader operation also included a Linux toolkit with downloaders, backdoors, a credential stealer, and an SSH brute-forcer, along with scanning and reconnaissance tooling used to identify and compromise vulnerable servers.
Why it succeeded
This attack worked because it exploited trust in the destination rather than trust in a sender or message. Visitors had no reason to suspect a familiar government or education domain would lead anywhere unsafe. Because the redirect happened server-side through custom modules rather than through an obvious link or email, there was little for an ordinary user to notice before landing on the fake app-store page. The use of well-known brand names like Google Play, Microsoft Store, and Amazon added a further layer of apparent legitimacy.
What to watch for
- An unexpected redirect from a trusted .gov or .edu site to an unfamiliar app-store style page
- A page that looks like a major app store but promotes gambling or sports betting instead of an app download
- A browser address bar showing a domain that does not match the real Google Play, Microsoft Store, or Amazon domain
- Page content that has nothing to do with the reason the site was originally visited
Building resistance
Employees, students, and members of the public who visit government and education sites should be encouraged to pause when a page's content suddenly shifts away from its expected purpose, especially toward app downloads or betting promotions. Verifying the domain before entering credentials or installing anything remains a reliable habit, since brand lookalike pages can convincingly imitate major stores.
For organizations running public-facing websites, especially in government, education, healthcare, and media, the takeaway is different: security teams should audit Apache and SSH configurations and hunt for rogue modules or masqueraded processes that could enable silent redirects like these. Regular integrity checks on web server configurations can help catch this kind of infrastructure abuse before it reaches end users.
Key findings
- Attackers compromised Brazilian government and education websites and used them as infrastructure for an SEO fraud campaign active since mid-2025.
- Custom malicious Apache modules acted as a reverse proxy to route selected visitors to attacker-controlled phishing pages.
- Phishing pages impersonated major brands (Google Play, Microsoft Store, Amazon), were localized for Brazilian users, and promoted gambling/sports betting.
- Victims included federal/state/municipal government entities, plus Brazilian commercial sites (news, healthcare, business associations).
- The operation included a wider Linux toolkit (downloaders, backdoors, credential stealer, SSH brute-forcer) and scanning/recon tooling.
Who’s being targeted
- Commonly targeted roles: All employees, Public-facing web/IT administrators, Communications/Digital teams, Students and staff at education institutions.
- Affected industries: Government, Education, Utilities, News/Media, Healthcare, Business associations/Nonprofits.
- Attack channels: website.
- Impersonated: Google Play / Microsoft Store / Amazon (impersonated app-store destination).
Red flags to watch for
- Unexpected redirect from a trusted .gov/.edu site to an app-store lookalike
- Brand lookalike page promoting gambling/betting instead of the expected government service
- Browser address/domain does not match the real Google Play/Microsoft Store/Amazon domain
Frequently asked questions
What is the Gambling Goblin campaign?
It's an SEO fraud operation, linked by researchers to Earth Berberoka, that compromised Brazilian government and education websites and used them as trusted entry points to redirect visitors to phishing pages since mid-2025.
How did attackers redirect visitors from legitimate sites?
Attackers installed custom malicious Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages.
What did the phishing pages look like?
The pages impersonated Google Play, the Microsoft Store, and Amazon, were localized for Brazilian users, and promoted online gambling and sports betting apps.
Who was affected by this campaign?
Victims included federal, state, and municipal government entities, as well as Brazilian commercial sites in news, healthcare, and business associations.
Read the video transcript
Imagine you open a Brazilian government site, and two seconds later you’re on a “Google Play” page pushing betting apps. Researchers found a group hijacking Brazilian gov and education servers, using custom Apache modules to quietly proxy visitors to phishing pages that mimic Google Play, Microsoft Store, and Amazon. Here’s the tell: you came for a government service, but you land on a Portuguese app-store page hyping gambling. And the browser’s address bar is not play.google.com, microsoft.com, or amazon.com.br. If a trusted .gov or .edu suddenly dumps you into any app store or betting promo, stop and check the domain, if it’s not the real brand, close the tab and don’t enter a thing.