Gov Websites Hijacked to Push Fake App Stores

Check Point Research · High sophistication
Last updated September 2, 2026

Check Point Research reports a real campaign where a Chinese-speaking actor compromised Brazilian government and education websites and used them as stealthy “front doors” to redirect visitors to attacker-controlled phishing pages. The fake pages impersonate trusted app stores (Google Play, Microsoft Store, Amazon) to hijack search traffic and funnel users toward online gambling/betting content, an approach that could easily be repurposed to deliver malware.

Key findings

  • A Chinese-speaking cybercrime cluster (“Gambling Goblin”) has run a sustained campaign against Brazilian organizations since mid-2025, especially government and education.
  • Compromised web servers were modified with malicious Apache modules that reverse-proxy visitors to attacker phishing pages while still appearing to be on the legitimate domain.
  • The phishing pages impersonate trusted app stores (Google Play, Microsoft Store, Amazon) and are optimized to manipulate SEO and hijack search-driven traffic.
  • The infrastructure chains many high-reputation Brazilian domains (including numerous .gov.br sites) to inflate search rankings and distribute the scam content at scale.
  • The campaign is built to scale internationally, with additional phishing networks localized for Vietnamese, Spanish, and English audiences.
  • Because the lure already mimics app-download pages, the operation is “one step” away from distributing malware directly.

Who’s being targeted

  • Commonly targeted roles: All employees (safe browsing / search-result hygiene), Public-sector staff, Education staff and students, Web/communications teams (spot suspicious site content), IT/Web administrators (awareness to escalate signs of website compromise).
  • Affected industries: Government (federal, state, municipal), Education, Utilities (state-owned utility mentioned), Media (local news outlets mentioned), Healthcare (health clinics mentioned), Nonprofits/Associations (business associations mentioned).
  • Attack channels: website.
  • Impersonated: Google Play / Microsoft Store / Amazon (app-download destinations), Compromised Brazilian government website (trusted domain acting as the “front door”).

Awareness takeaways

  • Treat “trusted brand” app-download pages as suspicious if the content/topic doesn’t match (e.g., gambling/betting) or if you arrived via an unusual government/education URL path.
  • Be cautious when clicking search results that lead to unexpected pages on reputable domains, attackers may be abusing trusted sites to make scams look legitimate.
  • Report “odd sections” of a legitimate website (strange new paths or unrelated content). Compromised sites can selectively serve attacker content without changing the homepage.
  • Assume fake download pages can quickly pivot to malware delivery; avoid downloading software from pages reached via search redirects or unfamiliar links.

Red flags to watch for

  • The content is gambling/sports betting even though the page looks like a mainstream app store
  • The page is served from an unexpected domain/path on a reputable site (e.g., unusual paths like /jogos or /nova)
  • Branding and social metadata are manipulated (e.g., tags referencing official handles) to appear legitimate
  • Unfamiliar URL prefixes on a trusted site leading to unrelated content
  • Security headers/protections appear weakened or missing on only certain pages
  • The website displays content that does not match the organization’s purpose (e.g., gambling promotions on a government site)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You click a Brazilian government site, and instead of forms and services… you get what looks like Google Play pushing betting apps. Behind the scenes, a hacked server with a malicious Apache module is quietly proxying you to a phishing page that poses as Google Play, Microsoft Store, or Amazon, still under that trusted .gov.br address. Here’s the tell: the URL path is weird, things like /jogos, /nova, or /wps on a government or school site, and the page is all gambling and betting, not what that organization actually does. If you land on any app-store-looking page with gambling content under a government or school domain, stop and report that URL to IT immediately, don’t click a single tile.

Similar attacks

Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026