Check Point Research reports a real campaign where a Chinese-speaking actor compromised Brazilian government and education websites and used them as stealthy “front doors” to redirect visitors to attacker-controlled phishing pages. The fake pages impersonate trusted app stores (Google Play, Microsoft Store, Amazon) to hijack search traffic and funnel users toward online gambling/betting content, an approach that could easily be repurposed to deliver malware.
Key findings
- A Chinese-speaking cybercrime cluster (“Gambling Goblin”) has run a sustained campaign against Brazilian organizations since mid-2025, especially government and education.
- Compromised web servers were modified with malicious Apache modules that reverse-proxy visitors to attacker phishing pages while still appearing to be on the legitimate domain.
- The phishing pages impersonate trusted app stores (Google Play, Microsoft Store, Amazon) and are optimized to manipulate SEO and hijack search-driven traffic.
- The infrastructure chains many high-reputation Brazilian domains (including numerous .gov.br sites) to inflate search rankings and distribute the scam content at scale.
- The campaign is built to scale internationally, with additional phishing networks localized for Vietnamese, Spanish, and English audiences.
- Because the lure already mimics app-download pages, the operation is “one step” away from distributing malware directly.
Who’s being targeted
- Commonly targeted roles: All employees (safe browsing / search-result hygiene), Public-sector staff, Education staff and students, Web/communications teams (spot suspicious site content), IT/Web administrators (awareness to escalate signs of website compromise).
- Affected industries: Government (federal, state, municipal), Education, Utilities (state-owned utility mentioned), Media (local news outlets mentioned), Healthcare (health clinics mentioned), Nonprofits/Associations (business associations mentioned).
- Attack channels: website.
- Impersonated: Google Play / Microsoft Store / Amazon (app-download destinations), Compromised Brazilian government website (trusted domain acting as the “front door”).
Awareness takeaways
- Treat “trusted brand” app-download pages as suspicious if the content/topic doesn’t match (e.g., gambling/betting) or if you arrived via an unusual government/education URL path.
- Be cautious when clicking search results that lead to unexpected pages on reputable domains, attackers may be abusing trusted sites to make scams look legitimate.
- Report “odd sections” of a legitimate website (strange new paths or unrelated content). Compromised sites can selectively serve attacker content without changing the homepage.
- Assume fake download pages can quickly pivot to malware delivery; avoid downloading software from pages reached via search redirects or unfamiliar links.
Red flags to watch for
- The content is gambling/sports betting even though the page looks like a mainstream app store
- The page is served from an unexpected domain/path on a reputable site (e.g., unusual paths like /jogos or /nova)
- Branding and social metadata are manipulated (e.g., tags referencing official handles) to appear legitimate
- Unfamiliar URL prefixes on a trusted site leading to unrelated content
- Security headers/protections appear weakened or missing on only certain pages
- The website displays content that does not match the organization’s purpose (e.g., gambling promotions on a government site)
Read the video transcript
You click a Brazilian government site, and instead of forms and services… you get what looks like Google Play pushing betting apps. Behind the scenes, a hacked server with a malicious Apache module is quietly proxying you to a phishing page that poses as Google Play, Microsoft Store, or Amazon, still under that trusted .gov.br address. Here’s the tell: the URL path is weird, things like /jogos, /nova, or /wps on a government or school site, and the page is all gambling and betting, not what that organization actually does. If you land on any app-store-looking page with gambling content under a government or school domain, stop and report that URL to IT immediately, don’t click a single tile.