Brazil: Gambling Goblin hijacks .gov.br sites
A campaign tied to Gambling Goblin is abusing Brazilian government and education servers to display illegal betting under official domains.
A campaign attributed to Gambling Goblin is compromising Linux servers at Brazilian government and education institutions, turning them into covert reverse proxies to display illegal betting and fraudulent downloads under legitimate .gov.br domains. The cited analyses put the main focus in Brazil, with about 30 affected servers identified there, and activity also seen in other countries.
A campaign attributed to Gambling Goblin is compromising Linux servers at Brazilian government and education institutions and turning them into covert reverse proxies that display illegal betting pages and fraudulent downloads under legitimate .gov.br domains. The cited analyses estimate about 30 affected servers in Brazil, while activity was also observed in Vietnam, Spain, and English-language sites.
How does the campaign work?
The operation relies on installing malicious Apache modules on Linux servers, including Debian, Ubuntu, CentOS, and Red Hat, according to the independent technical analysis cited by Techora.ru. Those modules rewrite HTTP requests and strip security headers such as Content-Security-Policy, which lets attackers hijack domain reputation without changing the official URL users see.
Escudo Digital said the attackers take advantage of the authority that government and education domains carry in search engines to push illegal betting content and downloads of questionable origin. That mix of reputation abuse and traffic manipulation turns compromised sites into promotion channels, not just defaced pages or sites taken offline.
How far does the focus in Brazil go?
The main focus of the campaign is public servers in Brazil, according to Infobae and the two technical analyses cited. Techora.ru said it identified about 30 compromised servers in the country, mostly tied to local authorities and educational centers.
The same source said the campaign has been active since mid-2025 and is not limited to Brazil. It also recorded confirmed activity in Vietnam, Spain, and other English-language sites, suggesting an operation able to reuse the same technique in different environments.
What regional precedent does this case leave?
Infobae recalled two earlier incidents that affected state institutions in Latin America and forced critical services to be suspended or limited. In 2022, a ransomware attack hit platforms tied to taxes, customs, and other government services. In 2023, the attack on IFX Networks affected 78 public entities and more than 760 private companies in the region.
That background places the Brazilian case within a string of incidents that have targeted public institutions and highly exposed services. Here, the difference is not direct system disruption, but the use of official sites to host and amplify content outside the domain’s original function.
Sources
- Una red global secuestra webs gubernamentales para mostrar apuestas y descargas ilegales sin tocar la URL oficialinfobae.com· Infobae
- Hackers hijack government servers to promote illegal gamblingescudodigital.com· Escudo Digital
- Китайские хакеры атакуют госсайты Бразилии через Apachetechora.ru· Techora.ru
- Alerta por el crecimiento de ciberataques en América Latina - Infobaeinfobae.com· Infobae



