Brazil .gov.br sites hit in SEO fraud campaign
Gambling Goblin compromised Brazilian public and education sites to redirect traffic to betting and phishing pages, officials said.
Check Point Research attributed a sustained campaign against Brazil’s .gov.br government and education sites to Gambling Goblin, a Chinese-speaking group linked to Earth Berberoka/GamblingPuppet. The operation used compromised state infrastructure for SEO fraud tied to betting and phishing, and Brazil’s government officially acknowledged the compromise of public servers.
Check Point Research attributed a sustained campaign against Brazilian government and education sites under the .gov.br domain to Gambling Goblin, a Chinese-speaking group linked to the Earth Berberoka/GamblingPuppet cluster. Since mid-2025, the operation has used compromised state infrastructure for SEO fraud aimed at betting and phishing, and the Brazilian government has officially acknowledged the compromise of public servers.
What did the group do to the Brazilian sites?
Gambling Goblin compromised public servers and turned them into a selective redirection layer that keeps the .gov.br domain visible while diverting traffic to betting and phishing content. According to the official GSI/CTIR notice, requests from search engine bots such as Googlebot were intercepted, and hundreds of links to betting houses, illegal casinos, and fraudulent schemes were injected in real time.
External technical analysis says the group installed malicious Apache modules that act as a proxy. As a result, the government domain still loads for the user or the search engine, but the content served can change depending on where the visit is headed. Pages impersonating Google Play, Microsoft Store, and Amazon appeared in that diverted traffic.
How broad was the institutional reach?
The campaign was not limited to a handful of isolated sites. According to Brazilian local coverage, compromised servers included a federal ministry, a federal public agency, a state legislative assembly, state audit courts, and dozens of municipalities.
That reach extends the impact beyond the municipal level or a few standalone pages and shows that public infrastructure was used as support for a traffic-capture operation with global reach. Specialized media in Europe said the case differs from the typical regional banking malware pattern and focuses instead on traffic capture and ranking manipulation.
What did the sources say about the end goal?
BNLData said Gambling Goblin takes advantage of loose laws and regulatory gaps around online betting to monetize diverted traffic from government sites. That monetization is tied to betting houses registered outside Brazil but active on Brazilian users.
The Hacker News and other international outlets also said the group exploits the trust and authority of .gov.br domains to manipulate results mainly in Google, although the pattern is mentioned in the context of broader poisoning campaigns affecting Bing and other search engines. In that reading, Brazil serves as a high-value infrastructure node within a multi-search-engine SEO poisoning strategy.
How does it connect to other campaigns in the region?
In parallel, coverage of CL-CRI-1163 described an operation against Brazil’s financial sector that gained initial access through phishing and a resume file. After entry, multiple remote access trojans were deployed, along with SockTz, a Go-based tool that creates a reverse SOCKS5 proxy to route covert traffic into the victim’s internal network.
Additional sources placed CL-CRI-1163 within a broader set of AI-assisted intrusions targeting transportation, government, water utilities, and financial organizations in Mexico, Ecuador, and Brazil. In that context, the campaign against Brazil’s financial sector appears to be part of a wider regional, multi-vertical pattern, while Russian-language coverage added that the infrastructure was intended to support lateral movement and possible data exfiltration.
Sources
- Attackers Use AI-Assisted Intrusions and Data Exfiltration to Target Latin American Organizationsvarutra.com· Varutra (Threatpost-style)
- ブラジル政府サイトを悪用した大規模SEO詐欺japansecuritysummit.org· JAPANSecuritySummit
- Weltweiter SEO-Betrug: Gambling Goblin kapert brasilianische Regierungsseitenit-daily.net· IT-daily
- Chinese network hacks '.gov.br' websites in online betting schemebnldata.com.br· BNLData (Brasil)
- Китайские хакеры используют вредоносные модули Apache для захвата трафика в Бразилииpravda.ru· Pravda.ru
- Hackers conectaron a Claude y GPT‑4.1 directamente a ataques; sus propios servidores los delataron.securitylab.lat· SecurityLab LATAM
- 7th September – Threat Intelligence Report - Gambling Goblin campaign overviewresearch.checkpoint.com· Check Point Research
- RECOMENDAÇÃO 17/2026 sobre comprometimento de servidores públicos e fraude de apostasgov.br· GSI/CTIR (Gov.br)
- Cybercrime: Brazilian Government Websites Attackedsoftwarebay.de· SoftwareBay
- Brazilian government and education websites abused for SEO manipulation by Gambling Goblinthehackernews.com· The Hacker News
- ИИ научил хакеров взламывать быстрее. Прятаться пока не научилnews.rambler.ru· Rambler



