Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages: A Complex Web of Cyber Deception




Malicious Apache modules have been hijacking the traffic of Brazilian government sites to push betting pages, according to a recent report by Check Point Research. This sophisticated cybercrime campaign involves the installation of malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, which then divert visitors to attacker-controlled pages promoting online gambling and sports betting. The likely goal of the attackers is to manipulate search engine optimization (SEO) at scale, using compromised high-reputation domains to inflate search rankings. The campaign is believed to be linked to an actor known as Earth Berberoka, who was targeted by Trend Micro in 2022. This complex web of cyber deception highlights the ongoing threats faced by organizations and individuals alike.

  • Malicious Apache modules are hijacking Brazilian government sites to push betting pages.
  • The modules reverse-proxy visitors to attacker-controlled pages, posing as trusted app stores and promoting online gambling and sports betting.
  • The likely goal is to manipulate search engine optimization (SEO) at scale using compromised high-reputation domains.
  • A range of tools, including custom downloaders, backdoors, and reconnaissance agents, are used in the campaign.
  • The attackers' goal is to control visibility, not to break into systems, according to Hunt.io.
  • Sophisticated cybercrime campaign linked to actor Earth Berberoka, who was targeted by Trend Micro in 2022.
  • At least 20 .gov.br portals were used to distribute malware, according to ANY.RUN.
  • GhostRedirector, an actor assessed as China-aligned, compromised Windows servers in Brazil, Thailand, and Vietnam in June 2025.



  • Malicious Apache modules have been hijacking the traffic of Brazilian government sites to push betting pages, according to a recent report by Check Point Research. This sophisticated cybercrime campaign involves the installation of malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, which then divert visitors to attacker-controlled pages promoting online gambling and sports betting.

    The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely. These pages pose as trusted app stores, including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade.

    The likely goal of the attackers is to manipulate search engine optimization (SEO) at scale, using compromised high-reputation domains, many of which are Brazilian government sites, to inflate search rankings. Check Point said it has tracked the campaign since mid-2025.

    In July, ANY.RUN reported that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks as PhantomEnigma. ANY_RUN said that the government systems are part of the delivery chain, not confirmed campaign targets, and that blocking them broadly would disrupt access to government resources.

    Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.

    The group behind this campaign deploys a range of tools, including DownPro, a custom downloader; AlphaAgent, a modular backdoor; oRAT, a remote access trojan (RAT); a 3snake-based credential stealer; an SSH brute-forcer; and a plugin-driven reconnaissance agent. The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication.

    Hunt.io said in July 2025 that it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites. The company redacted certain indicators in coordination with Brazil's government incident response team, CTIR, while that investigation continued.

    The goal of the attackers was not to break into systems but to control visibility, Hunt.io said. The campaign is believed to be linked to an actor known as Earth Berberoka, who was targeted by Trend Micro in 2022. Trend Micro documented Earth Berberoka malware in Windows and macOS samples, both flagged as version 0.5.1.

    ESET documented at least 65 Windows servers, mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor it assessed with medium confidence as China-aligned. GhostRedirector installed a native Internet Information Services (IIS) module called Gamshen, which can perform SEO fraud.

    Palo Alto Networks Unit 42 documented the same reverse-proxy technique on IIS servers in September 2025. The use of malicious Apache modules to hijack government site traffic is a sophisticated and complex web of cyber deception, highlighting the ongoing threats faced by organizations and individuals alike.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-Apache-Modules-Hijack-Brazilian-Government-Site-Traffic-to-Push-Betting-Pages-A-Complex-Web-of-Cyber-Deception-ehn.shtml

  • https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html


  • Published: Wed Sep 2 11:18:03 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us