A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud.
The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape.
Rather than deploying the country’s more familiar banking malware, the attackers are abusing trusted Brazilian domains especially .gov.br properties to manipulate search rankings and route visitors to attacker-controlled pages masquerading as legitimate app stores.
The group installs custom Apache modules on compromised Linux web servers, transforming legitimate websites into covert reverse proxies.
The malware monitors incoming requests and redirects traffic matching specific paths to externally hosted phishing content while keeping the victim domain visible in the browser address bar.
This allows malicious pages to inherit the credibility, reputation, and search authority of the compromised institution.
One module, identified as opsproxy.c, is deployed via a Bash-based installer that detects whether the victim is running Debian, Ubuntu, CentOS, or Red Hat.
It downloads the source code, installs Apache development dependencies, compiles the module locally with Apache’s apxs utility, and enables it in the web server configuration.
The installer then deletes build artifacts and timestomps the malicious .so file to resemble legitimate modules such as mod_ssl or mod_suexec.
The module hijacks requests to hard-coded paths, including /wps, /bmw, and /card, and forwards them to attacker infrastructure.
It also strips Content-Security-Policy protections and replaces them with permissive rules that allow inline scripts, dynamic JavaScript execution, third-party resources, and data: or blob: content.
That design gives the phishing infrastructure broad control over the content rendered through a trusted Brazilian website.
The proxied pages impersonate Google Play, Microsoft Store, and Amazon-themed download portals.
They are localized in Brazilian Portuguese, contain fabricated ratings and reviews, and use schema.org metadata, Open Graph tags, and social-media branding to appear trustworthy to users and search crawlers.

Behind the storefronts, the operators promote online gambling and sports-betting services.
Check Point found that the infrastructure linked dozens of legitimate Brazilian domains, many belonging to municipal, state, and federal government entities.
This domain chaining improves search visibility and enables the operators to funnel organic traffic through sites that already carry strong search-engine reputations.
The campaign is therefore not simply website defacement; it is an industrialized abuse of institutional trust for search manipulation and monetization.
The campaign, tracked by Check Point Research as Gambling Goblin, combines stealthy malicious Apache modules with a sophisticated Linux malware toolkit designed for persistence, credential theft, reconnaissance, and network pivoting.
Researchers also discovered related phishing templates in Vietnamese, Spanish, and English, as well as infrastructure capable of generating fresh domains daily.
The findings suggest the Brazil-focused operation is a scalable model that can be replicated in additional markets.
Gambling Goblin’s server-side tradecraft goes beyond SEO fraud.
Earth Berberoka Hits Brazil
The group deploys a heavily obfuscated Linux toolkit comprising the Go-based DownPro downloader, the modular AlphaAgent backdoor, the oRAT remote-access trojan.
To make that relayed content render without interference, the module strips the upstream site’s Content-Security-Policy headers.

A 3snake-derived credential stealer called PasswordHarvester, an SSH brute-force tool, and reconnaissance scripts.
DownPro downloads additional payloads using AES-GCM-encrypted URLs and drops them under names that blend into a Linux environment, such as systemd-udevd, rsync-tsl, or snapd-ext.
It can also install a setuid helper named chuser, allowing attackers to retain privileged command-execution capability.

PasswordHarvester targets authentication-related processes including sshd, sudo, su, ssh, passwd, and login.
Running as root, it monitors process events, attaches to selected processes through ptrace, captures credentials, and sends them to command-and-control infrastructure after RC4 encryption and Base64 encoding.
AlphaAgent supports remote shell access, file transfers, SOCKS5 proxying, tunneling, SSH-key collection, and lateral-movement reconnaissance.
It disguises its processes as Linux kernel workers, nginx, rsyslogd, or cloud-related services, and can use gRPC over HTTPS, DNS tunneling, or HTTP for command-and-control traffic.
Some variants mimic Chrome TLS fingerprints and camouflage communications as Google or Cloudflare traffic.
Check Point assessed with medium-to-high confidence that Gambling Goblin is connected to Earth Berberoka, also known as GamblingPuppet.
Trend Micro first documented Earth Berberoka in 2022 as a Chinese-speaking actor targeting online gambling platforms across Windows, Linux, and macOS. Its historic toolkit included PlugX, Gh0st RAT, PuppetLoader, and oRAT.
The strongest overlap is oRAT, whose codebase and REST-style control routes align with malware previously associated with Earth Berberoka.
Researchers also identified Chinese-language comments and dual-language operator strings, gambling-sector targeting, lookalike domains resembling trusted technology brands, and command-and-control hosting patterns consistent with earlier Earth Berberoka activity.
For Brazilian organizations, the campaign reinforces the need to monitor Apache module inventories, investigate unauthorized configuration changes, enforce file-integrity monitoring, and inspect unexpected reverse-proxy behavior.
Government and education-sector administrators should also hunt for suspicious .so files, altered CSP headers, hidden request-routing rules, unfamiliar systemd services, and Linux processes masquerading as standard kernel or web-server components.
IOCs
| Domains | IP Addresses |
|---|---|
| rb[.]aliyuntsl[.]com | 154[.]84[.]62[.]160 |
| br[.]team-c2[.]com | 154[.]84[.]62[.]128 |
| hwlocal[.]team-hw[.]com | 154[.]84[.]62[.]149 |
| br[.]team-hw[.]com | 154[.]84[.]62[.]145 |
| data[.]mirrors-inc[.]com | 15[.]228[.]251[.]82 |
| team-hw[.]com | 56[.]124[.]87[.]60 |
| update[.]team-c2[.]com | 18[.]229[.]255[.]14 |
| — | 18[.]166[.]208[.]57 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.





