Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Overview
A cybercrime group known as Gambling Goblin has been targeting Brazilian government and educational websites by installing malicious Apache modules on their servers. This operation, which Check Point Research has been tracking since mid-2025, redirects users from these sites to pages promoting online gambling and sports betting. The attackers are likely Chinese-speaking, and their activities raise concerns about the security of public web infrastructure in Brazil. This incident not only affects the integrity of government and educational institutions but also poses risks to users who may unknowingly interact with these compromised sites. The situation highlights the ongoing challenges in cybersecurity for public entities and the need for robust security measures.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Brazilian government and educational institution web servers running Apache
- Action Required: Organizations should audit their web server configurations, remove any unauthorized modules, and enhance monitoring of server traffic for unusual activities.
- Timeline: Ongoing since mid-2025
Original Article Summary
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules
Impact
Brazilian government and educational institution web servers running Apache
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since mid-2025
Remediation
Organizations should audit their web server configurations, remove any unauthorized modules, and enhance monitoring of server traffic for unusual activities.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Apache, Check Point.