Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gambling Goblin Brazilian SEO fraud campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The Gambling Goblin operation has been using compromised Brazilian government and education websites as infrastructure for a sustained SEO fraud campaign since mid-2025, redirecting selected visitors to phishing pages and expanding risk across Brazil. The phishing pages impersonate Google Play, the Microsoft Store and Amazon while promoting gambling and sports betting. The campaign spans federal, state and municipal public bodies and also reaches commercial Brazilian sites in media, healthcare and business sectors. The broader toolkit adds reverse-proxy Apache modules, oRAT, AlphaAgent and PasswordHarvester, which increases the chance of follow-on compromise and malware delivery.

Related Happenings

CPR Apache and SSH compromise hunt guidance

Advisory/Mitigation
H score14 First: 02.09.2026 17:00 Last: 02.09.2026 17:00 Sources 1

How related: CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.

About this happening: CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromise...

Brazilian government websites hit by network compromise

Incident
H score28 First: 16.07.2026 14:58 Last: 16.07.2026 14:58 Sources 1

About this happening: More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...

BTMOB phishing campaign targeting Brazil and Latin America

Campaign
H score39 First: 29.05.2026 00:10 Last: 29.05.2026 00:10 Sources 1

About this happening: BTMOB phishing activity is using localized fake-app lures to target users in Brazil and Latin America, increasing the risk of malicious installs and account compromise...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 02.09.2026 17:00 2 articles · 0h ago

    Check Point Research links Gambling Goblin to Brazilian SEO fraud campaign

    Initial Disclosure

    Check Point Research linked the Chinese-speaking Gambling Goblin cluster, assessed with medium-to-high confidence as connected to Earth Berberoka, to a sustained SEO fraud operation using compromised Brazilian government and education websites since mid-2025. The operators installed custom Apache modules that acted as a reverse proxy, stripped Content-Security-Policy headers, and redirected selected visitors to phishing pages impersonating Google Play, the Microsoft Store and Amazon.

    Show sources