Gambling Goblin Brazilian SEO fraud campaign
Campaign
Summary
Hide ▲
Show ▼
The Gambling Goblin operation has been using compromised Brazilian government and education websites as infrastructure for a sustained SEO fraud campaign since mid-2025, redirecting selected visitors to phishing pages and expanding risk across Brazil. The phishing pages impersonate Google Play, the Microsoft Store and Amazon while promoting gambling and sports betting. The campaign spans federal, state and municipal public bodies and also reaches commercial Brazilian sites in media, healthcare and business sectors. The broader toolkit adds reverse-proxy Apache modules, oRAT, AlphaAgent and PasswordHarvester, which increases the chance of follow-on compromise and malware delivery.
Related Happenings
CPR Apache and SSH compromise hunt guidance
Advisory/Mitigation
H score14
First: 02.09.2026 17:00
Last: 02.09.2026 17:00
Sources 1
How related:
CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
About this happening:
CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromise...
CPR Apache and SSH compromise hunt guidance
Advisory/MitigationHow related: CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
About this happening: CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromise...
Brazilian government websites hit by network compromise
Incident
H score28
First: 16.07.2026 14:58
Last: 16.07.2026 14:58
Sources 1
About this happening:
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...
Brazilian government websites hit by network compromise
IncidentAbout this happening: More than 20 Brazilian government websites were hijacked and turned into malware delivery channels, exposing public-sector infrastructure to downstream abuse. The comp...
BTMOB phishing campaign targeting Brazil and Latin America
Campaign
H score39
First: 29.05.2026 00:10
Last: 29.05.2026 00:10
Sources 1
About this happening:
BTMOB phishing activity is using localized fake-app lures to target users in Brazil and Latin America, increasing the risk of malicious installs and account compromise...
BTMOB phishing campaign targeting Brazil and Latin America
CampaignAbout this happening: BTMOB phishing activity is using localized fake-app lures to target users in Brazil and Latin America, increasing the risk of malicious installs and account compromise...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
02.09.2026 17:00 2 articles · 0h ago
Check Point Research links Gambling Goblin to Brazilian SEO fraud campaign
Initial DisclosureCheck Point Research linked the Chinese-speaking Gambling Goblin cluster, assessed with medium-to-high confidence as connected to Earth Berberoka, to a sustained SEO fraud operation using compromised Brazilian government and education websites since mid-2025. The operators installed custom Apache modules that acted as a reverse proxy, stripped Content-Security-Policy headers, and redirected selected visitors to phishing pages impersonating Google Play, the Microsoft Store and Amazon.
Show sources
- Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons — www.infosecurity-magazine.com — 02.09.2026 17:00
- Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons — www.infosecurity-magazine.com — 02.09.2026 17:00