Chinese-Speaking Crew Slips Malicious Apache Modules Onto Brazilian .gov and .edu Sites

Check Point tracks the cluster as Gambling Goblin, with medium-confidence links to Chinese-speaking SEO-poisoning operators active since mid-2025.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit government office desk in South Asia, an unopened manila document folder and a glowing lap
Share

Key points

  • Check Point Research says it has tracked a Chinese-speaking group it calls Gambling Goblin since mid-2025.
  • The crew planted malicious Apache modules on web servers belonging to Brazilian government and university sites.
  • The modules quietly redirected some visitors to pages selling online casinos and sports betting.
  • Attribution rests on language artefacts and infrastructure overlaps, so it should be read as medium confidence.
  • Site owners are urged to audit installed Apache modules and check for unfamiliar shared object files.

A Chinese-speaking cybercrime crew has been quietly tampering with Brazilian government and university websites to push people towards gambling sites, according to new research.

The group is tracked as Gambling Goblin by Check Point Research, which says the campaign has been running since around the middle of 2025. First reported by The Hacker News, the operation targets the web servers behind official Brazilian sites rather than the visitors directly.

Here is what that means in plain terms. When you type in the address of a government portal, your browser talks to a web server. Most Brazilian public sites run software called Apache, one of the oldest and most common pieces of web server software on the internet. Apache can be extended with small add-ons called modules, in the same way a browser can be extended with plugins.

The attackers wrote their own malicious Apache module and installed it on servers they had already broken into. Once loaded, the module sat inside the trusted web server and watched incoming visitors.

What did the malicious module actually do?

It hijacked traffic. For selected visitors, usually those arriving from search engines, the module quietly redirected the browser away from the real government or university page and towards attacker-controlled pages advertising online casinos and sports betting.

Other visitors, including administrators checking the site directly, saw the normal page. That selective behaviour is deliberate. It keeps the site looking healthy to its owners while the criminals skim commercial value from its search ranking, a technique analysts call SEO poisoning.

Check Point says the redirect pages point at gambling brands that pay affiliate commissions, so every diverted click can turn into money for the operators.

Who is Gambling Goblin, and how sure are we?

Gambling Goblin is a name Check Point uses for this specific activity cluster. It is not a nation-state group. The evidence pointing to Chinese-speaking operators includes language strings inside the tooling and infrastructure that overlaps with earlier Chinese-language gambling-promotion campaigns.

That is enough for medium-confidence attribution to a Chinese-speaking criminal cluster. It is not enough to name a company, a city, or a state sponsor, and Check Point does not try to.

The tactics, techniques and procedures, or TTPs, on show here (planting a rogue Apache module, filtering victims by referrer, monetising through affiliate gambling pages) overlap with other Chinese-language SEO-poisoning crews seen hitting Southeast Asian and Latin American servers over the past two years.

Should ordinary Brazilians worry?

Probably not in a direct way. The campaign is about making money from redirected clicks, not about stealing personal data from citizens or planting malware on their phones. If you were bounced from a .gov.br page to a betting site, close the tab. Do not enter card details. There is no sign that the underlying government services or databases were touched.

The people who need to act are the site administrators.

Item Detail
Cluster name Gambling Goblin (Check Point)
Suspected origin Chinese-speaking, medium confidence
Active since Mid-2025
Victims Brazilian government and educational web servers
Payload Malicious Apache module
Goal Redirect search traffic to gambling and betting pages

What should site owners do now?

List every Apache module loaded on your server and compare it against what your team actually installed. Anything unfamiliar, especially a shared object file (a .so file) sitting outside the standard package paths, deserves a hard look. Rotate credentials for anyone with server access, and check web logs for redirects triggered only on search-engine referrers.

And assume that if one server was reachable, others in the same estate may be too.

© 2026 Threat Vectr