Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites. For more than a year, the Chinese-language group known as Gambling Goblin has compromised Brazilian government servers, using the high reputation of the domains to boost the search-engine rankings of the group's phishing sites. The attacks focus on creating a reverse-proxy network to boost the legitimacy of gambling-oriented phishing sites, increasing the sites' rankings on search engines, according to a new report from Check Point Software Technologies. The group has compromised about 30 servers in Brazil, mainly belonging to local governments and education organizations, with a handful of companies affected as well.
"They can even allow it to download malware at some point because the infrastructure has already been created." Brazil continues to be a popular Latin American target of cybercriminals. The country is currently considering strengthening protections for citizens , who are frequently targeted with algorithmic casino games, but illegal gambling sites are often promoted by cybercriminals. The researchers have not yet identified the initial access vector used by the cybercriminals group.
"They could be collecting credentials that are potentially used within other [parts of the] infrastructure by those government institutions," Neto says.
What changed
Related: 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft "We don't know how separate those compromised Web servers are from the government networks," Neto says.
We don't know." Currently, the Gambling Goblin group's campaign is focused on creating infrastructure to boost visibility for gambling sites.
Who is affected
Yet, when Gambling Goblin gains access, they co-opt victims' servers to compile and install a stealthy Linux toolkit, including a downloader, multiple backdoors, a credential stealers, and other post-compromise offensive programs.
Many of the Web servers belong to small municipal governments, which typically have limited IT teams and rarely have a dedicated cybersecurity professional.
Check Point warned that malware distribution could be fairly simple, but the attackers' access to the servers could be a jumping-off point into the rest of the network, especially if they are able to find additional privileged credentials.
"That is the part where we believe is a little bit overlooked by some of defenders — OK, it's just phishing in a sense, but with those tools, they could collect those credentials." In the past, Brazilian organizations were mainly targeted by local cybercriminals groups, because the country benefitted from its heterogenous technology and business environment, Neto says.
The fact that Chinese groups have begun targeting Latin America for cybercrime shows that global cybercrime syndicates are quickly growing, often helped by AI systems' ability to natively translate phishing lures and content, he says.
Why this matters
"They can even allow it to download malware at some point because the infrastructure has already been created." Brazil continues to be a popular Latin American target of cybercriminals.
The country is currently considering strengthening protections for citizens , who are frequently targeted with algorithmic casino games, but illegal gambling sites are often promoted by cybercriminals.
The researchers have not yet identified the initial access vector used by the cybercriminals group.
The technical picture
"They could be collecting credentials that are potentially used within other [parts of the] infrastructure by those government institutions," Neto says.