CYBER DELTA FORCESearch

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

CDF News DeskDark Reading8 Sept 2026, 5:30 pm
Image courtesy of Dark Reading. Original report
CDF REPORT

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites. For more than a year, the Chinese-language group known as Gambling Goblin has compromised Brazilian government servers, using the high reputation of the domains to boost the search-engine rankings of the group's phishing sites. The attacks focus on creating a reverse-proxy network to boost the legitimacy of gambling-oriented phishing sites, increasing the sites' rankings on search engines, according to a new report from Check Point Software Technologies. The group has compromised about 30 servers in Brazil, mainly belonging to local governments and education organizations, with a handful of companies affected as well.

"They can even allow it to download malware at some point because the infrastructure has already been created." Brazil continues to be a popular Latin American target of cybercriminals. The country is currently considering strengthening protections for citizens , who are frequently targeted with algorithmic casino games, but illegal gambling sites are often promoted by cybercriminals. The researchers have not yet identified the initial access vector used by the cybercriminals group.

"They could be collecting credentials that are potentially used within other [parts of the] infrastructure by those government institutions," Neto says.

What changed

Related: 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft "We don't know how separate those compromised Web servers are from the government networks," Neto says.

We don't know." Currently, the Gambling Goblin group's campaign is focused on creating infrastructure to boost visibility for gambling sites.

Who is affected

Yet, when Gambling Goblin gains access, they co-opt victims' servers to compile and install a stealthy Linux toolkit, including a downloader, multiple backdoors, a credential stealers, and other post-compromise offensive programs.

Many of the Web servers belong to small municipal governments, which typically have limited IT teams and rarely have a dedicated cybersecurity professional.

Check Point warned that malware distribution could be fairly simple, but the attackers' access to the servers could be a jumping-off point into the rest of the network, especially if they are able to find additional privileged credentials.

"That is the part where we believe is a little bit overlooked by some of defenders — OK, it's just phishing in a sense, but with those tools, they could collect those credentials." In the past, Brazilian organizations were mainly targeted by local cybercriminals groups, because the country benefitted from its heterogenous technology and business environment, Neto says.

The fact that Chinese groups have begun targeting Latin America for cybercrime shows that global cybercrime syndicates are quickly growing, often helped by AI systems' ability to natively translate phishing lures and content, he says.

Why this matters

"They can even allow it to download malware at some point because the infrastructure has already been created." Brazil continues to be a popular Latin American target of cybercriminals.

The country is currently considering strengthening protections for citizens , who are frequently targeted with algorithmic casino games, but illegal gambling sites are often promoted by cybercriminals.

The researchers have not yet identified the initial access vector used by the cybercriminals group.

The technical picture

"They could be collecting credentials that are potentially used within other [parts of the] infrastructure by those government institutions," Neto says.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the PointThe Hacker News · 15 Sept 2026, 4:56 pmHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackSecurityWeek · 15 Sept 2026, 2:39 pmInternational Meteor Organization Hit by Cyberattack, Weeks of Disruption ExpectedThe Cyber Express · 15 Sept 2026, 12:35 pmUK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox FindsThe Cyber Express · 15 Sept 2026, 11:39 am