
Gambling Goblin Apache modules proxy .gov.br traffic to unlicensed betting fronts since mid-2025
Malicious Apache modules on Brazilian government servers silently redirect visitors to gambling phishing pages while preserving domain trust. Tool reuse ties the activity to Earth Berberoka with no public IOCs released for detection. The campaign exploits post-legalization betting demand and high-reputation domains for SEO manipulation.
The modules act as transparent proxies that preserve the original .gov.br or .jus.br domain in the address bar while serving attacker-controlled betting content. Check Point identified the toolkit stack as DownPro downloader, AlphaAgent backdoor, oRAT, a 3snake credential stealer, and an SSH brute-forcer; the public 3snake GitHub code confirms ptrace attachment to sshd and sudo for password extraction on rooted hosts. No module filenames, paths, or hashes were released, leaving administrators without IOCs to scan loaded Apache instances.
Evidence trails link the cluster to Trend Micro's 2022 Earth Berberoka reporting through oRAT v0.5.1 binaries and Xnote Linux backdoor reuse documented in March 2026 against Asian critical infrastructure. ANY.RUN's July 16 report separately flagged at least 20 .gov.br portals used in PhantomEnigma malware distribution, noting these hosts form part of the delivery chain rather than primary targets. Parallel Vietnamese, Spanish, and English phishing networks with daily domain generation indicate a multi-language SEO operation.
Brazil's January 2025 legalization of fixed-odds betting under Law 14,790/2023 created demand for .bet.br domains, yet Check Point provides no evidence the promoted sites hold Registro.br authorization. The absence of initial-access vectors and server counts in public reporting leaves open whether exposed directories or supply-chain compromises enabled the foothold. Operators now sit one step from direct malware delivery via the same app-store facades.
Next steps require defenders to extract loaded Apache modules from running processes on .gov.br infrastructure and cross-reference against Trend Micro and Check Point samples; broad blocking of government domains would disrupt legitimate access, so selective takedowns of the proxy endpoints are required.
Check Point: at least 30 additional .gov.br or .jus.br hosts will show the same proxy modules by December 2026 if no module hashes are published
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html)
- [2]Supporting Source(https://www.trendmicro.com/en_us/research/22/a/earth-berberoka-gambling-websites.html)
- [3]Supporting Source(https://any.run/cybersecurity-blog/phantom-enigma-campaign/)