The government’s website was hacked not for the sake of data, but for SEO. The Chinese group builds a network of foreign reputations

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
873
Deposit
0$
When the domain reputation is valued above the content of the page, the state site becomes a ready advertising asset. The Chinese-language group Gambling Goblin has been hacking the servers of Brazilian departments and educational institutions since mid-2025 to promote gambling in the SERPs. Check Point linked the campaign to the Earth Berberoka group with medium or high confidence.

After infiltration, the attackers install the Apache self-written module. The component checks the address of the request, titles, the source of the transition and the IP of the visitor, and then discreetly gives the content from the server under the name of the real domain. Simultaneously, the module removes Content Security Policy restrictions, so third-party scripts are freely launched in the browser.

Fake pages copy Google Play, Microsoft Store, and Amazon, but advertise online casinos and betting. False ratings, reviews and markings schema.org give the showcases a compelling look. Links connect dozens of compromised .gov.br domains into a single network, and their accumulated reputation helps to raise pages in search results and intercept traffic.

Among the victims were the Federal Ministry, the State Agency, the Legislative Assembly, the monitoring bodies, municipalities and the state utility company. Similar pages in Vietnamese, Spanish and English show that the scheme is not limited to Brazil. Generators create new domains in return for the locked ones every day.

The group uses not only tools for search cheating. The servers found the DownPro bootloader, AlphaAgent and oRAT backdoors, an accounting interceptor and an SSH password management program. This set allows you to execute commands, steal keys, navigate the internal network and hide processes. The direct distribution of malicious applications has not yet been observed, although the infrastructure is already ready for substitution.

The method of initial penetration could not be established. Check Point points to outdated services available from the internet, weak SSH passwords and rarely inspected Apache modules, but does not link the campaign to a new vulnerability. Administrators are advised to update external services, check Apache and SSH settings, find unknown modules, disguised processes and other signs of compromise.
 
Top Bottom