Cybersecurity researchers have uncovered a sprawling scam operation that hijacks Brazilian government websites to trick visitors into landing on fake Google Play, Microsoft Store, and Amazon pages, all in service of pushing online gambling and sports betting.
The campaign, detailed in a new report from Check Point Research, has been active since mid-2025 and is attributed to a Chinese-speaking cybercrime group the researchers have named “Gambling Goblin.” The group is linked to Earth Berberoka, a cluster previously documented targeting gambling websites across Asia, suggesting a decade-long pattern of gambling-driven fraud that is now expanding into new markets.
According to the report, the attackers break into legitimate Brazilian government web servers, spanning federal, state and municipal institutions, and install hidden software that silently reroutes visitors to attacker-controlled phishing pages. Crucially, the browser’s address bar continues to display the legitimate government URL throughout, making the redirect invisible to the average visitor.
Those phishing pages are dressed up to look like Google Play, the Microsoft Store and Amazon, complete with fabricated ratings and reviews. But rather than offering real apps, they funnel visitors toward gambling and sports betting platforms. By routing traffic through high-reputation government domains, the operators are able to manipulate search engine rankings and drive far more traffic to their gambling sites than a standalone scam page could achieve on its own.
Researchers describe the underlying toolkit as unusually sophisticated for a fraud operation. Once inside a compromised server, the group deploys a broad set of custom Linux tools, including a downloader, multiple backdoors, a credential-stealing utility, and a reconnaissance agent used to map out other vulnerable internet-facing systems. Much of the software is deliberately obfuscated to slow down security analysts.
More from Cybersecurity
- Hackers Shut Down A UK Power Plant – Are Cyberattacks Moving From Data Theft to Physical Interruption?
- ChatGPT Can Now Read Your iMessages – Does This Break The Implicit Contract Of End-to-End Encryption?
- Vega Introduces Detection Skills A New Open Standard For AI Reasoning in Agentic Cyber Defence
- OpenAI Launches Private Misuse Tracking – How Can It Detect Misuse Without Storing Sensitive Enterprise Data?
- Premier League Clubs Face £100,000 Fines Under New Mandatory Cybersecurity Rules
- Schools And Universities Are Now The Most Hacked Organisations In The World
- France’s Tax Agency Lost 678,000 Accounts To A Cyberattack – How Will SaaS Fight AI-Accelerated Breaches?
- How RuView Tracks Human Movement And Breathing Without Cameras – Is Your Home Already Watching You?
Check Point Research says the scheme is not confined to Brazil. Investigators found parallel versions of the same fake-app-store network built for Vietnamese, Spanish, and English-speaking audiences, along with infrastructure that generates new scam domains every day, evidence, researchers say, that the operation is designed to be exported to new regions rather than run as a one-off campaign.
Perhaps most concerning is how little would need to change for the scam to escalate. Because the fraudulent pages already mimic legitimate app download destinations, researchers warn the same infrastructure could be repurposed with a single configuration change to distribute real malicious apps instead of gambling redirects, turning a search-ranking scam into a direct malware delivery channel.
Brazil in particular, makes an attractive target. The country has become one of the world’s fastest-growing online betting markets, with a large base of mobile users accustomed to installing apps directly from search results. That combination of a receptive audience and under-secured, high-trust government infrastructure gives the operators exactly the conditions they need to scale.
The report marks a notable shift for Brazil’s threat landscape, which has historically been dominated by home-grown banking trojan groups rather than foreign, gambling-focused operators. Researchers say the case blurs the line between financially motivated cybercrime and more sophisticated, espionage-style operations, given the depth of the tooling involved.
Check Point Research is urging public sector IT teams to audit their Apache server configurations for unfamiliar modules, watch for web pages that are unexpectedly missing standard security headers, and treat their domains’ search engine reputation as an asset worth actively protecting.
