A cybercrime group known as Gambling Goblin has been exploiting compromised Brazilian government and educational websites since mid-2025 for an SEO fraud campaign. Check Point Research linked the group to Earth Berberoka, previously documented for targeting gambling platforms. The attackers used custom Apache modules to reroute visitors to phishing pages for online gambling, affecting a range of governmental and commercial entities.
Their operations included a Linux malware toolkit for remote access and reconnaissance, with phishing pages localized for various languages. Researchers cautioned about potential malware distribution through this infrastructure.