
highCyber Attacks
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Promote Betting Pages
A Chinese-speaking cybercrime cluster identified as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers belonging to Brazilian government and educational institutions. These modules divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research has tracked the campaign since mid-2025, with modules observed in September 2026. The exact exploitation vector and specific module names remain under investigation.
The Hacker News1 min read