CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

September 2, 2026

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages Swati KhandelwalSep 02, 2026Web Security / Malware A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely. Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon,…