Gambling Goblin Uses Compromised Brazilian Government Sites for SEO Phishing Campaign

Summary
Check Point Research details a campaign linked to Chinese-speaking actor Gambling Goblin that abuses compromised Brazilian sites to proxy phishing pages and manipulate search rankings, using Apache modules and a broad Linux malware toolkit.
Key points
- Researchers tracked the campaign against Brazilian organizations, especially government and educational institutions, since mid-2025; they assess with medium-to-high confidence that the actor is linked to Earth Berberoka.
- The group installs malicious Apache modules on compromised servers to proxy visitors to attacker-controlled pages and strip security headers, making the content appear to come from trusted domains.
- Phishing pages imitate app stores such as Google Play, Microsoft Store, and Amazon while promoting gambling and sports betting through SEO manipulation.
- The Linux toolkit includes the DownPro downloader, AlphaAgent and oRAT backdoors, a 3snake-based credential stealer, SSH brute-forcing, and reconnaissance tools.
- AlphaAgent supports encrypted command-and-control over gRPC/HTTPS or DNS, remote shells, file operations, tunneling, and credential and host-data collection.
- Researchers also found similar phishing networks localized for Vietnamese, Spanish, and English audiences, with infrastructure generating fresh domains daily.
- The report recommends patching exposed services, auditing Apache and SSH configurations, and hunting for rogue modules and disguised processes.
Article Details
- Attack Vectors
- Initial access was not directly observed. Researchers recovered an exposed reconnaissance agent with plugins for mapping internet-facing attack surfaces.
- After compromising web servers, the operators compile and install malicious modules that reverse-proxy selected URL paths to attacker infrastructure and weaken browser content-security restrictions.
- Response-filtering modules inject remotely fetched content into selected web responses, enabling SEO cloaking and gambling-page distribution through trusted domains.
- Fake app-store pages link together compromised high-reputation sites to manipulate search rankings and redirect visitor traffic.
- The toolkit includes concurrent SSH credential guessing, credential interception, remote shells, file transfer, and internal-network pivoting.
- Defensive Notes
- Patch exposed services and audit web-server and SSH configurations.
- Hunt for rogue web-server modules, unexpected module-loading configuration changes, and masqueraded processes.
- Do not treat timestamps matching legitimate modules as proof of legitimacy: the installer deliberately alters malicious-file timestamps.
- Inspect persistence through system-wide services, per-user services, and scheduled jobs.
- Consider encrypted DNS command traffic and browser-like TLS handshakes when investigating suspicious outbound communications.
- Direct malware distribution through the fake app-store pages was described as a potential escalation, not an observed outcome.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 404[.]443[.]team | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | 80[.]443[.]team | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | 8yiu[.]kernel-lib[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | api[.]gitlab[.]bet | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | api[.]onlinevrgame[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | bageyi[.]kernel-lib[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | br[.]team-c2[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | br[.]team-hw[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | data[.]mirrors-inc[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | data[.]windows-update-cdn[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | devops[.]aliyuntsl[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | dnslog[.]kernel-lib[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | file[.]ijjjst23m[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | github[.]la | Gambling Goblin lookalike infrastructure domain also listed in the IOC section. |
| DOMAIN | github[.]wiki | Domain previously attributed to Earth Berberoka by Trend Micro and cited as an infrastructure tradecraft overlap. |
| DOMAIN | gitlab[.]bet | Lookalike domain identified in Gambling Goblin infrastructure. |
| DOMAIN | hwlocal[.]team-hw[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | js[.]ai-jquery[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | kerneltty[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | microsoft-azure-loadbalance[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | playfootball[.]info | Phishing domain used by the second malicious Apache module to serve a fake app-store page. |
| DOMAIN | rb[.]aliyuntsl[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | team-hw[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | up[.]443[.]team | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | update[.]aliyun[.]la | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | update[.]opentls2[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| DOMAIN | update[.]team-c2[.]com | Threat-infrastructure domain listed in the Gambling Goblin IOC section. |
| IPV4 | 104[.]206[.]37[.]134 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 108[.]187[.]28[.]158 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 13[.]203[.]9[.]172 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 13[.]250[.]18[.]158 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 15[.]228[.]251[.]82 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 154[.]84[.]62[.]128 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 154[.]84[.]62[.]145 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 154[.]84[.]62[.]149 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 154[.]84[.]62[.]160 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 16[.]162[.]255[.]92 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 165[.]22[.]101[.]200 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 172[.]80[.]8[.]202 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]162[.]210[.]53 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]163[.]182[.]231 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]164[.]116[.]24 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]166[.]208[.]57 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]166[.]243[.]179 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]228[.]136[.]28 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]228[.]195[.]216 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 18[.]229[.]255[.]14 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 192[.]253[.]229[.]23 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 202[.]146[.]222[.]18 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 204[.]16[.]172[.]106 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 43[.]198[.]248[.]193 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 43[.]198[.]30[.]170 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 43[.]199[.]133[.]195 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 54[.]207[.]196[.]189 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 56[.]124[.]49[.]89 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 56[.]124[.]87[.]60 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| IPV4 | 56[.]125[.]218[.]234 | Threat-infrastructure IP address listed in the Gambling Goblin IOC section. |
| SHA256 | 02f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6 | Artifact hash listed in the research IOC section. |
| SHA256 | 0611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03e | Artifact hash listed in the research IOC section. |
| SHA256 | 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 | Artifact hash listed in the research IOC section. |
| SHA256 | 090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707e | Artifact hash listed in the research IOC section. |
| SHA256 | 0963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013d | Artifact hash listed in the research IOC section. |
| SHA256 | 0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7 | Artifact hash listed in the research IOC section. |
| SHA256 | 0e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133a | Artifact hash listed in the research IOC section. |
| SHA256 | 0f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31e | Artifact hash listed in the research IOC section. |
| SHA256 | 114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0 | Artifact hash listed in the research IOC section. |
| SHA256 | 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d | Artifact hash listed in the research IOC section. |
| SHA256 | 154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40 | Artifact hash listed in the research IOC section. |
| SHA256 | 16d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844 | Artifact hash listed in the research IOC section. |
| SHA256 | 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a | Artifact hash listed in the research IOC section. |
| SHA256 | 1eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9c | Artifact hash listed in the research IOC section. |
| SHA256 | 2305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197c | Artifact hash listed in the research IOC section. |
| SHA256 | 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 | Artifact hash listed in the research IOC section. |
| SHA256 | 24f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12 | Artifact hash listed in the research IOC section. |
| SHA256 | 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 | Artifact hash listed in the research IOC section. |
| SHA256 | 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 | Artifact hash listed in the research IOC section. |
| SHA256 | 2949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283 | Artifact hash listed in the research IOC section. |
| SHA256 | 297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7 | Artifact hash listed in the research IOC section. |
| SHA256 | 2de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035 | Artifact hash listed in the research IOC section. |
| SHA256 | 3537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820 | Artifact hash listed in the research IOC section. |
| SHA256 | 36cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8f | Artifact hash listed in the research IOC section. |
| SHA256 | 3a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdb | Artifact hash listed in the research IOC section. |
| SHA256 | 3ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1 | Artifact hash listed in the research IOC section. |
| SHA256 | 44373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459f | Artifact hash listed in the research IOC section. |
| SHA256 | 45b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88 | Artifact hash listed in the research IOC section. |
| SHA256 | 52863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611 | Artifact hash listed in the research IOC section. |
| SHA256 | 582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9 | Artifact hash listed in the research IOC section. |
| SHA256 | 5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8 | Artifact hash listed in the research IOC section. |
| SHA256 | 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 | Artifact hash listed in the research IOC section. |
| SHA256 | 5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710 | Artifact hash listed in the research IOC section. |
| SHA256 | 612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4c | Artifact hash listed in the research IOC section. |
| SHA256 | 67ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9b | Artifact hash listed in the research IOC section. |
| SHA256 | 749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52 | Artifact hash listed in the research IOC section. |
| SHA256 | 7d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3 | Artifact hash listed in the research IOC section. |
| SHA256 | 8495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40c | Artifact hash listed in the research IOC section. |
| SHA256 | 85b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9a | Artifact hash listed in the research IOC section. |
| SHA256 | 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 | Artifact hash listed in the research IOC section. |
| SHA256 | 8a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1 | Artifact hash listed in the research IOC section. |
| SHA256 | 94aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84a | Artifact hash listed in the research IOC section. |
| SHA256 | 96488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148 | Artifact hash listed in the research IOC section. |
| SHA256 | 98e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322 | Artifact hash listed in the research IOC section. |
| SHA256 | 99b5404df81992cad104dd242bc736d75fd6c58af34dc1a75a8ee3c5e1784fa4 | Artifact hash listed in the research IOC section. |
| SHA256 | 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb | Artifact hash listed in the research IOC section. |
| SHA256 | 9d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fb | Artifact hash listed in the research IOC section. |
| SHA256 | a71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162 | Artifact hash listed in the research IOC section. |
| SHA256 | ab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334e | Artifact hash listed in the research IOC section. |
| SHA256 | ac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248 | Artifact hash listed in the research IOC section. |
| SHA256 | adbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bc | Artifact hash listed in the research IOC section. |
| SHA256 | b88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877 | Artifact hash listed in the research IOC section. |
| SHA256 | bcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838 | Artifact hash listed in the research IOC section. |
| SHA256 | c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f | Artifact hash listed in the research IOC section. |
| SHA256 | c3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882 | Artifact hash listed in the research IOC section. |
| SHA256 | c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69 | Artifact hash listed in the research IOC section. |
| SHA256 | c59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6 | Artifact hash listed in the research IOC section. |
| SHA256 | cff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109 | Artifact hash listed in the research IOC section. |
| SHA256 | d138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932b | Artifact hash listed in the research IOC section. |
| SHA256 | d478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4 | Artifact hash listed in the research IOC section. |
| SHA256 | d948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cd | Artifact hash listed in the research IOC section. |
| SHA256 | e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 | Artifact hash listed in the research IOC section. |
| SHA256 | e8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76a | Artifact hash listed in the research IOC section. |
| SHA256 | f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf | Artifact hash listed in the research IOC section. |
| SHA256 | f32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1 | Artifact hash listed in the research IOC section. |
| SHA256 | f4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063 | Artifact hash listed in the research IOC section. |
| SHA256 | fa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3 | Artifact hash listed in the research IOC section. |
| SHA256 | fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d | Artifact hash listed in the research IOC section. |
| SHA256 | fc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3 | Artifact hash listed in the research IOC section. |
MITRE ATT&CK
T1003 · OS Credential DumpingPasswordHarvester attaches with ptrace to authentication processes and reads their credential buffers.T1014 · RootkitThe article describes AlphaAgent builds with a kernel-module component that hides processes and network connections, while noting that analyzed embedded rootkit slots contained placeholders.T1016 · System Network Configuration DiscoveryReconnaissance gathers interface addresses, active connections, local listening ports, and ARP neighbors.T1027.002 · Software PackingThe toolkit uses packing layers, and a protected AlphaAgent variant unpacks its payload only in memory.T1033 · System Owner/User DiscoveryAlphaAgent and info.sh inspect login records and current sessions to identify users of compromised hosts.T1036.004 · Masquerade Task or ServiceoRAT registers a systemd service named xtables-addons to resemble legitimate firewall tooling.T1036.005 · Match Legitimate Resource Name or LocationThe downloader and backdoors use system-like filenames and process names, including kernel-thread disguises and sshd: root@pts/0.T1041 · Exfiltration Over C2 ChannelPasswordHarvester sends intercepted credentials to C2, and AlphaAgent transfers collected files through its command channel.T1046 · Network Service DiscoveryoRAT exposes a victim-side port-scanning route, and reconnaissance scripts identify listening services and adjacent hosts.T1053.003 · CronoRAT supports a cron entry for per-user persistence.T1059.004 · Unix ShellA Bash installer deploys the malicious modules; AlphaAgent and oRAT execute operator commands through sh -c.T1070.003 · Clear Command HistoryAlphaAgent sets HISTFILE=/dev/null when executing shell commands to prevent shell-history recording.T1070.004 · File DeletionThe module installer deletes source and build artifacts; oRAT can delete its original binary after relocation.T1070.006 · TimestompThe installer timestamps malicious modules and load configurations to match legitimate files; DownPro timestamps ChUser to match /bin/ls.T1071.001 · Web ProtocolsAlphaAgent uses gRPC over HTTPS for jobs and results; oRAT exchanges HTTP routes through its established tunnel.T1071.004 · DNSAlphaAgent can exchange encrypted, Base32-encoded commands through DNS labels and TXT-style traffic on port 53.T1082 · System Information DiscoveryAlphaAgent and oRAT collect host details, including distribution, kernel, hostname, and virtualization information.T1083 · File and Directory DiscoveryAlphaAgent provides interactive directory listing, while info.sh walks user home directories and inventories .ssh folders.T1090.001 · Internal ProxyAlphaAgent and oRAT provide SOCKS proxies and connection forwarding through compromised hosts for internal-network pivoting.T1090.002 · External ProxyAlphaAgent supports a tunnel-edge relay role that forwards agent traffic upstream to the C2 server.T1105 · Ingress Tool TransferDownPro downloads and launches additional payloads, while the backdoors support uploading files to compromised hosts.T1110.001 · Password GuessingBruteForcer attempts concurrent SSH logins using supplied usernames, passwords, and user:pass pairs.T1113 · Screen CaptureoRAT provides an operator route to capture and return a screen image.T1140 · Deobfuscate/Decode Files or InformationAlphaAgent and oRAT decrypt embedded configuration at runtime; the second malicious module decrypts its static configuration with RC4.T1497.001 · System ChecksAlphaAgent collects virtualization hints and reports a virtualization-role field that can help operators identify analysis environments.T1497.003 · Time Based ChecksAlphaAgent sleeps for a randomized interval intended to outlast brief sandbox execution.T1505.004 · IIS ComponentsThe operators install malicious Apache modules that hook requests and responses to proxy or inject attacker content.T1543.002 · Systemd ServiceoRAT installs a boot-starting systemd service as root and falls back to a per-user service when system-wide installation is unavailable.T1548.001 · Setuid and SetgidDownPro deploys ChUser as a setuid helper intended to provide persistent local privilege escalation.T1552.001 · Credentials In Filesinfo.sh searches home directories for private-key files and other reusable secrets.T1552.003 · Shell Historyinfo.sh searches .bash_history for sensitive commands and credentials; AlphaAgent collects shell history.T1552.004 · Private KeysThe operators inventory private keys in .ssh folders, and AlphaAgent can archive those folders for exfiltration.T1560.001 · Archive via UtilityAlphaAgent compresses .ssh and .bash_history into an exfiltration bundle; oRAT can archive selected paths.T1562.001 · Disable or Modify ToolsoRAT disables SELinux enforcement with setenforce 0 during preparation.T1564.013 · Bind MountsAlphaAgent and oRAT can bind-mount over their own /proc entries to obstruct process inspection.T1565.001 · Stored Data ManipulationThe malicious Apache modules replace or inject content in compromised sites' responses to serve gambling pages and manipulate search visibility.T1572 · Protocol TunnelingAlphaAgent encapsulates command traffic in DNS and provides multiplexed relay tunnels; oRAT carries HTTP and embedded SSH through its C2 session.T1573.001 · Symmetric CryptographyAlphaAgent encrypts jobs and results with AES-GCM, while PasswordHarvester encrypts stolen credentials with RC4.T1595.001 · Scanning IP BlocksThe recovered cam-agent performs TCP port scanning against supplied internet-facing IP addresses and hostnames.T1595.002 · Vulnerability Scanningcam-agent includes nuclei workflows that execute template-defined HTTP, DNS, and TCP checks against external targets.T1622 · Debugger EvasionA protected AlphaAgent variant detects debuggers, displays a decoy error, and exits.
People
Threat Actors
Earth BerberokaPreviously documented Chinese-speaking threat cluster targeting gambling platforms. Researchers assess Gambling Goblin is tied to it with medium-to-high confidence based on tooling, operator artifacts, and infrastructure overlaps.Gambling GoblinCheck Point Research's name for the Chinese-speaking cybercrime cluster targeting Brazilian organizations since mid-2025. Researchers assess a connection to Earth Berberoka with medium-to-high confidence, rather than asserting an alias relationship.
Malware
3snaketools – downloader (DownPro), multiple backdoors including the modular AlphaAgent and the oRAT RAT, a 3snake-based credential stealer, an SSH brute-forcer, and a plugin-driven reconnaissance agent.AlphaAgenta host, the group deploys custom tools – downloader (DownPro), multiple backdoors including the modular AlphaAgent and the oRAT RAT, a 3snake-based credential stealer, an SSH brute-forcer, and a plugin-drivenChUserid – URL of the ChUser payloadDownProOnce inside a host, the group deploys custom tools – downloader (DownPro), multiple backdoors including the modular AlphaAgent and the oRAT RAT, a 3snake-based credential stealer, an SSH brute-forcer, and aoRATdeploys custom tools – downloader (DownPro), multiple backdoors including the modular AlphaAgent and the oRAT RAT, a 3snake-based credential stealer, an SSH brute-forcer, and a plugin-driven reconnaissance agent.PasswordHarvesterup – URL of the unix_updates payload (the PasswordHarvester)
Vendors
AmazonThe phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon.CloudflareGoogle and Cloudflare camouflage.GoogleThe phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon.ipinfoWhichever channel it uses, the agent bootstraps through public DoH and GeoIP providers such as Cloudflare, Google, ipinfo, and others, both to resolve its server and to run the geofence check described above.
Products
ApacheThe attackers compile and install malicious Apache modules on victim servers that silently reverse-proxy visitors to attacker-controlled phishing pages, while the traffic still appears to originate from the legitimateDockera storage analysis that hunts for remote network mounts (NFS, CIFS/Samba, WebDAV, cloud FUSE) and Docker volumes while deliberately filtering out overlay, tmpfs, and container-ID noise, so the operator seesGoogle PlayThe phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon.LinuxA broad, heavily obfuscated Linux toolkit.Microsoft StoreThe phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon.NGINXWhen not running as root, it falls back to php-fpm: pool www or nginx: worker process.SELinuxIt configures logging to /dev/null by default, daemonizes, disables SELinux enforcement (setenforce 0), installs itself to a persistent location, registers a service, writes a GUID, takes a file lock so only one copysystemd/usr/local/bin/systemd-udevd
Tools
cam-agentThe group refers to this agent as “cluster-asset-mapping”, or “cam-agent” for short.dirprobedirprobe – takes URLs and a directory list or profile, sends HTTP requests, and records the status code, response length, and title for each probed path.findweb.shThe second script, findweb.sh, surveys a compromised host’s web-server landscape and maps out every site it serves.fscantwo kinds of tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader, severalhttpxhttpx – takes URLs, ports, and HTTP options, then collects the status code, response length, title, protocol, TLS details, and banners from each target.info.shThe first, info.sh, proceeds in four stages.Ligolo-ng4 server parameters SocksProxy (using Ligolo-ng)naabunaabu – takes IPs or hostnames, port ranges, and a scan mode, attempts TCP connections across all targets, and marks each port as open, closed, or filtered.netcatdraws on two kinds of tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader,Nucleinuclei (v3) – takes URLs, paths, and workflows, executes HTTP/DNS/TCP checks as defined by templates, and emits a structured result for each match (template ID, severity, affected URL, evidence).pwnkitof tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader, several backdoors, asubfindersubfinder – takes root domains, resolvers, and a depth, then enumerates subdomains via DNS brute force, certificate transparency, and passive sources, returning the discovered subdomains.whatwebwhatweb – a Wappalyzer-style fingerprinter that issues HTTP requests to each target and applies rules to identify web servers, frameworks, CMS platforms, JavaScript libraries, and more.
Countries
Industries
EducationGovernmentGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponHealthcareNews mediaonline gamblingBehind that facade, they push online gambling and sports betting, and they chain together compromised high-reputation domains, many of them Brazilian government sites, to inflate search rankings and hijack traffic atUtilitiesOnce inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, and familiar offensive utilities.