Gambling Goblin Uses Compromised Brazilian Government Sites for SEO Phishing Campaign

· Original article ↗

Summary

Check Point Research details a campaign linked to Chinese-speaking actor Gambling Goblin that abuses compromised Brazilian sites to proxy phishing pages and manipulate search rankings, using Apache modules and a broad Linux malware toolkit.

Key points

  • Researchers tracked the campaign against Brazilian organizations, especially government and educational institutions, since mid-2025; they assess with medium-to-high confidence that the actor is linked to Earth Berberoka.
  • The group installs malicious Apache modules on compromised servers to proxy visitors to attacker-controlled pages and strip security headers, making the content appear to come from trusted domains.
  • Phishing pages imitate app stores such as Google Play, Microsoft Store, and Amazon while promoting gambling and sports betting through SEO manipulation.
  • The Linux toolkit includes the DownPro downloader, AlphaAgent and oRAT backdoors, a 3snake-based credential stealer, SSH brute-forcing, and reconnaissance tools.
  • AlphaAgent supports encrypted command-and-control over gRPC/HTTPS or DNS, remote shells, file operations, tunneling, and credential and host-data collection.
  • Researchers also found similar phishing networks localized for Vietnamese, Spanish, and English audiences, with infrastructure generating fresh domains daily.
  • The report recommends patching exposed services, auditing Apache and SSH configurations, and hunting for rogue modules and disguised processes.

Article Details

Attack Vectors
  • Initial access was not directly observed. Researchers recovered an exposed reconnaissance agent with plugins for mapping internet-facing attack surfaces.
  • After compromising web servers, the operators compile and install malicious modules that reverse-proxy selected URL paths to attacker infrastructure and weaken browser content-security restrictions.
  • Response-filtering modules inject remotely fetched content into selected web responses, enabling SEO cloaking and gambling-page distribution through trusted domains.
  • Fake app-store pages link together compromised high-reputation sites to manipulate search rankings and redirect visitor traffic.
  • The toolkit includes concurrent SSH credential guessing, credential interception, remote shells, file transfer, and internal-network pivoting.
Defensive Notes
  • Patch exposed services and audit web-server and SSH configurations.
  • Hunt for rogue web-server modules, unexpected module-loading configuration changes, and masqueraded processes.
  • Do not treat timestamps matching legitimate modules as proof of legitimacy: the installer deliberately alters malicious-file timestamps.
  • Inspect persistence through system-wide services, per-user services, and scheduled jobs.
  • Consider encrypted DNS command traffic and browser-like TLS handshakes when investigating suspicious outbound communications.
  • Direct malware distribution through the fake app-store pages was described as a potential escalation, not an observed outcome.

Indicators of compromise

TypeIndicatorContext
DOMAIN404[.]443[.]teamThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAIN80[.]443[.]teamThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAIN8yiu[.]kernel-lib[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINapi[.]gitlab[.]betThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINapi[.]onlinevrgame[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINbageyi[.]kernel-lib[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINbr[.]team-c2[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINbr[.]team-hw[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINdata[.]mirrors-inc[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINdata[.]windows-update-cdn[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINdevops[.]aliyuntsl[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINdnslog[.]kernel-lib[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINfile[.]ijjjst23m[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINgithub[.]laGambling Goblin lookalike infrastructure domain also listed in the IOC section.
DOMAINgithub[.]wikiDomain previously attributed to Earth Berberoka by Trend Micro and cited as an infrastructure tradecraft overlap.
DOMAINgitlab[.]betLookalike domain identified in Gambling Goblin infrastructure.
DOMAINhwlocal[.]team-hw[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINjs[.]ai-jquery[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINkerneltty[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINmicrosoft-azure-loadbalance[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINplayfootball[.]infoPhishing domain used by the second malicious Apache module to serve a fake app-store page.
DOMAINrb[.]aliyuntsl[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINteam-hw[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINup[.]443[.]teamThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINupdate[.]aliyun[.]laThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINupdate[.]opentls2[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
DOMAINupdate[.]team-c2[.]comThreat-infrastructure domain listed in the Gambling Goblin IOC section.
IPV4104[.]206[.]37[.]134Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4108[.]187[.]28[.]158Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV413[.]203[.]9[.]172Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV413[.]250[.]18[.]158Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV415[.]228[.]251[.]82Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4154[.]84[.]62[.]128Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4154[.]84[.]62[.]145Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4154[.]84[.]62[.]149Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4154[.]84[.]62[.]160Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV416[.]162[.]255[.]92Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4165[.]22[.]101[.]200Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4172[.]80[.]8[.]202Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]162[.]210[.]53Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]163[.]182[.]231Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]164[.]116[.]24Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]166[.]208[.]57Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]166[.]243[.]179Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]228[.]136[.]28Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]228[.]195[.]216Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV418[.]229[.]255[.]14Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4192[.]253[.]229[.]23Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4202[.]146[.]222[.]18Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV4204[.]16[.]172[.]106Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV443[.]198[.]248[.]193Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV443[.]198[.]30[.]170Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV443[.]199[.]133[.]195Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV454[.]207[.]196[.]189Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV456[.]124[.]49[.]89Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV456[.]124[.]87[.]60Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
IPV456[.]125[.]218[.]234Threat-infrastructure IP address listed in the Gambling Goblin IOC section.
SHA25602f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6Artifact hash listed in the research IOC section.
SHA2560611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03eArtifact hash listed in the research IOC section.
SHA256088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815Artifact hash listed in the research IOC section.
SHA256090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707eArtifact hash listed in the research IOC section.
SHA2560963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013dArtifact hash listed in the research IOC section.
SHA2560d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7Artifact hash listed in the research IOC section.
SHA2560e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133aArtifact hash listed in the research IOC section.
SHA2560f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31eArtifact hash listed in the research IOC section.
SHA256114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0Artifact hash listed in the research IOC section.
SHA25612af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120dArtifact hash listed in the research IOC section.
SHA256154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40Artifact hash listed in the research IOC section.
SHA25616d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844Artifact hash listed in the research IOC section.
SHA2561829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020aArtifact hash listed in the research IOC section.
SHA2561eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9cArtifact hash listed in the research IOC section.
SHA2562305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197cArtifact hash listed in the research IOC section.
SHA256232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017Artifact hash listed in the research IOC section.
SHA25624f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12Artifact hash listed in the research IOC section.
SHA2562567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91Artifact hash listed in the research IOC section.
SHA256263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31Artifact hash listed in the research IOC section.
SHA2562949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283Artifact hash listed in the research IOC section.
SHA256297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7Artifact hash listed in the research IOC section.
SHA2562de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035Artifact hash listed in the research IOC section.
SHA2563537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820Artifact hash listed in the research IOC section.
SHA25636cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8fArtifact hash listed in the research IOC section.
SHA2563a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdbArtifact hash listed in the research IOC section.
SHA2563ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1Artifact hash listed in the research IOC section.
SHA25644373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459fArtifact hash listed in the research IOC section.
SHA25645b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88Artifact hash listed in the research IOC section.
SHA25652863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611Artifact hash listed in the research IOC section.
SHA256582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9Artifact hash listed in the research IOC section.
SHA2565a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8Artifact hash listed in the research IOC section.
SHA2565af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611Artifact hash listed in the research IOC section.
SHA2565f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710Artifact hash listed in the research IOC section.
SHA256612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4cArtifact hash listed in the research IOC section.
SHA25667ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9bArtifact hash listed in the research IOC section.
SHA256749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52Artifact hash listed in the research IOC section.
SHA2567d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3Artifact hash listed in the research IOC section.
SHA2568495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40cArtifact hash listed in the research IOC section.
SHA25685b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9aArtifact hash listed in the research IOC section.
SHA25688544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0Artifact hash listed in the research IOC section.
SHA2568a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1Artifact hash listed in the research IOC section.
SHA25694aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84aArtifact hash listed in the research IOC section.
SHA25696488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148Artifact hash listed in the research IOC section.
SHA25698e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322Artifact hash listed in the research IOC section.
SHA25699b5404df81992cad104dd242bc736d75fd6c58af34dc1a75a8ee3c5e1784fa4Artifact hash listed in the research IOC section.
SHA2569d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdbArtifact hash listed in the research IOC section.
SHA2569d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fbArtifact hash listed in the research IOC section.
SHA256a71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162Artifact hash listed in the research IOC section.
SHA256ab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334eArtifact hash listed in the research IOC section.
SHA256ac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248Artifact hash listed in the research IOC section.
SHA256adbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bcArtifact hash listed in the research IOC section.
SHA256b88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877Artifact hash listed in the research IOC section.
SHA256bcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838Artifact hash listed in the research IOC section.
SHA256c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98fArtifact hash listed in the research IOC section.
SHA256c3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882Artifact hash listed in the research IOC section.
SHA256c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69Artifact hash listed in the research IOC section.
SHA256c59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6Artifact hash listed in the research IOC section.
SHA256cff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109Artifact hash listed in the research IOC section.
SHA256d138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932bArtifact hash listed in the research IOC section.
SHA256d478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4Artifact hash listed in the research IOC section.
SHA256d948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cdArtifact hash listed in the research IOC section.
SHA256e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052Artifact hash listed in the research IOC section.
SHA256e8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76aArtifact hash listed in the research IOC section.
SHA256f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcfArtifact hash listed in the research IOC section.
SHA256f32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1Artifact hash listed in the research IOC section.
SHA256f4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063Artifact hash listed in the research IOC section.
SHA256fa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3Artifact hash listed in the research IOC section.
SHA256fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288dArtifact hash listed in the research IOC section.
SHA256fc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3Artifact hash listed in the research IOC section.

MITRE ATT&CK

T1003 · OS Credential DumpingPasswordHarvester attaches with ptrace to authentication processes and reads their credential buffers.T1014 · RootkitThe article describes AlphaAgent builds with a kernel-module component that hides processes and network connections, while noting that analyzed embedded rootkit slots contained placeholders.T1016 · System Network Configuration DiscoveryReconnaissance gathers interface addresses, active connections, local listening ports, and ARP neighbors.T1027.002 · Software PackingThe toolkit uses packing layers, and a protected AlphaAgent variant unpacks its payload only in memory.T1033 · System Owner/User DiscoveryAlphaAgent and info.sh inspect login records and current sessions to identify users of compromised hosts.T1036.004 · Masquerade Task or ServiceoRAT registers a systemd service named xtables-addons to resemble legitimate firewall tooling.T1036.005 · Match Legitimate Resource Name or LocationThe downloader and backdoors use system-like filenames and process names, including kernel-thread disguises and sshd: root@pts/0.T1041 · Exfiltration Over C2 ChannelPasswordHarvester sends intercepted credentials to C2, and AlphaAgent transfers collected files through its command channel.T1046 · Network Service DiscoveryoRAT exposes a victim-side port-scanning route, and reconnaissance scripts identify listening services and adjacent hosts.T1053.003 · CronoRAT supports a cron entry for per-user persistence.T1059.004 · Unix ShellA Bash installer deploys the malicious modules; AlphaAgent and oRAT execute operator commands through sh -c.T1070.003 · Clear Command HistoryAlphaAgent sets HISTFILE=/dev/null when executing shell commands to prevent shell-history recording.T1070.004 · File DeletionThe module installer deletes source and build artifacts; oRAT can delete its original binary after relocation.T1070.006 · TimestompThe installer timestamps malicious modules and load configurations to match legitimate files; DownPro timestamps ChUser to match /bin/ls.T1071.001 · Web ProtocolsAlphaAgent uses gRPC over HTTPS for jobs and results; oRAT exchanges HTTP routes through its established tunnel.T1071.004 · DNSAlphaAgent can exchange encrypted, Base32-encoded commands through DNS labels and TXT-style traffic on port 53.T1082 · System Information DiscoveryAlphaAgent and oRAT collect host details, including distribution, kernel, hostname, and virtualization information.T1083 · File and Directory DiscoveryAlphaAgent provides interactive directory listing, while info.sh walks user home directories and inventories .ssh folders.T1090.001 · Internal ProxyAlphaAgent and oRAT provide SOCKS proxies and connection forwarding through compromised hosts for internal-network pivoting.T1090.002 · External ProxyAlphaAgent supports a tunnel-edge relay role that forwards agent traffic upstream to the C2 server.T1105 · Ingress Tool TransferDownPro downloads and launches additional payloads, while the backdoors support uploading files to compromised hosts.T1110.001 · Password GuessingBruteForcer attempts concurrent SSH logins using supplied usernames, passwords, and user:pass pairs.T1113 · Screen CaptureoRAT provides an operator route to capture and return a screen image.T1140 · Deobfuscate/Decode Files or InformationAlphaAgent and oRAT decrypt embedded configuration at runtime; the second malicious module decrypts its static configuration with RC4.T1497.001 · System ChecksAlphaAgent collects virtualization hints and reports a virtualization-role field that can help operators identify analysis environments.T1497.003 · Time Based ChecksAlphaAgent sleeps for a randomized interval intended to outlast brief sandbox execution.T1505.004 · IIS ComponentsThe operators install malicious Apache modules that hook requests and responses to proxy or inject attacker content.T1543.002 · Systemd ServiceoRAT installs a boot-starting systemd service as root and falls back to a per-user service when system-wide installation is unavailable.T1548.001 · Setuid and SetgidDownPro deploys ChUser as a setuid helper intended to provide persistent local privilege escalation.T1552.001 · Credentials In Filesinfo.sh searches home directories for private-key files and other reusable secrets.T1552.003 · Shell Historyinfo.sh searches .bash_history for sensitive commands and credentials; AlphaAgent collects shell history.T1552.004 · Private KeysThe operators inventory private keys in .ssh folders, and AlphaAgent can archive those folders for exfiltration.T1560.001 · Archive via UtilityAlphaAgent compresses .ssh and .bash_history into an exfiltration bundle; oRAT can archive selected paths.T1562.001 · Disable or Modify ToolsoRAT disables SELinux enforcement with setenforce 0 during preparation.T1564.013 · Bind MountsAlphaAgent and oRAT can bind-mount over their own /proc entries to obstruct process inspection.T1565.001 · Stored Data ManipulationThe malicious Apache modules replace or inject content in compromised sites' responses to serve gambling pages and manipulate search visibility.T1572 · Protocol TunnelingAlphaAgent encapsulates command traffic in DNS and provides multiplexed relay tunnels; oRAT carries HTTP and embedded SSH through its C2 session.T1573.001 · Symmetric CryptographyAlphaAgent encrypts jobs and results with AES-GCM, while PasswordHarvester encrypts stolen credentials with RC4.T1595.001 · Scanning IP BlocksThe recovered cam-agent performs TCP port scanning against supplied internet-facing IP addresses and hostnames.T1595.002 · Vulnerability Scanningcam-agent includes nuclei workflows that execute template-defined HTTP, DNS, and TCP checks against external targets.T1622 · Debugger EvasionA protected AlphaAgent variant detects debuggers, displays a decoy error, and exits.

People

Threat Actors

Malware

Vendors

Products

Tools

cam-agentThe group refers to this agent as “cluster-asset-mapping”, or “cam-agent” for short.dirprobedirprobe – takes URLs and a directory list or profile, sends HTTP requests, and records the status code, response length, and title for each probed path.findweb.shThe second script, findweb.sh, surveys a compromised host’s web-server landscape and maps out every site it serves.fscantwo kinds of tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader, severalhttpxhttpx – takes URLs, ports, and HTTP options, then collects the status code, response length, title, protocol, TLS details, and banners from each target.info.shThe first, info.sh, proceeds in four stages.Ligolo-ng4 server parameters SocksProxy (using Ligolo-ng)naabunaabu – takes IPs or hostnames, port ranges, and a scan mode, attempts TCP connections across all targets, and marks each port as open, closed, or filtered.netcatdraws on two kinds of tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader,Nucleinuclei (v3) – takes URLs, paths, and workflows, executes HTTP/DNS/TCP checks as defined by templates, and emits a structured result for each match (template ID, severity, affected URL, evidence).pwnkitof tooling: well-known offensive utilities that any attacker might reach for, such as netcat, fscan, and pwnkit, and a broad set of custom tools written by the operators themselves: a downloader, several backdoors, asubfindersubfinder – takes root domains, resolvers, and a depth, then enumerates subdomains via DNS brute force, certificate transparency, and passive sources, returning the discovered subdomains.whatwebwhatweb – a Wappalyzer-style fingerprinter that issues HTTP requests to each target and applies rules to identify web servers, frameworks, CMS platforms, JavaScript libraries, and more.

Countries

Industries

Related Articles