Interestana
Home/News/Malicious Apache Modules Hijack Brazilian Government Site Traffic
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Malicious Apache Modules Hijack Brazilian Government Site Traffic

Malicious Apache Modules Hijack Brazilian Government Site Traffic

A cybercrime group identified as Gambling Goblin has been actively exploiting vulnerabilities to install malicious Apache modules on web servers belonging to Brazilian government and educational institutions. These compromised servers are then used to redirect unsuspecting visitors to attacker-controlled websites that promote online gambling and sports betting. Check Point Research, a cybersecurity firm, has been monitoring this campaign since mid-2025, observing its persistent efforts to monetize compromised infrastructure through illicit means. The primary objective of this operation appears to be the redirection of traffic from legitimate, trusted government and educational domains to fraudulent betting platforms, thereby generating revenue for the cybercriminals.

The modus operandi involves the deployment of custom-built Apache modules, which are designed to intercept and alter web traffic originating from the compromised servers. Once installed, these modules can manipulate requests and responses, effectively rerouting users who attempt to access legitimate government services or educational resources to pages controlled by Gambling Goblin. This tactic leverages the trust associated with government and educational websites to lure users into engaging with the betting sites, which may involve deceptive practices or outright scams. The use of Apache modules suggests a sophisticated understanding of web server architecture and a targeted approach to exploiting specific environments.

Check Point Research's analysis indicates that the campaign has been ongoing since at least mid-2025, highlighting the sustained nature of the threat and the challenges in detecting and mitigating such attacks. The group's focus on Brazilian government and educational entities suggests a strategic targeting of sectors that typically experience high website traffic and may have varying levels of cybersecurity maturity. By compromising these servers, Gambling Goblin gains access to a broad audience, increasing the potential reach of their malicious redirection scheme. The ultimate goal is to profit from the increased traffic and potential sign-ups or deposits made on the promoted betting platforms.

The implications of this campaign extend beyond mere traffic diversion. It raises significant concerns regarding data security and user privacy for individuals who interact with these compromised websites. While the primary aim is financial gain through betting promotion, the underlying compromise of government and educational infrastructure could potentially expose sensitive information or facilitate further malicious activities. The ongoing nature of the threat underscores the critical need for enhanced cybersecurity measures within these sectors to prevent such exploitation and protect both institutional integrity and user trust.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next