Advisory
Published 2026-09-02
Verified 2026-09-19

Gambling Goblin: malicious Apache modules on .gov.br sites push betting pages

The Hacker News (2 September 2026) reports Check Point Research tracking Chinese-speaking cluster Gambling Goblin since mid-2025 installing malicious Apache modules on compromised Brazilian government and education web servers. Modules reverse-proxy visitors to phishing pages that spoof Google Play, Microsoft Store and Amazon while stripping security headers, mainly to inflate SEO for online gambling. ANY.RUN had previously noted at least 20 .gov.br municipal and police portals abused in related distribution. Hunt for unexpected Apache modules/loadable objects, outbound reverse-proxy behaviour, and stripped CSP/HSTS on public sites.

Product
Apache HTTP Server (malicious modules)
Exploited in Australia?
unknown
Patch to
Audit LoadModule / module directories; rebuild from known-good packages; monitor reverse-proxy anomalies

Primary: The Hacker News (2 Sep 2026) ยท Vendor: Check Point Research (campaign cited by THN)

vulnerabilities network