Advisory
Published 2026-09-02
Verified 2026-09-19
Gambling Goblin: malicious Apache modules on .gov.br sites push betting pages
The Hacker News (2 September 2026) reports Check Point Research tracking Chinese-speaking cluster Gambling Goblin since mid-2025 installing malicious Apache modules on compromised Brazilian government and education web servers. Modules reverse-proxy visitors to phishing pages that spoof Google Play, Microsoft Store and Amazon while stripping security headers, mainly to inflate SEO for online gambling. ANY.RUN had previously noted at least 20 .gov.br municipal and police portals abused in related distribution. Hunt for unexpected Apache modules/loadable objects, outbound reverse-proxy behaviour, and stripped CSP/HSTS on public sites.
- Product
- Apache HTTP Server (malicious modules)
- Exploited in Australia?
- unknown
- Patch to
- Audit LoadModule / module directories; rebuild from known-good packages; monitor reverse-proxy anomalies
Primary: The Hacker News (2 Sep 2026) ยท Vendor: Check Point Research (campaign cited by THN)
