Cyber Security News

Malicious Apache Modules Turn Trusted Government Websites Into Stealth Phishing Proxies

Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious scam sites, attackers are using compromised web servers to make fraudulent content look legitimate immediately.

The campaign has targeted Brazilian government and education organizations since mid-2025. Operators deploy a Linux toolkit after gaining access, and use hijacked sites to promote gambling pages disguised as app-download services.

Check Point researchers identified the activity as the work of Gambling Goblin, a Chinese-speaking cybercrime cluster linked with medium-to-high confidence to Earth Berberoka.

Check Point said in a report shared with Cyber Security News (CSN) that the discovery signals a sharp change from Brazil’s largely domestic banking-trojan landscape to a foreign group exploiting public-sector trust.

Infection chain (Source – Check Point)

Trusted domains can boost malicious pages in search results, steer visitors toward fake stores, and make fraud seem official. Researchers also found similar templates in Vietnamese, Spanish, and English, suggesting an operation designed to expand.

Malicious Apache Modules

The attackers’ key tool is a custom Apache module compiled directly on an infected server. A Bash installer checks the operating system, installs the needed Apache development packages, retrieves the C source code, and uses Apache’s own tooling to build and activate the module.

To avoid raising alarms, the installer removes source and build files after deployment. It then changes timestamps on the malicious shared object and configuration files so they resemble ordinary Apache components. This makes a quick server review less likely to expose the intrusion.

One module watches for selected request paths and silently relays them to attacker infrastructure. Visitors remain on a genuine government domain but receive remote phishing content. It also removes browser content-security restrictions, allowing injected scripts and external assets to load.

CSP stripping so injected scripts can run (Source – Check Point)

A second module can inspect the path, referrer, browser details, and client address before deciding what content to display.

It can insert remote material into a web response, enabling selective cloaking and search manipulation. Similar abuse of official domains has appeared in government website phishing campaigns, where domain reputation helps criminal pages seem safe.

The pages observed in this campaign imitate Google Play, Microsoft Store, and Amazon-style download destinations. Fabricated ratings and page data help them look convincing, while the real business model appears to be gambling promotion.

A Toolkit Built for Reach and Evasion

Researchers did not directly observe the initial break-in, but uncovered a scanning agent called cam-agent on exposed infrastructure. It uses reconnaissance tools to map internet-facing systems. That can identify trusted web properties worth abusing.

Once inside, the group can use DownPro to fetch further payloads, including the ChUser backdoor, a password-harvesting tool, AlphaAgent, oRAT, and an SSH credential-testing utility.

Several tools use disguises, encryption, and memory-only unpacking, echoing tactics seen in Linux RAT attacks targeting developers.

AlphaAgent can run commands, move files, create tunnels, collect SSH keys and shell history, and hide under system-service names. oRAT can establish persistence through a service that mimics a legitimate firewall component.

These features support credential theft, movement inside networks, and long-term access. The infrastructure also creates new domains daily, to replace blocked locations.

Several phishing pages (Source – Check Point)

The report connects its tooling, Chinese-language artifacts, gambling focus, and lookalike-domain behavior to Earth Berberoka. Readers tracking this pattern can compare it with Brazilian government malware delivery and AI-driven phishing site cloning.

Public-sector and education administrators should urgently patch exposed services, review Apache modules and configuration changes, and audit SSH access for weak credentials or unusual login attempts.

They should investigate unfamiliar libraries, altered timestamps, proxy rules, and disguised processes. Administrators should compare loaded modules with approved baselines and verify that each reverse-proxy rule supports a legitimate application.

Teams should preserve logs before cleanup, reset exposed credentials, and inspect nearby systems across their environment for related tools.

The immediate campaign centers on search fraud and gambling traffic, but its fake app-store pages could easily deliver malware.

Organizations must treat a trusted domain as a possible victim, not automatic proof that a page is safe, and monitor public servers accordingly.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-256232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017Malware sample hash
SHA-256088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815Malware sample hash
SHA-25688544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0Malware sample hash
SHA-2569d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdbMalware sample hash
SHA-256263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31Malware sample hash
SHA-25612af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120dMalware sample hash
SHA-2565af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611Malware sample hash
SHA-256e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052Malware sample hash
SHA-256fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288dMalware sample hash
SHA-256c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98fMalware sample hash
SHA-2562567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91Malware sample hash
SHA-2561829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020aMalware sample hash
SHA-256f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcfMalware sample hash
SHA-2565a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8Malware sample hash
SHA-2560d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7Malware sample hash
SHA-2565f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710Malware sample hash
SHA-256c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69Malware sample hash
SHA-256c3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882Malware sample hash
SHA-256582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9Malware sample hash
SHA-2563a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdbMalware sample hash
SHA-25602f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6Malware sample hash
SHA-25616d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844Malware sample hash
SHA-256a71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162Malware sample hash
SHA-256d138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932bMalware sample hash
SHA-25644373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459fMalware sample hash
SHA-25645b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88Malware sample hash
SHA-2561eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9cMalware sample hash
SHA-256fc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3Malware sample hash
SHA-256adbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bcMalware sample hash
SHA-2560f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31eMalware sample hash
SHA-256ab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334eMalware sample hash
SHA-256ac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248Malware sample hash
SHA-25694aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84aMalware sample hash
SHA-2563ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1Malware sample hash
SHA-2560611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03eMalware sample hash
SHA-256114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0Malware sample hash
SHA-256297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7Malware sample hash
SHA-2560963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013dMalware sample hash
SHA-256749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52Malware sample hash
SHA-2568495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40cMalware sample hash
SHA-25698e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322Malware sample hash
SHA-256bcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838Malware sample hash
SHA-25624f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12Malware sample hash
SHA-2562de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035Malware sample hash
SHA-25652863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611Malware sample hash
SHA-2569d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fbMalware sample hash
SHA-256d478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4Malware sample hash
SHA-256b88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877Malware sample hash
SHA-256f4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063Malware sample hash
SHA-2562305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197cMalware sample hash
SHA-25699b5404df81992cad104dd242bc736d75fd6c58af34dc1cbf8a75a8ee3c5e1784fa4Malware sample hash
SHA-25685b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9aMalware sample hash
SHA-256cff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109Malware sample hash
SHA-256154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40Malware sample hash
SHA-25667ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9bMalware sample hash
SHA-256e8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76aMalware sample hash
SHA-256f32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1Malware sample hash
SHA-256c59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6Malware sample hash
SHA-2563537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820Malware sample hash
SHA-2562949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283Malware sample hash
SHA-2560e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133aMalware sample hash
SHA-2567d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3Malware sample hash
SHA-2568a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1Malware sample hash
SHA-25636cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8fMalware sample hash
SHA-256090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707eMalware sample hash
SHA-256fa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3Malware sample hash
SHA-256d948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cdMalware sample hash
SHA-256612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4cMalware sample hash
SHA-25696488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148Malware sample hash
Domainrb[.]aliyuntsl[.]comCommand-and-control or campaign infrastructure
Domainbr[.]team-c2[.]comCommand-and-control or campaign infrastructure
Domainhwlocal[.]team-hw[.]comCommand-and-control or campaign infrastructure
Domainbr[.]team-hw[.]comCommand-and-control or campaign infrastructure
Domaindata[.]mirrors-inc[.]comCommand-and-control or campaign infrastructure
Domainteam-hw[.]comCommand-and-control or campaign infrastructure
Domainupdate[.]team-c2[.]comCommand-and-control or campaign infrastructure
Domaindevops[.]aliyuntsl[.]comCommand-and-control or campaign infrastructure
Domainbageyi[.]kernel-lib[.]comCommand-and-control or campaign infrastructure
Domain8yiu[.]kernel-lib[.]comCommand-and-control or campaign infrastructure
Domaindnslog[.]kernel-lib[.]comCommand-and-control or campaign infrastructure
Domainjs[.]ai-jquery[.]comCommand-and-control or campaign infrastructure
Domainapi[.]onlinevrgame[.]comCommand-and-control or campaign infrastructure
Domainfile[.]ijjjst23m[.]comCommand-and-control or campaign infrastructure
Domainkerneltty[.]comCommand-and-control or campaign infrastructure
Domain80[.]443[.]teamCommand-and-control or campaign infrastructure
Domainup[.]443[.]teamCommand-and-control or campaign infrastructure
Domain404[.]443[.]teamCommand-and-control or campaign infrastructure
Domaindata[.]windows-update-cdn[.]comCommand-and-control or campaign infrastructure
Domainmicrosoft-azure-loadbalance[.]comCommand-and-control or campaign infrastructure
Domainupdate[.]aliyun[.]laCommand-and-control or campaign infrastructure
Domainapi[.]gitlab[.]betCommand-and-control or campaign infrastructure
Domaingithub[.]laLookalike campaign domain
Domainupdate[.]opentls2[.]comCommand-and-control or campaign infrastructure
IP Address154[.]84[.]62[.]160Campaign infrastructure
IP Address154[.]84[.]62[.]128Campaign infrastructure
IP Address154[.]84[.]62[.]149Campaign infrastructure
IP Address154[.]84[.]62[.]145Campaign infrastructure
IP Address15[.]228[.]251[.]82Campaign infrastructure
IP Address56[.]124[.]87[.]60Campaign infrastructure
IP Address18[.]229[.]255[.]14Campaign infrastructure
IP Address18[.]166[.]208[.]57Campaign infrastructure
IP Address18[.]228[.]136[.]28Campaign infrastructure
IP Address43[.]198[.]248[.]193Campaign infrastructure
IP Address43[.]199[.]133[.]195Campaign infrastructure
IP Address18[.]166[.]243[.]179Campaign infrastructure
IP Address18[.]164[.]116[.]24Campaign infrastructure
IP Address13[.]203[.]9[.]172Campaign infrastructure
IP Address43[.]198[.]30[.]170Campaign infrastructure
IP Address18[.]162[.]210[.]53Campaign infrastructure
IP Address56[.]125[.]218[.]234Campaign infrastructure
IP Address18[.]228[.]195[.]216Campaign infrastructure
IP Address56[.]124[.]49[.]89Campaign infrastructure
IP Address54[.]207[.]196[.]189Campaign infrastructure
IP Address165[.]22[.]101[.]200Campaign infrastructure
IP Address172[.]80[.]8[.]202Campaign infrastructure
IP Address104[.]206[.]37[.]134Campaign infrastructure
IP Address108[.]187[.]28[.]158Campaign infrastructure
IP Address202[.]146[.]222[.]18Campaign infrastructure
IP Address192[.]253[.]229[.]23Campaign infrastructure
IP Address16[.]162[.]255[.]92Campaign infrastructure
IP Address13[.]250[.]18[.]158Campaign infrastructure
IP Address18[.]163[.]182[.]231Campaign infrastructure
IP Address204[.]16[.]172[.]106Campaign infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago