Check Point Research describes Gambling Goblin, a Chinese-speaking cybercrime group linked to Earth Berberoka, as running a sustained campaign against Brazilian government and educational organizations since mid-2025. The operation uses malicious Apache modules, SEO manipulation, and a large Linux toolkit to hijack traffic, serve phishing pages that impersonate Google Play, Microsoft Store, and Amazon, and scale into Vietnamese, Spanish, and English targeting. #GamblingGoblin #EarthBerberoka #Apache #GooglePlay #MicrosoftStore #Amazon
Keypoints
- Check Point Research attributes the campaign to a Chinese-speaking cluster dubbed Gambling Goblin and links it to Earth Berberoka.
- The main victims in Brazil are government and educational organizations, with many compromised .gov.br domains used as traffic relays.
- The attackers deploy malicious Apache modules that reverse-proxy selected requests to attacker-controlled phishing infrastructure.
- The phishing pages impersonate trusted app stores and are used for SEO manipulation and gambling traffic monetization.
- The group uses a broad Linux toolkit including DownPro, ChUser, PasswordHarvester, AlphaAgent, and oRAT, plus brute-force and reconnaissance utilities.
- The infrastructure is built for scale, with daily domain generation and localized phishing pages in Vietnamese, Spanish, and English.
- The same infrastructure could be repurposed for direct malware delivery with only a configuration change.
MITRE Techniques
- [T1105 ] Ingress Tool Transfer â The actors download and deploy custom components and payloads onto victim systems, including Apache module source and Linux toolkit binaries (âIt downloads the moduleâs C source, opsproxy.c, from a hardcoded staging serverâ / âit downloads a file to /usr/bin/chuserâ).
- [T1059.004 ] Command and Scripting Interpreter: Unix Shell â Bash scripts and shell commands are used for installation, execution, and administration of malware (âvia a Bash installerâ / âruns it with /bin/sh -câ).
- [T1505.003 ] Server Software Component: Web Shell â Malicious Apache modules are installed on web servers to inject or relay attacker content (âcompile and install malicious Apache modulesâ / âa purpose-built reverse proxyâ).
- [T1090.002 ] Proxy: External Proxy â Compromised servers act as stealth reverse proxies that forward visitors to phishing pages (âsilently reverse-proxy visitors to attacker-controlled phishing pagesâ).
- [T1027 ] Obfuscated Files or Information â Malware and scripts are heavily obfuscated with packing, virtualization, encryption, and RC4/AES-GCM protection (âwrapped in packing and virtualization layersâ / âdecrypts it with RC4â / âAES-GCM encryptedâ).
- [T1036 ] Masquerading â Tools disguise themselves as legitimate binaries, services, or system components (âsystemd-udevdâ, âxtables-addonsâ, âsshd: root@pts/0â).
- [T1070.006 ] File and Directory Discovery: Timestomp â The module and payloads timestomp files to match legitimate Apache components (âtimestomps the resulting .so and its load-configuration filesâ).
- [T1016 ] System Network Configuration Discovery â Reconnaissance scripts and agents enumerate network interfaces, ARP neighbors, listening ports, and IPs (âgathers classic lateral-movement intelligenceâ / âinterface addressesâ / âlocal listening TCP portsâ).
- [T1046 ] Network Service Discovery â The cam-agent, nuclei, naabu, and related tools scan hosts, ports, and services (âtakes IPs or hostnames, port rangesâ / âportscanâ).
- [T1110.001 ] Brute Force: Password Guessing â The BruteForcer utility attempts SSH logins with supplied usernames and passwords (âattempts concurrent SSH loginsâ).
- [T1056.001 ] Input Capture: Keylogging â PasswordHarvester intercepts credentials by attaching to authentication programs and reading credential buffers (âmonitors newly executed authentication programsâ / âreads the credential buffersâ).
- [T1021.004 ] Remote Services: SSH â The malware targets SSH sessions and also provides an embedded SSH server for operator access (âsshdâ, âssh sessionsâ / âembedded SSH serverâ).
- [T1098 ] Account Manipulation â ChUser and setuid helper behavior support privileged access and persistence (âturning it into a setuid helper that serves as a persistent local privilege-escalation backdoorâ).
- [T1070.004 ] Indicator Removal: File Deletion â Installer scripts remove source and build artifacts after deployment (âthe script deletes the source and all build artifactsâ).
- [T1070.001 ] Indicator Removal: Clear Windows Event Logs â The group suppresses traces through logging redirection and cleanup-like behavior on Linux (âwrites to /dev/nullâ / âredirecting stdout and stderr to a fileâ / âdeletes its original on-disk copyâ).
- [T1095 ] Non-Application Layer Protocol â The agent uses DNS and gRPC tunnels as alternate communication channels (âcommands travel inside DNS queriesâ / âgRPC over HTTPSâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â C2 and payload traffic are hidden inside HTTPS and HTTP-like web traffic (âgRPC over HTTPSâ / âplain HTTP connectionâ).
- [T1132.001 ] Data Encoding: Standard Encoding â Jobs are Base32/Base64-encoded before transport in DNS and C2 channels (âencrypted, Base32-encodedâ / âRC4-encrypted and Base64-encodedâ).
- [T1112 ] Modify Registry or Configuration â The actors alter security-relevant configuration on Linux systems, including Apache settings, SELinux, and service entries (âdisables SELinux enforcementâ / âwires the module into the serverâs configurationâ).
- [T1204.002 ] User Execution: Malicious File â Payloads are executed after being downloaded and staged on the host (âdownloads a file ⌠and executes itâ).
- [T1562.001 ] Impair Defenses: Disable or Modify Tools â The Apache module strips CSP headers and oRAT disables SELinux to weaken defenses (âstrips the upstream siteâs Content-Security-Policy headersâ / âdisables SELinux enforcementâ).
- [T1018 ] Remote System Discovery â The tools enumerate hosts, domains, users, and services across environments (âhostname, users, running services, active network connectionsâ).
- [T1021.001 ] Remote Services: Remote Desktop Protocol â No direct RDP is mentioned; not applicable.
- [T1219 ] Remote Access Software â AlphaAgent and oRAT function as remote access backdoors with shells, file transfer, tunneling, and proxying (âremote shell and interactive terminalâ / âREST-style routesâ / âproxyOpen a SOCKS proxyâ).
Indicators of Compromise
- [File hashes ] multiple malware samples and tooling binaries â 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017, 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815, and other 70+ hashes
- [Domains ] phishing, C2, and staging infrastructure â rb[.]aliyuntsl[.]com, br[.]team-c2[.]com, update[.]team-c2[.]com, api[.]gitlab[.]bet, github[.]la, update[.]opentls2[.]com, and other domains
- [IP addresses ] malicious hosting and proxy infrastructure â 154[.]84[.]62[.]160, 18[.]229[.]255[.]14, 43[.]198[.]248[.]193, 204[.]16[.]172[.]106, and other IPs
- [File names ] malware components and scripts â opsproxy.c, payload-run.log, chuser, unix_updates, info.sh, findweb.sh
- [Paths ] persistence, hiding, and payload locations â /usr/local/bin/systemd-udevd, /usr/bin/chuser, /usr/sbin/unix_updates, /tmp/asset-scan, /etc/protocols
- [URLs / endpoints ] operator and agent communications â /join, /agent/heartbeat, /notifications/v1/push, /agent/exec, /agent/upload, /agent/download