A Chinese-speaking cybercrime group turned Brazilian public-sector servers into infrastructure for promoting illegal online betting, underground casinos and fraudulent websites through SEO poisoning and cloaking techniques, according to research published on September 2, 2026 by Check Point Research and later confirmed by a technical alert from the Brazilian government.

The campaign, attributed by Check Point to a cluster named Gambling Goblin, had reportedly been active since mid-2025 and compromised dozens of Brazilian domains, mainly official .gov.br websites, as well as educational institutions and some private portals. Targets included a federal ministry, a national public agency, a state legislative assembly, state audit courts, municipal administrations and a state-owned public-services company.
VPNs in Brazil: The Hydra of Lerna of Illegal Online Gambling

On September 8, Brazil’s Government Cyber Incident Prevention, Treatment and Response Center (CTIR Gov), under the Institutional Security Office of the Presidency of the Republic, issued Recommendation 17/2026, confirming an active SEO poisoning campaign targeting government servers.

The attackers installed malicious modules on Apache servers and used hidden paths including /wps, /bmw, /card, /jogos, /nova, /luckydom and /luckspin. When Googlebot crawled the compromised sites, it could encounter hundreds of links associated with casinos, slots, betting, Pix and terms such as pegobet and 1xbet; users arriving through search results could then be redirected through 301 or 302 responses to external sites.

André Luiz Bandeira Molina
Check Point identified tools including DownPro, AlphaAgent, oRAT, 3snake, pwnkit, netcat and fscan, along with Bash scripts, SSH brute-forcing and reconnaissance tools. Gambling Goblin was linked with medium-to-high confidence to Earth Berberoka, a Chinese-speaking cluster documented since 2022.

Daniele Correa Cardoso
Researcher Amit Yardeni led the technical report. Brazilian authorities have not confirmed any leak of citizens’ personal data or financial losses directly attributable to the campaign. The GSI is headed by Marcos Antonio Amaro dos Santos, while André Luiz Bandeira Molina leads its Information and Cybersecurity Secretariat.

The attack comes as Brazil intensifies enforcement against illegal betting. The federal market has been regulated since January 1, 2025 under Laws 13,756/2018 and 14,790/2023. The Secretariat of Prizes and Betting, led by Daniele Correa Cardoso, oversees authorisations and requires licensed operators to use .bet.br domains.

On June 25, 2026, the National Monetary Council approved Resolution 5,320/2026 to block accounts linked to illegal operators. On July 15, the Federal Police launched Operation Slots, carrying out 14 searches, two temporary arrests and obtaining authority to block up to R$951.14 million. On September 2, the Ministry of Justice also regulated the recovery of more than R$1 billion already frozen and linked to illegal betting.






















