Chinese-language gang hijacks .gov.br sites to push online betting fraud in Brazil
Check Point Research says a Chinese-speaking cybercrime group it calls “Gambling Goblin” has been compromising Brazilian government servers to manipulate Google search results and funnel users to fake pages promoting online and sports betting. For PSPs and acquirers, the detail that matters is simple: official domains are being used as trust signals for fraud at scale.
- According to Check Point Research, the group targets servers under the
.gov.brdomain, including a ministry, a federal public agency, a legislative assembly, state audit courts, and dozens of city halls. The compromised pages are then used to boost search rankings and push traffic to fraudulent pages. - Those pages imitate major app stores such as Google Play, Microsoft Store, and Amazon, but in practice promote online gambling and sports betting. The campaign has been monitored by CPR since mid-2025, and it already appears in Vietnamese, Spanish, and English.
- CPR says the operators use an automated system that creates new domains every day to stay ahead of blocks. The group is linked to the “Earth Berberoka” cluster, which has previously been associated with attacks on the betting sector in Asia.
- Christine Hoepers, general manager of CERT.br, said there is “nothing” that Registro.br can do in these cases. Her point was technical: the problem sits in the configuration of the compromised servers, not in the domain registry itself.
- The Brazilian government told TecMundo that CTIR Gov did not receive reports of data leaks affecting citizens or public servants in the incidents described by CPR. The GSI also said fixing the technical issue is each affected agency’s responsibility, while CTIR Gov can only provide initial technical guidance.
TecMundo also reported that most of the incidents identified by Check Point were in city halls, and that this kind of server hijacking to manipulate search traffic had already triggered a CTIR Gov recommendation in 2024. The same report says the attackers are using artificial intelligence to automate parts of the operation, and that Brazil is the group’s main market.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!