Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Summary
A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been compromising Brazilian government and educational web servers. They install malicious Apache modules to redirect visitors to websites promoting online gambling and sports betting.
IFF Assessment
FOE
The identified threat actor is engaging in malicious activity by hijacking web server traffic for financial gain, posing a threat to the integrity and security of the affected institutions.
Defender Context
This campaign highlights the ongoing threat of supply chain attacks and the importance of securing web server configurations, particularly Apache modules. Defenders should monitor for unusual traffic redirection and unauthorized module installations on critical infrastructure.