<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages]]></title><description><![CDATA[<p dir="auto">A Chinese-speaking threat actor, tracked as <em>Gambling Goblin</em>, is compromising Apache web servers at Brazilian government and educational institutions to redirect legitimate visitors toward attacker-controlled pages promoting online gambling and sports betting.</p>
<p dir="auto">According to <strong>Check Point Research</strong>, this campaign has been active since <em>mid-2025</em>. The attackers deploy malicious Apache modules on the compromised servers, allowing them to intercept and reroute traffic without altering the core website files, making detection by standard file integrity checks less straightforward.</p>
<p dir="auto">Key technical details of the operation include:</p>
<ul>
<li>The malicious modules are specifically designed for Apache HTTP Server, enabling request-level redirection.</li>
<li>The target set includes domains ending in <code>.gov.br</code> and academic institutions, reflecting a focus on high-traffic, authoritative sites.</li>
<li>The ultimate aim of the redirection is monetization via illegal betting page impressions and potential credential or payment data harvesting on the landing pages.</li>
</ul>
<p dir="auto">The main risk here is that unsuspecting users who trust these official domains may be exposed to phishing-style lures for gambling services, which could also lead to financial fraud. Check Point researchers emphasize that these module injections are difficult to spot without regular server-level log audits and binary analysis of loaded modules.</p>
<p dir="auto">For defenders, the following mitigation steps are recommended:</p>
<ul>
<li>Conduct regular reviews of loaded Apache modules (<code>httpd -M</code>) to spot unfamiliar entries.</li>
<li>Monitor server access logs for unusual patterns of redirect responses (3xx) to external domains.</li>
<li>Ensure that web server binaries and module directories are under strict file integrity monitoring (e.g., Tripwire or AIDE).</li>
<li>Keep Apache and all associated libraries patched to the latest versions to close known privilege escalation routes.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given that these attacks leverage legitimate server infrastructure rather than user-side exploits, how is your organization auditing its Apache module integrity and detecting unauthorized outbound redirects?</p>
]]></description><link>https://xploitlk.com/topic/233/malicious-apache-modules-hijack-brazilian-government-site-traffic-to-push-betting-pages</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:28:00 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/233.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 04:30:22 GMT</pubDate><ttl>60</ttl></channel></rss>