Hackers Hijack Brazilian Government Websites to Manipulate Search Results

Cybercriminals have compromised Brazilian government websites and turned them into hidden platforms for phishing pages, gambling promotions, and search-engine manipulation.

Researchers at Check Point Research linked the activity to a Chinese-speaking threat group believed to be connected to Earth Berberoka, a cluster previously known for targeting online gambling operations in Asia.

The campaign has been active since mid-2025 and primarily targets Linux web servers. Instead of defacing sites or displaying obvious malicious content, the attackers quietly modify web-server behavior.

This lets them use trusted Brazilian government domains to host attacker-controlled pages without immediately alerting administrators or visitors.

The goal appears to be large-scale SEO abuse. By serving content from reputable .gov.br websites, the attackers can make malicious pages appear more trustworthy to search engines and users.

The tactic may help fraudulent gambling pages rank higher in search results and attract traffic from people looking for legitimate apps or online services.

Brazil Government Websites Hijacked

The attackers deploy custom Apache modules on compromised servers. These modules act as secret reverse proxies, meaning that selected requests to the real government website are silently forwarded to attacker infrastructure.

Researchers observed the modules reacting to specific URL paths, including /wps, /bmw, and /card.

Infection chain (Source: checkpoint)
Infection chain (Source: checkpoint)

When a visitor opens one of these paths, the compromised government site can load content from a remote attacker-controlled server while keeping the official domain name visible in the browser.

The malicious module also weakens browser protections. It removes the original Content-Security-Policy headers and replaces them with permissive rules.

This allows externally hosted scripts and injected content to load more easily, increasing the effectiveness of phishing and content-injection attacks.

Another module can inspect visitor details such as the requested URL, referrer, user-agent, and IP address. It can then decide which content to show.

This behavior is associated with SEO cloaking, where search-engine crawlers and normal users may receive different pages. Such filtering makes the campaign harder to detect because the malicious content may only appear under specific conditions.

CSP stripping so injected scripts can run (Source: checkpoint)
CSP stripping so injected scripts can run (Source: checkpoint)

The phishing pages impersonate well-known platforms, including Google Play, Microsoft Store, and Amazon.

They are written in Brazilian Portuguese and include fake ratings, reviews, and structured metadata designed to look legitimate to both visitors and search engines.

Many pages promote online gambling and sports-betting services aimed at Brazilian users. Researchers found Chinese-language comments in the page code and attacker scripts, providing another link to the group’s likely origin.

Some pages also use real Google-hosted assets, including Play Store styling and logos, to make fake download pages appear convincing, checkpoint said.

Indicators of Compromise

IOC TypeDefanged IndicatorObserved/Potential Role
Domainrb[.]aliyuntsl[.]comSuspected attacker infrastructure
Domainbr[.]team-c2[.]comSuspected command-and-control infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories