Chinese‑Speaking Hackers Exploit Brazilian Gov and Academic Sites with Linux Malware and SEO Poisoning
Brazilian cyber‑defense officials have confirmed that a Chinese‑language criminal cluster linked to the Earth Berberoka threat actor has infiltrated a number of government and university web servers, using Linux‑based malware to launch a large‑scale SEO poisoning campaign and funnel users to illicit online‑gambling operations.
The attackers gained footholds on the compromised servers by exploiting outdated web‑application components and weak administrative credentials. Once inside, they installed custom Linux payloads that allowed persistent remote access while remaining largely invisible to standard security tools. The compromised hosts were then used to inject hidden links and scripts into the sites' publicly indexed pages.
SEO poisoning, the technique employed in the campaign, manipulates search‑engine results so that users searching for legitimate services are redirected to fraudulent pages. In this case, the malicious redirects pointed to gambling platforms that generated revenue for the operators through affiliate payouts and user betting activity. By leveraging trusted Brazilian domains, the group amplified the credibility of the fraudulent links, increasing click‑through rates and financial gain.
Threat‑intel analysts trace the operation back to mid‑2025, noting a steady escalation in both the number of compromised sites and the sophistication of the injected code. The campaign appears coordinated, with consistent malware signatures and command‑and‑control infrastructure across the affected servers, suggesting a centrally managed effort rather than isolated incidents.
While no public data breach has been reported, the intrusion raises concerns about potential exposure of internal communications and citizen information hosted on the targeted portals. Moreover, the redirection of traffic to gambling sites could undermine public trust in essential online services and impose indirect costs on the government through lost productivity and remediation expenses.
Brazil’s Computer Emergency Response Team (CERT‑BR) has issued advisories urging all public institutions to audit their web assets, apply security patches, and rotate privileged credentials. The Ministry of Justice has opened a formal investigation and is coordinating with international law‑enforcement partners to trace the command servers, which are believed to be located outside Brazil.
Security experts warn that the Earth Berberoka cluster could replicate this model against other countries with similar infrastructure weaknesses. They recommend adopting zero‑trust architectures, continuous monitoring of DNS and web traffic, and regular penetration testing to detect and disrupt such supply‑chain style attacks before they can be leveraged for profit.
Comments (0)
Be the first to comment.
Join the discussion