CTIPilot

Apache HTTP Server

product · product:apache-http-server

Coverage timeline
1
first 2026-09-03 → last 2026-09-03
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
deep-dive
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
17
pinned v19.2 · see below

ATT&CK techniques

17 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Resource Development TA0042

T1584.004Compromise Infrastructure: Server×1

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Persistence TA0003

T1543.002Create or Modify System Process: Systemd Service×1

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Privilege Escalation TA0004

T1543.002Create or Modify System Process: Systemd Service×1

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1070.006Indicator Removal: Timestomp×1

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1497.001Virtualization/Sandbox Evasion: System Checks×1

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Credential Access TA0006

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×1

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Discovery TA0007

T1046Network Service Discovery×1

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1497.001Virtualization/Sandbox Evasion: System Checks×1

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1614System Location Discovery×1

Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1572Protocol Tunneling×1

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

Story timeline

  1. 2026-09-03Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network
    deep-diveThe victim domain never changes in the browser bar, a hooked Apache module quietly reverse-proxies matching requests to attacker infrastructure

Where this entity is cited

  • deep-dive1

Source distribution

  • blog.checkpoint.com1 (33%)
  • infosecurity-magazine.com1 (33%)
  • research.checkpoint.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Apache HTTP Server (1)

2026-09-03 · view entry permalink →

NOTABLENATOB1

Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network

Check Point Research documents Gambling Goblin, a Chinese-speaking cluster it assesses with medium-to-high confidence overlaps Earth Berberoka, first documented by Trend Micro in 2022 targeting gambling platforms serving Chinese-speaking users. Active against Brazilian organisations since mid-2025, primarily government and educational institutions, the operation's distinguishing move is weaponising the search-engine trust of compromised .gov.br domains: navigation tiles on the resulting fraud pages point to dozens of real domains spanning a federal ministry, a national public agency, a state legislative assembly, state courts of accounts, a state utility, and numerous municipal administrations (Check Point Research, 2026-09-02). The technique (compromising a government web server to graft attacker content onto its own trusted domain) is directly transferable to any public-sector web-hosting estate, at any administrative tier, regardless of region.

On an already-compromised Linux host, a Bash installer confirms root, fingerprints the distribution, patches a missing macro, and compiles a custom Apache module (opsproxy.c) via apxs, then deletes the build artefacts and timestomps the resulting .so and its load configuration to match legitimate modules such as mod_ssl or mod_suexec (Check Point Research, 2026-09-02). The module registers at Apache's name-translation stage and inspects every incoming request for a small set of hardcoded URL prefixes (/wps, /bmw, /card in the analysed samples); a match rewrites the request into a reverse proxy to a hardcoded upstream, so the visitor is silently relayed to attacker infrastructure while the request still appears, from the outside, to originate from the legitimate compromised domain (Check Point Research, 2026-09-02). The module also strips the site's own Content-Security-Policy header and replaces it with a permissive one allowing inline/eval'd scripts and third-party assets, so the injected phishing content renders unrestricted. A second, separate Apache module disguises itself as a basic filter, decrypts an RC4-protected ruleset keyed on path/referrer/User-Agent/client-IP, locates the page body via a compiled-in <body.*?> regex, and injects fetched remote content via ap_rwrite, classic SEO-cloaking and content-injection behaviour, distinct from the reverse-proxy module (Check Point Research, 2026-09-02). The upstream phishing pages impersonate Google Play, Microsoft Store and Amazon with fabricated ratings and schema.org metadata, pushing gambling and sports-betting content.

Beyond the Apache modules, the group runs an internet-facing reconnaissance agent (a Go ELF binary wrapping dirprobe, httpx, naabu, nuclei v3, subfinder and whatweb over gRPC C2) to map attack surface, plus a downloader (DownPro) that stages the rest of the toolkit, blending its drop paths into names mimicking legitimate system binaries. Two backdoors carry Check Point's own attribution basis: oRAT, a Go RAT with an embedded SSH/SFTP server that persists as a systemd service disguised as the legitimate xtables-addons netfilter package, disables SELinux enforcement (setenforce 0) as part of its setup routine, and masquerades its process as sshd: root@pts/0, sharing the same orat/cmd/agent codebase and REST-style operator routes Check Point tied to Earth Berberoka in 2022 (Check Point Research, 2026-09-02). AlphaAgent, a modular Go backdoor using gRPC-over-HTTPS with browser-fingerprint mimicry (or a DNS covert channel) and bundling a SOCKS5 proxy and Ligolo-style relay for pivoting, was recovered from the same archive as tools already attributed to Earth Berberoka, placing it directly alongside the group's known toolset (Check Point Research, 2026-09-02). A third attribution point is infrastructure: the group's command-and-control shares Earth Berberoka's historical Amazon ASN (AS16509) (Check Point Research, 2026-09-02). A credential stealer built on the open-source 3snake project intercepts sshd/sudo/su/ssh/passwd/kinit/ login executions via netlink process-event monitoring and ptrace, masquerading as one of roughly 29 fake kernel-thread process names. Check Point states the model is already exported beyond Brazil: parallel phishing templates localised for Vietnamese, Spanish and English audiences, with daily domain generation.

No source describes how the group obtains its initial foothold on a target web server, the reporting begins from already-established root access. Defenders should read this as post-compromise infrastructure abuse, not an exploitation narrative to patch against.

Triage and hunting: a sudden absence of Content-Security-Policy headers on specific URL paths of a public-sector web server is a strong signal of injected reverse-proxy behaviour (Check Point Blog, 2026-09-02). Audit installed Apache modules for .so files timestamped to match legitimate modules such as mod_ssl or mod_suexec; a mismatch between a module's claimed identity and its actual behaviour is the core detection concept, not any single file name (Check Point Blog, 2026-09-02). Further behavioural artefacts a defender can hunt for without treating them as fixed indicators: a systemd service claiming to be xtables-addons that does not match the real package's binary; a process presenting as sshd but running from an unexpected path; unexplained apxs/module-compilation activity on a production web server outside a maintenance window; and process names drawn from common kernel-worker naming conventions (kworker, ksoftirqd, watchdog, journald) that do not correspond to genuine kernel threads when inspected further.

The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor

Check Point Blog 2026-09-02

We assess with medium-to-high confidence that Gambling Goblin is tied to Earth Berberoka

Check Point Research 2026-09-02

Audit Apache configurations and installed modules. Look for unexpected .so files, especially any timestamped to match legitimate modules like mod_ssl or mod_suexec.

Check Point Blog 2026-09-02

oRAT was tied to Earth Berberoka in 2022, and the variant we analyzed shares the same orat/cmd/agent codebase and REST-style operator routes

one of the AlphaAgent samples we recovered was uploaded in the same archive as other tools previously attributed to Earth Berberoka, placing AlphaAgent directly alongside the group's known toolset

Check Point Research 2026-09-02
threat03 Sep 05:15Zmulti-sourceOpen finding ↗