Brazil is attracting new cybercriminals — and its government websites are becoming part of their campaigns
Analytics2026-09-09, 09:27
Almost simultaneously Check Point Research and Google Threat Intelligence Group published reports on two different financially motivated groups targeting Brazil. Their objectives and methods differ significantly, but they share one common feature: both use compromised government organization websites in their attacks.
First is the Gambling Goblin group. The primary victims were Brazilian government and educational organizations. After compromising Linux servers, the attackers installed malicious Apache modules that stealthily redirected visitors to pages under their control while preserving the appearance of a legitimate domain. Dozens of trusted Brazilian domains — primarily .gov.br — were used to promote pages masquerading as app stores and advertising online casinos and betting.
Second is the BREEZE COMET group. The group has been active since at least 2024 and primarily targets financial services, retail, and e-commerce. Its goal is to gain access to banking software and payment systems, including Pix, STR, and Boleto, in order to conduct fraudulent transfers. BREEZE COMET also used compromised websites belonging to small Brazilian government agencies, but this time to host remote-access tools, infostealers, and backdoors, as well as to support part of its C2 infrastructure. Trusted government infrastructure allowed the threat actors to avoid detection by network domain reputation filters.
At a broader level, Brazil remains one of the main targets for cybercriminals in the region. According to Recorded Future, by the end of 2025, the country's assessed risk of network intrusion had risen from Medium to Very High; Brazil became the most targeted country in Latin America and ranked among the world's top ten by ransomware victim count.
Both campaigns clearly illustrate the downside of Brazil's rapid digitalization. As the number of digital services and their role in the economy grow faster than the level of protection they receive, attackers gain more than just a larger pool of potential targets. Once compromised, inadequately protected government resources themselves become tools: trusted domains can be used to promote fraudulent content, distribute malware, and conceal C2 traffic. As a result, weak protection of even a relatively small government resource can create risks far beyond the organization itself.
Vendors
Products