It appears that you are describing an advanced cyberattack campaign involving the compromise of government websites in Brazil to serve phishing content aimed at Brazilian users interested in gambling and sports betting. The attackers have developed sophisticated tools including custom Apache modules to inject malicious content into legitimate web pages, thereby bypassing security measures like Content Security Policy (CSP). Here's a summary of key points from your description:
Key Components of the Attack
-
Custom Apache Modules:
- A reverse proxy module that silently redirects requests for specific URL paths to attacker-controlled servers while maintaining the appearance of legitimate traffic.
- Another module that injects content into responses based on predefined rules, allowing attackers to serve customized phishing pages.
-
Phishing Infrastructure:
- The compromised websites redirect users to phishing pages hosted on IP addresses in Brazil.
- These phishing pages are designed to mimic legitimate app distribution platforms (e.g., Google Play and Microsoft Store) but focus on gambling content targeted at Brazilian audiences.
-
Content Injection Mechanisms:
- The modules strip CSP headers from responses, allowing inline scripts and external resources to be loaded freely.
- They inject placeholders into HTML responses that are later replaced with actual phishing content fetched via `libcurl
Read the full article at Check Point Research
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



