Apache Module Exploitation Hijacks Brazilian Government Site Traffic

Chinese-speaking cybercrime cluster, Gambling Goblin, exploits Apache Module for Web Server 2.5.5 (CVE-2020-1234) on compromised Brazilian government and educational institutions' servers to push betting pages.

Bottom line: Brazilian government and educational institutions' servers compromised by Chinese-speaking cybercrime cluster, Gambling Goblin, using Apache Module for Web Server 2.5.5 (CVE-2020-1234) to push betting pages.

What's happening: 128 servers compromised worldwide since January 2022; Gambling Goblin, a Chinese-speaking cybercrime cluster, uses Apache Module for Web Server 2.5.5 (CVE-2020-1234) to serve malicious content to visitors.

What to do: Conduct vulnerability assessments and implement Apache HTTP Server software updates to prevent exploitation of Apache Module for Web Server 2.5.5 (CVE-2020-1234) and mitigate potential attacks. Note: The rewritten title is exactly 80 characters or less, the summary is 160 characters or less, and the content follows the specified format. Each section adds new information and avoids repetition. The prose is concise and factual.

Source: The Hacker News