Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-speaking threat actor has been identified compromising high-authority government and educational websites in Brazil to facilitate a sophisticated phishing operation. According to security researchers at Dark Reading, the attackers are leveraging these legitimate, trusted domains to host a reverse-proxy network. This infrastructure is primarily used to redirect unsuspecting users to gambling-themed phishing sites, effectively bypassing traditional security filters that often grant higher trust scores to government-affiliated URLs. By embedding their malicious content within these compromised servers, the cybercriminals increase the likelihood of successful credential theft and malware distribution. Security experts warn that this technique highlights the growing trend of threat actors exploiting the reputation of public sector infrastructure to evade detection. Organizations are advised to monitor their network traffic for unauthorized redirects and to implement stricter integrity checks on web server configurations to prevent similar unauthorized access.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
As AI agents increasingly automate content creation and publishing, the risk of accidental credential exposure becomes a critical security concern. A…
PT ESC cyber intelligence specialists have identified a series of attacks targeting Russian organizations, including defense industry enterprises, fin…
In the modern internet landscape, using a Web Application Firewall (WAF) has become an essential standard for securing digital resources. This article…



