Earth Berberoka Turns Government Sites Into Phishing Relays

Check Point Research says a Chinese-speaking actor tied to Earth Berberoka has run a sustained campaign since mid-2025 that abuses compromised Brazilian government sites, and a second network aimed at Vietnamese victims. The group uses those public domains as part of its delivery chain instead of just defacing them. On the victim servers, the actor installs a Linux toolkit and custom Apache modules that proxy visitors to phishing pages. Because the pages sit behind trusted, high-reputation domains, they can rank better in search and look safer to users, while cleanup focused only on the site itself leaves the phishing infrastructure and borrowed reputation partly intact. For Brazilian government web teams and local SOCs, the key shift is that a compromised site can become attacker infrastructure, not just a damaged asset. If public-facing domains feed search traffic or login journeys, a single foothold can distort trust and keep driving victims long after the visible compromise is removed.

Part of the PlainSec briefing for 2026-09-02

Every edition of this story: Earth Berberoka Turns Government Sites Into Phishing Relays

Sources