B
今週中
中国語圏のサイバー犯罪グループ「Gambling Goblin」が、ブラジルの政府機関や教育機関のWebサーバーに悪意のあるApacheモジュールをインストール…
📌 一言でいうと
中国語圏のサイバー犯罪グループ「Gambling Goblin」が、ブラジルの政府機関や教育機関のWebサーバーに悪意のあるApacheモジュールをインストールし、トラフィックをオンラインギャンブルサイトへリダイレクトさせる攻撃を展開しています。このモジュールはリバースプロキシとして機能し、正規ドメインのままフィッシングページへ誘導し、Google Playなどの偽ストアを介してギャンブルアプリを推進します。主な目的は、高評価の政府ドメインを利用した大規模なSEO操作であると分析されています。
🔍該当判定
- 自社で Apache HTTP Server を利用して Web サイトを公開している
- Web サーバーの管理権限を持つユーザーが、身に覚えのない Apache モジュール(.soファイル)を追加・変更した形跡がある
- 自社サイトにアクセスした際、意図せずオンラインカジノやスポーツベッティングなどのギャンブルサイトへ転送される
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Webサーバー上のApacheモジュールの整合性確認、不審なモジュールの削除、およびサーバーへの不正アクセスログの監視を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Apacheモジュールを悪用したトラフィックハイジャック攻撃について
お疲れさまです。Gambling Goblinによる攻撃キャンペーンに関する情報共有です。
■ 概要
攻撃者が侵害したWebサーバーに悪意のあるApacheモジュールを導入し、リバースプロキシとして機能させることで、ユーザーを正規ドメインのままギャンブル系フィッシングサイトへ誘導する手法が確認されています。セキュリティヘッダーを削除し、偽のアプリストア(Google Play等)を介して不正アプリを配布しています。
■ 影響範囲
- Apache HTTP Server を運用しているWebサーバー
- 特に高評価ドメインを運用する組織(政府・教育機関等)
■ 対応手順
1. インストールされているApacheモジュールの一覧を確認し、身に覚えのない、または不審なバイナリが存在しないか検証してください。
2. Webサーバーのアクセスログおよび設定ファイルの変更履歴を確認し、不正なリダイレクト設定やモジュールの追加がないか調査してください。
3. サーバーの特権管理権限の監査を行い、侵害の痕跡がないか確認してください。
■ 参考情報
- Check Point Research / ANY.RUN レポート
対応優先度: 中
対応期限: 速やかに確認
お疲れさまです。Gambling Goblinによる攻撃キャンペーンに関する情報共有です。
■ 概要
攻撃者が侵害したWebサーバーに悪意のあるApacheモジュールを導入し、リバースプロキシとして機能させることで、ユーザーを正規ドメインのままギャンブル系フィッシングサイトへ誘導する手法が確認されています。セキュリティヘッダーを削除し、偽のアプリストア(Google Play等)を介して不正アプリを配布しています。
■ 影響範囲
- Apache HTTP Server を運用しているWebサーバー
- 特に高評価ドメインを運用する組織(政府・教育機関等)
■ 対応手順
1. インストールされているApacheモジュールの一覧を確認し、身に覚えのない、または不審なバイナリが存在しないか検証してください。
2. Webサーバーのアクセスログおよび設定ファイルの変更履歴を確認し、不正なリダイレクト設定やモジュールの追加がないか調査してください。
3. サーバーの特権管理権限の監査を行い、侵害の痕跡がないか確認してください。
■ 参考情報
- Check Point Research / ANY.RUN レポート
対応優先度: 中
対応期限: 速やかに確認
Subject: [Info] Traffic Hijacking via Malicious Apache Modules
Dear team,
We are sharing information regarding a campaign by the threat actor 'Gambling Goblin'.
■ Overview
Attackers are installing malicious Apache modules on compromised servers to act as reverse proxies. This allows them to divert traffic to gambling-related phishing pages while the URL remains that of the legitimate domain. They also strip security headers to ensure the injected content runs without interference.
■ Scope
- Web servers running Apache HTTP Server
- Organizations managing high-reputation domains
■ Action Plan
1. Audit installed Apache modules for any unauthorized or suspicious binaries.
2. Review web server access logs and configuration files for unauthorized changes or redirection rules.
3. Perform a privilege audit on the server to identify potential compromise vectors.
■ Reference
- Check Point Research / ANY.RUN reports
Priority: Medium
Deadline: Immediate review
Dear team,
We are sharing information regarding a campaign by the threat actor 'Gambling Goblin'.
■ Overview
Attackers are installing malicious Apache modules on compromised servers to act as reverse proxies. This allows them to divert traffic to gambling-related phishing pages while the URL remains that of the legitimate domain. They also strip security headers to ensure the injected content runs without interference.
■ Scope
- Web servers running Apache HTTP Server
- Organizations managing high-reputation domains
■ Action Plan
1. Audit installed Apache modules for any unauthorized or suspicious binaries.
2. Review web server access logs and configuration files for unauthorized changes or redirection rules.
3. Perform a privilege audit on the server to identify potential compromise vectors.
■ Reference
- Check Point Research / ANY.RUN reports
Priority: Medium
Deadline: Immediate review