
Findings and evidence
Check Point Research tracks a sustained campaign affecting Brazilian organizations, including government and educational sites. Its analysis connects altered web-serving behavior, a Linux malware toolkit and manipulation of trusted sites’ search visibility.
Why it matters
For web-server forensics, preserve configuration, loaded modules, content changes and access records together. A familiar domain name can remain visible even when the behavior behind it has changed.
Scope and limits
The researchers’ cluster and attribution assessments depend on observed overlaps. Unexpected search results alone do not identify the operator or establish the full compromise path.
Primary source
Check Point Research: original publication. Source published 2026-09-02. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.