logo

Cloud DNS Takeover Powers Thai Gambling Campaign

ID: 9c1993db-3fc6-51ae-a6fa-5b12ec199a43

STIX ID: report--9c1993db-3fc6-51ae-a6fa-5b12ec199a43

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Do Son

...
...

## Executive Summary Cyble Research uncovered a global SEO-poisoning campaign in which a suspected single operator claims abandoned cloud DNS delegations (mainly Azure) to host Thai gambling content under trusted corporate subdomains, compromising 163 organizations across 30+ countries; the attacker uses Let’s Encrypt wildcard certificates, a standardized Next.js gambling kit, a 103-node Hong Kong backend, and geographic filtering to target Thai users and evade scanners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.