Cloud DNS Takeover Powers Thai Gambling Campaign
ID: 9c1993db-3fc6-51ae-a6fa-5b12ec199a43
STIX ID: report--9c1993db-3fc6-51ae-a6fa-5b12ec199a43
Feed Name: securityonline.info
Threat Score
## Executive Summary Cyble Research uncovered a global SEO-poisoning campaign in which a suspected single operator claims abandoned cloud DNS delegations (mainly Azure) to host Thai gambling content under trusted corporate subdomains, compromising 163 organizations across 30+ countries; the attacker uses Let’s Encrypt wildcard certificates, a standardized Next.js gambling kit, a 103-node Hong Kong backend, and geographic filtering to target Thai users and evade scanners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
