Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO Attack
ID: be4272f9-cb2b-5956-ac3d-9ee6a9654096
STIX ID: report--be4272f9-cb2b-5956-ac3d-9ee6a9654096
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs discovered an active, large-scale SEO poisoning campaign that systematically claims abandoned cloud DNS delegations (primarily Azure, also DigitalOcean and orphaned wildcard records) to serve Thai-language gambling sites under 163 enterprise subdomains across 30+ countries. The operator automates zone claiming, obtains Let’s Encrypt wildcard certificates, routes content through OVH delivery nodes and a 103-node backend in Hong Kong, and monetizes via affiliate redirects that validate Thai-origin traffic; the report includes technical IOCs, detection rules, and remediation steps focused on DNS and CT monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
