logo

Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO Attack

ID: be4272f9-cb2b-5956-ac3d-9ee6a9654096

STIX ID: report--be4272f9-cb2b-5956-ac3d-9ee6a9654096

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-06-12

Date Updated: 2026-07-17

...
...

Cyble Research & Intelligence Labs discovered an active, large-scale SEO poisoning campaign that systematically claims abandoned cloud DNS delegations (primarily Azure, also DigitalOcean and orphaned wildcard records) to serve Thai-language gambling sites under 163 enterprise subdomains across 30+ countries. The operator automates zone claiming, obtains Let’s Encrypt wildcard certificates, routes content through OVH delivery nodes and a 103-node backend in Hong Kong, and monetizes via affiliate redirects that validate Thai-origin traffic; the report includes technical IOCs, detection rules, and remediation steps focused on DNS and CT monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.