Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content

Borrowed Trust – Systematic Exploitation of Abandoned Cloud DNS Delegations to serve Thai Gambling SEO Content

Cyble reports an SEO poisoning campaign that hijacked abandoned cloud DNS delegations to serve Thai gambling content from 163 compromised organizations across 30+ countries. The operation relied on Azure DNS zone takeovers, a smaller set of DigitalOcean and wildcard misconfiguration cases, and a monetization stack tied to OVH delivery nodes, a Hong Kong backend fleet, and affiliate infrastructure such as link99 and ibiza99vip1. #Azure #DigitalOcean #Verizon #OVH #PEGTECHINC #brokerxm #link99 #ibiza99vip1

Keypoints

  • Cyble identified an active Thai gambling SEO poisoning campaign abusing abandoned cloud DNS delegations.
  • The campaign compromised 163 organizations across more than 30 countries, including government, healthcare, finance, critical infrastructure, and universities.
  • The main technique was Azure DNS zone takeover, where abandoned delegated zones were reclaimed under a new Azure subscription.
  • Two additional compromises involved DigitalOcean DNS takeovers, while others used direct wildcard DNS misconfigurations or per-subdomain A records.
  • The delivery layer used three OVH-hosted IPs and Next.js gambling pages with valid Let’s Encrypt certificates to appear legitimate under victim domains.
  • The monetization layer used affiliate parameters, Thai-only server-side filtering, and a multi-tier referral structure centered on link99.
  • A separate 103-node backend fleet in Hong Kong was attributed to a single Chinese operator through multiple technical evidence points.

MITRE Techniques

  • [T1583.003 ] Acquire Infrastructure – The actor used rented and hosted infrastructure for delivery and backend operations, including OVH nodes and the Hong Kong fleet (‘OVH VPS for delivery; PEG TECH INC ASN for backend fleet’).
  • [T1584 ] Compromise Infrastructure – The campaign took over legitimate enterprise DNS infrastructure by reclaiming abandoned Azure DNS zones (‘Azure DNS zone takeover of legitimate enterprise subdomains’).
  • [T1189 ] Drive-by Compromise – Thai users reached malicious gambling pages through normal web browsing and search results, not a direct exploit chain (‘Thai users directed to compromised enterprise subdomains via organic search’).
  • [T1078 ] Valid Accounts – The Verizon-style bulk per-subdomain record creation implies the use of legitimate DNS management access or credentials (‘DNS management credentials implied by per-subdomain record creation (Verizon)’).
  • [T1656 ] Impersonation – The gambling kit was served beneath trusted enterprise domains with valid TLS certificates, making the pages look like legitimate corporate properties (‘Gambling kit served under legitimate enterprise TLS certificates’).
  • [T1078.004 ] Valid Accounts: Cloud Accounts – A cloud account was used to claim abandoned DNS zones in Azure (‘Azure account used to claim abandoned DNS zones’).
  • [T1557 ] Adversary-in-the-Middle – The backend verified the referrer server-side before redirecting, inserting a controlled validation step in the user flow (‘server-side affiliate referrer verification intercepts the user session’).
  • [T1567 ] Exfiltration to Web Service – User registrations and financial activity were sent to gambling platforms for conversion and commission tracking (‘User registration data and financial transactions were exfiltrated to gambling platforms’).

Indicators of Compromise

  • [IP address ] Delivery and hosting infrastructure – 51.79.199.51, 139.99.82.106, and 38.127.8.49
  • [CIDR ranges ] Backend fleet in Hong Kong – 38.173.30.0/24, 38.173.56.0/24, and 38.173.239.0/24
  • [Domain ] Affiliate and destination platforms – ibiza99.autos, seven77.click, and link99.nova555.rest
  • [Domain ] Backend and supporting infrastructure – broker-xm.com, pub-a4952b46ff9c4f6b8d5529cd21f9a1e3.r2.dev, and 99997778.com
  • [URI / file path ] Campaign-specific asset – /img/ib99-hq.ico, used as a shared favicon path across compromised endpoints
  • [File hash ] Shared backend and page fingerprints – 7df3d7cf3358af3f470ac7229387ef94 MD5 and 07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d JARM
  • [String / build ID ] Next.js page fingerprint – QQOrXCFjoI6C9oF-4YVhl
  • [TLS certificate CN ] Certificate observed on backend fleet – broker-xm.com


Read more: https://cyble.com/blog/borrowed-trust-cloud-dns-takeover-thai-gambling-seo-poisoning/