Cyble reports an SEO poisoning campaign that hijacked abandoned cloud DNS delegations to serve Thai gambling content from 163 compromised organizations across 30+ countries. The operation relied on Azure DNS zone takeovers, a smaller set of DigitalOcean and wildcard misconfiguration cases, and a monetization stack tied to OVH delivery nodes, a Hong Kong backend fleet, and affiliate infrastructure such as link99 and ibiza99vip1. #Azure #DigitalOcean #Verizon #OVH #PEGTECHINC #brokerxm #link99 #ibiza99vip1
Keypoints
- Cyble identified an active Thai gambling SEO poisoning campaign abusing abandoned cloud DNS delegations.
- The campaign compromised 163 organizations across more than 30 countries, including government, healthcare, finance, critical infrastructure, and universities.
- The main technique was Azure DNS zone takeover, where abandoned delegated zones were reclaimed under a new Azure subscription.
- Two additional compromises involved DigitalOcean DNS takeovers, while others used direct wildcard DNS misconfigurations or per-subdomain A records.
- The delivery layer used three OVH-hosted IPs and Next.js gambling pages with valid Let’s Encrypt certificates to appear legitimate under victim domains.
- The monetization layer used affiliate parameters, Thai-only server-side filtering, and a multi-tier referral structure centered on link99.
- A separate 103-node backend fleet in Hong Kong was attributed to a single Chinese operator through multiple technical evidence points.
MITRE Techniques
- [T1583.003 ] Acquire Infrastructure – The actor used rented and hosted infrastructure for delivery and backend operations, including OVH nodes and the Hong Kong fleet (‘OVH VPS for delivery; PEG TECH INC ASN for backend fleet’).
- [T1584 ] Compromise Infrastructure – The campaign took over legitimate enterprise DNS infrastructure by reclaiming abandoned Azure DNS zones (‘Azure DNS zone takeover of legitimate enterprise subdomains’).
- [T1189 ] Drive-by Compromise – Thai users reached malicious gambling pages through normal web browsing and search results, not a direct exploit chain (‘Thai users directed to compromised enterprise subdomains via organic search’).
- [T1078 ] Valid Accounts – The Verizon-style bulk per-subdomain record creation implies the use of legitimate DNS management access or credentials (‘DNS management credentials implied by per-subdomain record creation (Verizon)’).
- [T1656 ] Impersonation – The gambling kit was served beneath trusted enterprise domains with valid TLS certificates, making the pages look like legitimate corporate properties (‘Gambling kit served under legitimate enterprise TLS certificates’).
- [T1078.004 ] Valid Accounts: Cloud Accounts – A cloud account was used to claim abandoned DNS zones in Azure (‘Azure account used to claim abandoned DNS zones’).
- [T1557 ] Adversary-in-the-Middle – The backend verified the referrer server-side before redirecting, inserting a controlled validation step in the user flow (‘server-side affiliate referrer verification intercepts the user session’).
- [T1567 ] Exfiltration to Web Service – User registrations and financial activity were sent to gambling platforms for conversion and commission tracking (‘User registration data and financial transactions were exfiltrated to gambling platforms’).
Indicators of Compromise
- [IP address ] Delivery and hosting infrastructure – 51.79.199.51, 139.99.82.106, and 38.127.8.49
- [CIDR ranges ] Backend fleet in Hong Kong – 38.173.30.0/24, 38.173.56.0/24, and 38.173.239.0/24
- [Domain ] Affiliate and destination platforms – ibiza99.autos, seven77.click, and link99.nova555.rest
- [Domain ] Backend and supporting infrastructure – broker-xm.com, pub-a4952b46ff9c4f6b8d5529cd21f9a1e3.r2.dev, and 99997778.com
- [URI / file path ] Campaign-specific asset – /img/ib99-hq.ico, used as a shared favicon path across compromised endpoints
- [File hash ] Shared backend and page fingerprints – 7df3d7cf3358af3f470ac7229387ef94 MD5 and 07d14d16d21d21d07c42d43d000000270a013a3e21e28897e76e8fe13e2f7d JARM
- [String / build ID ] Next.js page fingerprint – QQOrXCFjoI6C9oF-4YVhl
- [TLS certificate CN ] Certificate observed on backend fleet – broker-xm.com
Read more: https://cyble.com/blog/borrowed-trust-cloud-dns-takeover-thai-gambling-seo-poisoning/