Cyble
Read post

Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO Attack

Cyble Research & Intelligence Labs uncovered an active SEO poisoning campaign exploiting abandoned Azure DNS zone delegations to serve Thai-language gambling content under the domain authority of 163 enterprise organizations across 30+ countries. The attack works by identifying subdomains whose NS records still point to Azure DNS after the underlying subscription was canceled, then claiming the orphaned zone under a new Azure subscription, adding a wildcard A record, and obtaining a valid Let's Encrypt wildcard TLS certificate — all resolving cleanly under the victim's own domain. The campaign compromised federal agencies, healthcare systems, financial institutions, and universities, with some delegations left abandoned for over six years. A 103-node backend fleet in Hong Kong handles the application layer, while three OVH delivery nodes serve the gambling kit. The operation monetizes through a dual-tier affiliate commission structure with server-side geographic filtering targeting Thai users. Detection requires Certificate Transparency log monitoring and DNS delegation auditing, as conventional security controls produce no signal. Remediation involves removing stale NS delegations and auditing all cloud-delegated subdomains.

    #security#azure
Jun 12•17m read time•From cyble.com
Post cover image
Table of contents
Executive SummaryBackground: The Vulnerability ClassDNS Compromise MechanismsTechnical AnalysisRemediationConclusionMITRE ATT&CK® TechniquesIndicators of Compromise (IOCs)
171 Impressions
Cyble's image
Cyble

Cyble's publication is a resource for cybersecurity professionals and businesses seeking to stay ahe...

112 Followers

•

131 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard