Surprisingly, a major SEO poisoning effort tied to Thai gambling networks has breached 163 groups in over thirty nations - leveraging outdated cloud DNS setups. Forgotten domain name system delegations were seized by hackers, according to findings from Cyble's research team. These compromised entries then hosted gambling sites in Thai, piggybacking on legitimate corporate web addresses. Government bodies faced risks alongside hospitals, banks, schools, and essential service providers. The attack spanned industries once thought too secure for such oversights.
Abandoned Azure DNS zone delegations form the main focus of this attack method. Companies shutting down cloud initiatives often leave DNS entries intact by mistake. These lingering records catch the attention of hackers looking for weaknesses. Under their own accounts, attackers rebuild the forgotten zones once tied to those domains. Control shifts to them without immediate detection. What follows is silent redirection through seemingly valid subdomains. Users encounter harmful material believing it trustworthy.
Search systems treat the pages as genuine due to unchanged domain signals. Browsers show no warnings because technical checks pass unnoticed. Oversight at decommissioning enables this entire chain.
One way hackers operated involved deploying a gambling toolkit based on Next.js, protected by real Let’s Encrypt wildcard certificates. Security systems often overlook such threats since the pages appear under trusted corporate domains carrying proper encryption credentials. When analysts reviewed the situation, they discovered most targets - 161 out of 163 - were still infiltrated.
What made detection hard was not just the tech used, but how convincingly it mimicked authorized web traffic.
Unusual DNS patterns in a Verizon subdomain initially drew attention to the campaign. Over 1,000 subdomains were found serving Thai gambling content - each packed with referral links meant to earn signup-based payouts. Identical code markers tied these sites together: matching Next.js build IDs, favicons, and redirect paths showed up repeatedly. Investigations then revealed similar setups spread across 162 separate entities. Where one breach ended, another began; nearly all of them echoed the same digital fingerprints.
Four main tactics powered the attacks, analysis showed.
Most frequent: hijacking Azure DNS zones - over 150 groups impacted. Some breaches emerged from unused DigitalOcean domains; two companies fell victim this way. Misconfigured wildcards redirected data flow in separate cases, benefiting hostile servers. On its own track, Verizon's setup hosted a surge of deceptive A-records, exceeding one thousand entries.
Certificate transparency logs show certain unused domains stayed dormant for long periods prior to being hijacked. One example involves a drug maker's subdomain, which saw zero valid certificate issuance past 2019 - then suddenly received a fresh certificate issued by adversaries in April 2026.
Among the sites involved were ibiza99.autos, big888.store, seven77.click, and link99.nova555.rest, each tied to affiliate systems bringing in income. Hidden behind them sat a network of 103 machines based in Hong Kong, discovered by analysts who noticed uniform admin software, matching security credentials, along with mirrored setup patterns across every server.
Not one alert was raised before the breach exposed weak spots in basic domain setups.
A closer look shows outdated links lingering long after they should have been dropped. These loose ends give attackers room to move without detection. Monitoring public logs might catch early signs of misuse, though many teams skip this step. Old ties to cloud services often stay active, quietly inviting abuse. When ignored, such gaps let criminals twist legitimate sites toward shady goals. Routine checks could block these paths, yet few organizations follow through consistently.
