163 Organizations Hit by Thai Gambling SEO Poisoning Campaign

How the SEO Poisoning Campaign Works
Researchers found that the campaign primarily abuses abandoned Azure DNS zone delegations. When organizations retire cloud projects, DNS records that delegate subdomains to Azure are often left behind. Threat actors identify these orphaned delegations, recreate the abandoned DNS zones under new Azure subscriptions, and gain authority over the affected subdomains. Using this method, the attackers deploy a Next.js-based Thai-language gambling kit protected by valid Let's Encrypt wildcard certificates. As a result, users, browsers, and search engines see what appears to be legitimate content hosted under trusted corporate domains. At the time of publication, 161 of the 163 affected organizations remained actively compromised.Discovery Leads to Global Exposure
The investigation began when CRIL identified unusual DNS activity on a Verizon subdomain environment. Researchers discovered more than 1,000 individually named subdomains serving Thai-language gambling content. Each page contains affiliate links designed to drive user registrations and generate commissions. Further analysis revealed the same infrastructure and content fingerprints across 162 additional organizations. More than 90 compromised enterprise subdomains shared the same Next.js build ID (QQOrXCFjoI6C9oF-4YVhl), favicon path (/img/ib99-hq.ico), and affiliate redirect destinations.Four DNS Abuse Methods Identified
The Thai gambling SEO poisoning operation relied on four compromise mechanisms:- Azure DNS zone takeover: More than 150 organizations were affected through abandoned Azure DNS delegations.
- DigitalOcean DNS zone takeover: Two organizations were compromised using a similar technique.
- Direct wildcard DNS misconfigurations: Two organizations had wildcard records pointing to attacker-controlled infrastructure.
- Mass A-record creation: Verizon's environment contained over 1,000 individual DNS records directing traffic to gambling content.