ZeroHour
Cyber Security Newspublished ()ingested Kaaviya
Part of a story covered by 2 sources: “Hacked Thai College Domain Used for 'Zero-Code Cloaking' to Funnel Google Searchers to Illegal Casino Sites” — merged summary and timeline →

Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino

mediumPhishing & fraud exploited in the wildimportance 40
AI summary · glm-5.3-flash

ADEX uncovered a hacked Thai college domain serving casino pages through real Google search redirects, part of a global campaign compromising government and education sites.

Anti-fraud platform ADEX found a casino-themed page planted on the compromised km.chpc.ac.th domain in Thailand's educational .ac.th zone, which Google indexed and ranked first to redirect users to illegal online gambling. The scheme achieved full ad cloaking without deploying any cloaking code by chaining a genuine Google results page and a third-party redirect. The same domain-borrowing tactic is tracked globally: Thailand reports roughly 30 million gambling URLs across about 1,000 public-sector sites, Indonesia blocked 683 government and education sites, and Netcraft found an underground market selling access to more than 15,000 compromised .gov, .edu and ccTLD domains. ADEX argues Google's site reputation abuse policy does not cover institutions that are hijacked without their knowledge.

  • Casino page planted on compromised km.chpc.ac.th ranked first on Google for targeted queries
  • Cloaking achieved with no custom code by chaining a real Google results page and a redirect
  • Thailand reports about 30 million gambling URLs across roughly 1,000 public-sector sites
  • Netcraft tracks a market selling access to over 15,000 compromised .gov, .edu and ccTLD domains
  • ADEX urges ad networks to treat .ac., .gov and .edu zones as flags in redirect chains
Full article733 words · extracted from cybersecuritynews.com · click to collapse

A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform ADEX, which says the campaign achieved full ad cloaking without deploying a single line of cloaking code, mirroring evasion tactics seen in campaigns designed to bypass Google Ads screening.

The scheme, uncovered by ADEX’s traffic-monitoring team, abused the genuine domain km.chpc.ac.th, which sits in Thailand’s .ac.th zone reserved for educational institutions.

Attackers planted a casino-themed page on the hacked site, which Google indexed and ranked first for a targeted search query. Users who clicked the top result were redirected to an online gambling site, a product that is illegal to advertise in Thailand.

How the Attack Chain Worked

Unlike traditional cloaking, in which a fraudster’s own server fingerprints visitors and serves clean content to crawlers and malicious content to humans, this campaign relied entirely on legitimate infrastructure.

ADEX first flagged an advertiser whose ad traffic was being routed through what appeared to be an ordinary Google search page rather than a direct landing page.

To an ad moderator or automated crawler, the destination URL looked harmless: a neutral Google results page, taking advantage of how Google search results and redirect mechanisms can obscure final destinations. The malicious step happened one click later, on a third-party website that sat completely outside the advertiser’s infrastructure.

“No part of the chain was fabricated,” ADEX noted. The Google search, the college website, and the redirect were each exactly what they claimed to be. Only the combination produced the violation.

Part of a Much Larger Problem

ADEX says the Thai case is one instance of a domain-borrowing tactic now being tracked on trusted sites worldwide. Public figures cited by the company point to the scale:

  • Thailand’s Ministry of Digital Economy and Society has reported roughly 30 million gambling-related URLs across about 1,000 public-sector sites, with the Ministry of Public Health alone accounting for some 8 million injected scripts.
  • Indonesia’s Ministry of Communication and Informatics has blocked 683 government and educational sites carrying gambling content, including 461 in the .go.id zone and 222 in .ac.id.
  • An August 2025 academic crawl of Indonesian domains found 147 compromised sites and 346 pages loaded with gambling keywords, with .ac.id the hardest-hit zone at 65 sites.
  • Netcraft has tracked an underground marketplace selling access to more than 15,000 already-compromised .gov, .edu, and country-code domains, with campaigns concentrated on Turkey’s gambling market.
  • Researchers at cSide identified an injection campaign hitting more than 500 government and university sites globally, hiding gambling and adult links from humans while leaving them visible to search crawlers.

Vietnam has flagged the same dynamic on its .gov.vn and .edu.vn domains, attributing the repeat targeting to under-investment in cybersecurity at public institutions.

Google’s Policy Falls Short

Google introduced a “site reputation abuse” rule in March 2024 and tightened it in November 2024 to remove the exemption for site owners claiming no involvement.

But ADEX points out the policy is aimed at sites that deliberately rent out their reputation, not at institutions where adversaries are quietly hijacking web servers to manipulate search crawlers and redirect visitors, leaving cases like the Thai college largely uncovered.

ADEX urges ad networks and advertisers to treat restricted domain zones such as .ac., .gov, .edu, .mi., and .go.* as a flag rather than a pass when they appear in a redirect chain, reflecting a broader trend where malvertising is shifting from deceptive content to weaponized redirect infrastructure.

“Checking a single landing page is not enough, because in a case like this one, the landing page itself breaks no rule at all. Whatever is malicious sits behind it,” the company said.

The firm also recommends re-checking campaigns after approval, since redirect chains can be rewired at any time, and warns that a valid TLS certificate is no guarantee of legitimacy.

Site owners are advised to maintain an inventory of forgotten subdomains and to periodically search their own domain the way an attacker would, since injected pages are designed to stay invisible to ordinary visitors.

ADEX is the AI-driven anti-fraud and traffic-quality platform within AdTech Holding, analyzing billions of impressions, clicks, and conversions to protect ad-tech products and partners from malware-driven and invalid traffic.

Kaaviyahttp://cybersecuritynews.com/

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/hacked-thai-college-website-abused-to-redirect-google-searchers-to-illegal-online-casino/