Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform ADEX, which says the campaign achieved full ad cloaking without deploying a single line of cloaking code, mirroring evasion tactics seen in campaigns designed to bypass Google Ads screening.

The scheme, uncovered by ADEX’s traffic-monitoring team, abused the genuine domain km.chpc.ac.th, which sits in Thailand’s .ac.th zone reserved for educational institutions.

Attackers planted a casino-themed page on the hacked site, which Google indexed and ranked first for a targeted search query. Users who clicked the top result were redirected to an online gambling site, a product that is illegal to advertise in Thailand.

How the Attack Chain Worked

Unlike traditional cloaking, in which a fraudster’s own server fingerprints visitors and serves clean content to crawlers and malicious content to humans, this campaign relied entirely on legitimate infrastructure.

ADEX first flagged an advertiser whose ad traffic was being routed through what appeared to be an ordinary Google search page rather than a direct landing page.

To an ad moderator or automated crawler, the destination URL looked harmless: a neutral Google results page, taking advantage of how Google search results and redirect mechanisms can obscure final destinations. The malicious step happened one click later, on a third-party website that sat completely outside the advertiser’s infrastructure.

“No part of the chain was fabricated,” ADEX noted. The Google search, the college website, and the redirect were each exactly what they claimed to be. Only the combination produced the violation.

Part of a Much Larger Problem

ADEX says the Thai case is one instance of a domain-borrowing tactic now being tracked on trusted sites worldwide. Public figures cited by the company point to the scale:

  • Thailand’s Ministry of Digital Economy and Society has reported roughly 30 million gambling-related URLs across about 1,000 public-sector sites, with the Ministry of Public Health alone accounting for some 8 million injected scripts.
  • Indonesia’s Ministry of Communication and Informatics has blocked 683 government and educational sites carrying gambling content, including 461 in the .go.id zone and 222 in .ac.id.
  • An August 2025 academic crawl of Indonesian domains found 147 compromised sites and 346 pages loaded with gambling keywords, with .ac.id the hardest-hit zone at 65 sites.
  • Netcraft has tracked an underground marketplace selling access to more than 15,000 already-compromised .gov, .edu, and country-code domains, with campaigns concentrated on Turkey’s gambling market.
  • Researchers at cSide identified an injection campaign hitting more than 500 government and university sites globally, hiding gambling and adult links from humans while leaving them visible to search crawlers.

Vietnam has flagged the same dynamic on its .gov.vn and .edu.vn domains, attributing the repeat targeting to under-investment in cybersecurity at public institutions.

Google’s Policy Falls Short

Google introduced a “site reputation abuse” rule in March 2024 and tightened it in November 2024 to remove the exemption for site owners claiming no involvement.

But ADEX points out the policy is aimed at sites that deliberately rent out their reputation, not at institutions where adversaries are quietly hijacking web servers to manipulate search crawlers and redirect visitors, leaving cases like the Thai college largely uncovered.

ADEX urges ad networks and advertisers to treat restricted domain zones such as .ac., .gov, .edu, .mi., and .go.* as a flag rather than a pass when they appear in a redirect chain, reflecting a broader trend where malvertising is shifting from deceptive content to weaponized redirect infrastructure.

“Checking a single landing page is not enough, because in a case like this one, the landing page itself breaks no rule at all. Whatever is malicious sits behind it,” the company said.

The firm also recommends re-checking campaigns after approval, since redirect chains can be rewired at any time, and warns that a valid TLS certificate is no guarantee of legitimacy.

Site owners are advised to maintain an inventory of forgotten subdomains and to periodically search their own domain the way an attacker would, since injected pages are designed to stay invisible to ordinary visitors.

ADEX is the AI-driven anti-fraud and traffic-quality platform within AdTech Holding, analyzing billions of impressions, clicks, and conversions to protect ad-tech products and partners from malware-driven and invalid traffic.

The post Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino appeared first on Cyber Security News.