Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical BIND 9 Vulnerabilities Allow Cache Poisoning, DoS
September 17, 2026
CISA Urges Defenders to Deploy Deception Technologies
September 17, 2026
SilkParasite Malware Infrastructure Active for Four Years in Central Asia
September 17, 2026
Home/CyberSecurity News/Thai College Website Redirects Google Users to Illegal Online Casino
CyberSecurity News

Thai College Website Redirects Google Users to Illegal Online Casino

Key Takeaways A Thai college website was exploited to redirect Google search users to an illegal online casino. The attack utilized a sophisticated ad cloaking technique without custom code,...

Emy Elsamnoudy
Emy Elsamnoudy
September 17, 2026 4 Min Read
2 0

Key Takeaways

  • A Thai college website was exploited to redirect Google search users to an illegal online casino.
  • The attack utilized a sophisticated ad cloaking technique without custom code, mimicking evasion strategies used against Google Ads.
  • The scheme leveraged legitimate infrastructure, including Google search results and a compromised educational domain, to obscure the malicious redirect.
  • This incident is part of a growing global trend where trusted government and educational domains are being hijacked for illicit advertising.
  • Current Google policies on “site reputation abuse” do not adequately address this specific method of exploitation.

A Thai educational institution’s website was surreptitiously co-opted to funnel unsuspecting Google users toward an illicit online casino, according to recent discoveries by the anti-fraud platform ADEX. This sophisticated operation achieved complete ad cloaking without deploying any specialized cloaking code, mirroring advanced evasion tactics observed in campaigns designed to circumvent Google Ads screening mechanisms.

Table Of Content

  • Key Takeaways
  • How the Attack Chain Operated
  • Part of a Much Larger Problem
  • Google’s Policy Falls Short
  • What You Should Do

The fraudulent scheme, brought to light by ADEX’s dedicated traffic-monitoring team, exploited the authentic domain km.chpc.ac.th, which falls within Thailand’s .ac.th zone designated for academic bodies. Attackers successfully embedded a casino-themed page onto the compromised site. Google subsequently indexed this page, ranking it as the top result for a specific search query. Users who clicked on this seemingly legitimate search result were then redirected to an online gambling platform, an activity explicitly illegal to advertise in Thailand.

How the Attack Chain Operated

This campaign diverged significantly from conventional cloaking methods, which typically involve a fraudster’s server identifying visitors to serve clean content to crawlers and malicious content to human users. Instead, this operation relied entirely on legitimate, uncompromised infrastructure for its execution.

ADEX initially flagged an advertiser whose ad traffic was observed routing through what appeared to be a standard Google search results page, rather than directly to a designated landing page. To an ad moderator or an automated crawler, the initial destination URL seemed innocuous: a neutral Google search results page. This leveraged Google’s search result and redirect mechanisms to mask the ultimate destination. The critical malicious step occurred a subsequent click later, on a third-party website entirely separate from the advertiser’s own infrastructure.

As ADEX says, “No part of the chain was fabricated.” Each component—the Google search, the college website, and the subsequent redirect—was genuine in its individual capacity. It was only their orchestrated combination that constituted the policy violation and facilitated the illicit activity.

Part of a Much Larger Problem

The incident involving the Thai college is not isolated. ADEX says it represents one example of a widespread “domain-borrowing” tactic now being actively tracked across trusted websites globally. Data from various public entities underscores the significant scale of this issue:

  • Thailand’s Ministry of Digital Economy and Society has documented approximately 30 million gambling-related URLs across about 1,000 public-sector websites, with the Ministry of Public Health alone reportedly accounting for around 8 million injected scripts.
  • Indonesia’s Ministry of Communication and Informatics has blocked 683 government and educational sites hosting gambling content. This includes 461 sites within the .go.id zone and 222 in the .ac.id zone.
  • An academic crawl of Indonesian domains in August 2025 identified 147 compromised sites and 346 pages laden with gambling keywords. The .ac.id zone was the most severely affected, with 65 compromised sites.
  • Netcraft has uncovered an underground marketplace offering access to over 15,000 already-compromised .gov, .edu, and country-code domains, with many campaigns targeting Turkey’s gambling market.
  • Researchers at cSide documented an injection campaign affecting more than 500 government and university sites worldwide. This campaign specifically hid gambling and adult links from human visitors while ensuring they remained visible to search engine crawlers.

Vietnam has also reported similar patterns on its .gov.vn and .edu.vn domains, attributing the persistent targeting to insufficient cybersecurity investments within its public institutions.

Google’s Policy Falls Short

Google implemented a “site reputation abuse” policy in March 2024, which was further tightened in November 2024 to remove exemptions for site owners claiming no involvement. However, ADEX highlights that this policy primarily targets sites that intentionally lease out their reputation. It does not adequately address scenarios where adversaries silently hijack web servers to manipulate search crawlers and redirect visitors, leaving cases like the Thai college largely unaddressed by the current policy framework.

ADEX strongly advises ad networks and advertisers to treat restricted domain zones, such as .ac.*, .gov, .edu, .mi.*, and .go.*, as potential red flags rather than automatic passes when they appear within a redirect chain. This recommendation reflects a broader industry trend where malvertising is evolving from deceptive content to weaponized redirect infrastructure. The company emphasized, “Checking a single landing page is not enough, because in a case like this one, the landing page itself breaks no rule at all. Whatever is malicious sits behind it.”

What You Should Do

  • For Ad Networks and Advertisers: Treat restricted domain zones (.ac.*, .gov, .edu, .mi.*, .go.*) as potential indicators of compromise within redirect chains, not as inherently safe.
  • For Ad Networks and Advertisers: Implement post-approval monitoring of campaigns, as redirect chains can be altered at any time.
  • For Ad Networks and Advertisers: Do not solely rely on a valid TLS certificate as a guarantee of legitimacy for a domain.
  • For Site Owners (especially educational and government institutions): Maintain a comprehensive inventory of all subdomains, including forgotten or legacy ones.
  • For Site Owners: Periodically conduct searches of your own domain from an attacker’s perspective to identify any injected pages designed to be invisible to regular visitors.
  • For Site Owners: Invest in robust cybersecurity measures to protect against unauthorized access and content injection.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityMalwareSecurity

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

North Korean IT workers exploit AI, remote tools to fake interviews

Next Post

HEAVYGRAM Malware Uses Telegram as Command and Control Server

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT workers exploit AI, remote tools to fake interviews
September 17, 2026
Critical Docker Sandbox Vulnerabilities Let Guests Escape microVMs
September 17, 2026
Critical Cisco ISE 0-Day Vulnerability Exploited in Attacks
September 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us