Thai College Website Redirects Google Users to Illegal Online Casino
Key Takeaways A Thai college website was exploited to redirect Google search users to an illegal online casino. The attack utilized a sophisticated ad cloaking technique without custom code,...
Key Takeaways
- A Thai college website was exploited to redirect Google search users to an illegal online casino.
- The attack utilized a sophisticated ad cloaking technique without custom code, mimicking evasion strategies used against Google Ads.
- The scheme leveraged legitimate infrastructure, including Google search results and a compromised educational domain, to obscure the malicious redirect.
- This incident is part of a growing global trend where trusted government and educational domains are being hijacked for illicit advertising.
- Current Google policies on “site reputation abuse” do not adequately address this specific method of exploitation.
A Thai educational institution’s website was surreptitiously co-opted to funnel unsuspecting Google users toward an illicit online casino, according to recent discoveries by the anti-fraud platform ADEX. This sophisticated operation achieved complete ad cloaking without deploying any specialized cloaking code, mirroring advanced evasion tactics observed in campaigns designed to circumvent Google Ads screening mechanisms.
Table Of Content
The fraudulent scheme, brought to light by ADEX’s dedicated traffic-monitoring team, exploited the authentic domain km.chpc.ac.th, which falls within Thailand’s .ac.th zone designated for academic bodies. Attackers successfully embedded a casino-themed page onto the compromised site. Google subsequently indexed this page, ranking it as the top result for a specific search query. Users who clicked on this seemingly legitimate search result were then redirected to an online gambling platform, an activity explicitly illegal to advertise in Thailand.
How the Attack Chain Operated
This campaign diverged significantly from conventional cloaking methods, which typically involve a fraudster’s server identifying visitors to serve clean content to crawlers and malicious content to human users. Instead, this operation relied entirely on legitimate, uncompromised infrastructure for its execution.
ADEX initially flagged an advertiser whose ad traffic was observed routing through what appeared to be a standard Google search results page, rather than directly to a designated landing page. To an ad moderator or an automated crawler, the initial destination URL seemed innocuous: a neutral Google search results page. This leveraged Google’s search result and redirect mechanisms to mask the ultimate destination. The critical malicious step occurred a subsequent click later, on a third-party website entirely separate from the advertiser’s own infrastructure.
As ADEX says, “No part of the chain was fabricated.” Each component—the Google search, the college website, and the subsequent redirect—was genuine in its individual capacity. It was only their orchestrated combination that constituted the policy violation and facilitated the illicit activity.
Part of a Much Larger Problem
The incident involving the Thai college is not isolated. ADEX says it represents one example of a widespread “domain-borrowing” tactic now being actively tracked across trusted websites globally. Data from various public entities underscores the significant scale of this issue:
- Thailand’s Ministry of Digital Economy and Society has documented approximately 30 million gambling-related URLs across about 1,000 public-sector websites, with the Ministry of Public Health alone reportedly accounting for around 8 million injected scripts.
- Indonesia’s Ministry of Communication and Informatics has blocked 683 government and educational sites hosting gambling content. This includes 461 sites within the .go.id zone and 222 in the .ac.id zone.
- An academic crawl of Indonesian domains in August 2025 identified 147 compromised sites and 346 pages laden with gambling keywords. The .ac.id zone was the most severely affected, with 65 compromised sites.
- Netcraft has uncovered an underground marketplace offering access to over 15,000 already-compromised .gov, .edu, and country-code domains, with many campaigns targeting Turkey’s gambling market.
- Researchers at cSide documented an injection campaign affecting more than 500 government and university sites worldwide. This campaign specifically hid gambling and adult links from human visitors while ensuring they remained visible to search engine crawlers.
Vietnam has also reported similar patterns on its .gov.vn and .edu.vn domains, attributing the persistent targeting to insufficient cybersecurity investments within its public institutions.
Google’s Policy Falls Short
Google implemented a “site reputation abuse” policy in March 2024, which was further tightened in November 2024 to remove exemptions for site owners claiming no involvement. However, ADEX highlights that this policy primarily targets sites that intentionally lease out their reputation. It does not adequately address scenarios where adversaries silently hijack web servers to manipulate search crawlers and redirect visitors, leaving cases like the Thai college largely unaddressed by the current policy framework.
ADEX strongly advises ad networks and advertisers to treat restricted domain zones, such as .ac.*, .gov, .edu, .mi.*, and .go.*, as potential red flags rather than automatic passes when they appear within a redirect chain. This recommendation reflects a broader industry trend where malvertising is evolving from deceptive content to weaponized redirect infrastructure. The company emphasized, “Checking a single landing page is not enough, because in a case like this one, the landing page itself breaks no rule at all. Whatever is malicious sits behind it.”
What You Should Do
- For Ad Networks and Advertisers: Treat restricted domain zones (.ac.*, .gov, .edu, .mi.*, .go.*) as potential indicators of compromise within redirect chains, not as inherently safe.
- For Ad Networks and Advertisers: Implement post-approval monitoring of campaigns, as redirect chains can be altered at any time.
- For Ad Networks and Advertisers: Do not solely rely on a valid TLS certificate as a guarantee of legitimacy for a domain.
- For Site Owners (especially educational and government institutions): Maintain a comprehensive inventory of all subdomains, including forgotten or legacy ones.
- For Site Owners: Periodically conduct searches of your own domain from an attacker’s perspective to identify any injected pages designed to be invisible to regular visitors.
- For Site Owners: Invest in robust cybersecurity measures to protect against unauthorized access and content injection.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.