Borrowed Trust SEO Poisoning Campaign Backend Subnet Activity

Detects outbound network traffic to specific Hong Kong backend fleet subnets (AS398478) identified as being utilized by the 'Borrowed Trust' threat actor. This infrastructure is used to manage redirection and affiliate attribution for their SEO poisoning campaign.