Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO
Score: 9/10

Borrowed Trust: Cloud DNS Hijack Fuels Gambling SEO

Threat actor link99 systematically exploits abandoned Azure and DigitalOcean DNS zone delegations to host Thai gambling platforms under the authority of over 160 enterprise and government domains.

Executive Summary

Cyble Research & Intelligence Labs (CRIL) has identified a widespread campaign titled 'Borrowed Trust,' attributed to a Chinese-operated actor known as link99. The campaign exploits a critical oversight in cloud infrastructure decommissioning where NS (nameserver) delegations are left pointing to cloud DNS providers like Azure and DigitalOcean after the associated resources are deleted. The actor claims these orphaned zones, allowing them to host content on high-authority subdomains of over 160 organizations across 30+ countries.

Technical analysis revealed a sophisticated 103-node backend fleet in Hong Kong serving a Next.js gambling kit. The actor uses valid Let's Encrypt wildcard TLS certificates and geographic server-side filtering to target Thai users through organic search results. This campaign is particularly insidious because it bypasses traditional security controls by operating entirely within legitimate infrastructure and leveraging the clean reputation of compromised enterprise domains.

Key Details

Threat Name

Borrowed Trust Campaign

Affects

—

Adversary

link99

Malware/Tools

Next.js gambling kit

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance8
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources