Executive Summary
Cyble Research & Intelligence Labs (CRIL) has identified a widespread campaign titled 'Borrowed Trust,' attributed to a Chinese-operated actor known as link99. The campaign exploits a critical oversight in cloud infrastructure decommissioning where NS (nameserver) delegations are left pointing to cloud DNS providers like Azure and DigitalOcean after the associated resources are deleted. The actor claims these orphaned zones, allowing them to host content on high-authority subdomains of over 160 organizations across 30+ countries.
Technical analysis revealed a sophisticated 103-node backend fleet in Hong Kong serving a Next.js gambling kit. The actor uses valid Let's Encrypt wildcard TLS certificates and geographic server-side filtering to target Thai users through organic search results. This campaign is particularly insidious because it bypasses traditional security controls by operating entirely within legitimate infrastructure and leveraging the clean reputation of compromised enterprise domains.
