HomeCyber BalkansAttackers Exploit Google Search and Compromise .ac.th Domain to Evade Ad Moderation

Attackers Exploit Google Search and Compromise .ac.th Domain to Evade Ad Moderation

Published on

spot_img

Cloaking Technique Discovered by ADEX Researchers Allows Malicious Ads to Bypass Google Scrutiny

Security researchers at ADEX have recently uncovered a sophisticated cloaking technique that intriguingly requires no actual cloaking code. This strategy represents a departure from conventional methods, as it utilizes a chain of fully legitimate components to circumvent detection by Google Ads screening and moderation systems.

Instead of engaging in user-agent detection on servers controlled by attackers, the operators skillfully combined a Google search results page, a compromised educational website, and a standard redirect. Their goal was to slip an illegal online casino campaign past the scrutiny of ad networks, presenting a clever evasion strategy that poses significant challenges for current ad verification systems.

At the heart of this operation lies the compromised domain km.chpc.ac.th, which belongs to a Thai college situated in the .ac.th zone—a domain reserved specifically for accredited educational institutions. The attackers leveraged the inherent trust associated with such a domain to enhance the credibility of their malevolent activities.

Anatomy of the Redirect Chain

ADEX’s monitoring team first became aware of this alarming development when they observed that an advertiser’s destination URL did not link to a conventional landing page; instead, it directed users to a Google search query. The breakdown of this redirect chain reveals the depth of the evasion strategy employed:

  1. Ad Click → Google Search Results: The ad’s destination URL leads to a Google SERP (Search Engine Results Page) for a specific query. For moderators or automated crawlers, this initially appears benign, as it simply redirects to Google.

  2. Compromised Results: Attackers had previously infiltrated km.chpc.ac.th, implanting a page themed around online casinos. Due to the domain’s established authority, hackers manipulated search engine rankings to ensure that their injected page appeared as the top search result for the targeted query.

  3. Trusted Click → Redirect: When users clicked on the top search result, they were redirected to an online casino, which is illegal to advertise in Thailand.

The pivotal aspect of this evasion strategy lies in the fact that the malicious component is merely one click removed from the ad’s declared destination, situated on third-party infrastructure that the advertiser does not own. Consequently, traditional ad-verification tools that resolve and inspect the landing URL fail to detect any illicit activity since the landing URL itself remains compliant.

Why Classic Cloaking Detection Fails

Conventional cloaking methods rely on server-side logic that inspects visitors and determines whether they are Googlebot, a moderator’s browser, or human users. The detection mechanisms usually involve tactics such as fingerprint spoofing, IP rotation, and other techniques aimed at mimicking human behavior. However, this particular campaign deviates from the established norms, rendering typical detection methods ineffective.

In this case, no alternative content is served to different visitors; everyone, whether human or bot, is directed to the same Google page, the same college page, and the same redirect. The differential lies not in the content provided but in the depth to which a reviewer follows the redirect chain. As ADEX aptly summarized, “Only the combination created the violation.”

A Global Escalation of Similar Techniques

The situation involving the Thai college is not an isolated incident. ADEX has cited data that indicates this underlying technique has been industrialized, with attackers infiltrating thousands of websites to inject malicious redirects and gambling content into high-authority public and academic domains. For instance, in Thailand alone, approximately 30 million gambling-related URLs have been traced back to about 1,000 public-sector sites, while Indonesia has witnessed over 600 government and educational sites being blocked due to similar issues.

ADEX has noted that most of the injected content pertains to gambling and is often concealed using CSS to remain invisible to human visitors while still being easily detectable by crawlers. This mechanism is identical to tactics previously observed on the compromised Thai website but utilizes markup rather than redirecting users.

The Policy Gap

Google’s "site reputation abuse" spam policy, first introduced in March 2024 and tightened in November 2024, aims to address publishers who knowingly rent out their ranking to third-party content. However, in cases involving hacked colleges, the institutions are victims rather than collaborators, which means the existing policy offers little practical protection against such malicious abuse.

Recommendations for Mitigation

In light of these alarming trends, ADEX has provided crucial recommendations for ad networks, advertisers, and verification vendors:

  1. Scrutinize Restricted TLD Zones: Treat domains with .ac., .gov, .edu, and other trusted TLDs with heightened scrutiny. Do not automatically approve redirects involving these domains.

  2. Follow the Redirect Chain: Only inspecting the declared landing page is no longer sufficient; it is crucial to examine the entire redirect chain to uncover potentially malicious content hidden behind compliant-looking URLs.

  3. Re-verify Post-Approval: Redirect chains can be altered anytime after initial approval, making post-approval verification essential.

  4. TLS Should Not Be a Trust Signal: Just because a site holds a valid TLS certificate does not guarantee the legitimacy of its content.

For site owners, particularly those in academic and public-sector environments, taking proactive measures is vital:

  1. Take Inventory of Forgotten Subdomains: Abandoned DNS records can lead to subdomain takeover attacks, granting unauthorized authority to threat actors.

  2. Self-Search Like an Attacker Might: Use targeted search queries to identify potential vulnerabilities in one’s domain, as injected pages often go unnoticed by typical navigation paths.

ADEX positions the trend as an escalation rather than a novelty, stating, “The domain as a trust signal stopped working long before this, back when malware started being distributed through the CDNs of major players.” This shift indicates a clear move away from utilizing obscure domains, with attackers now aiming for higher-profile and more trusted targets.

In conclusion, as attackers refine their tactics and target legitimate domains, the ramifications for advertisers and web users alike grow increasingly severe. ADEX stands as a pivotal player in the anti-fraud and traffic-quality realm, advocating for stronger protective measures to combat these evolving threats.

Source link

Latest articles

OpenAI Reports Six New Misalignment Incidents Under Updated Framework

OpenAI has recently released a series of six reports that delve into the complexities...

AI Redefining Threat-Led Penetration Testing

Crest CEO Discusses Governance, Ethics, and Risks in AI-Driven Penetration Testing In a recent discussion,...

CISA Advises Critical Infrastructure to Implement Decoys Within Networks

CISA Advocates for Cyber Decoys to Enhance Critical Infrastructure Security The Cybersecurity and Infrastructure Security...

Why AI Security Investments May Not Always Yield Profits

The Evolving Landscape of AI Security Investments: Opportunities and Challenges In the rapidly evolving realm...

More like this

OpenAI Reports Six New Misalignment Incidents Under Updated Framework

OpenAI has recently released a series of six reports that delve into the complexities...

AI Redefining Threat-Led Penetration Testing

Crest CEO Discusses Governance, Ethics, and Risks in AI-Driven Penetration Testing In a recent discussion,...

CISA Advises Critical Infrastructure to Implement Decoys Within Networks

CISA Advocates for Cyber Decoys to Enhance Critical Infrastructure Security The Cybersecurity and Infrastructure Security...