SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
ADEX flags cloaked ads via hacked college websites

ADEX flags cloaked ads via hacked college websites

Tue, 29th Sep 2026 (Yesterday)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

ADEX has identified a cloaking method that uses compromised education and government websites to route ad traffic to prohibited or malicious content. The tactic can hide the final destination from ad moderators and automated crawlers.

In one case tracked by the anti-fraud business, traffic passed from a Google search result through a hacked Thai college website before redirecting users to an online casino. The setup did not rely on conventional cloaking code on an advertiser-controlled server. Instead, it used legitimate services and compromised third-party infrastructure to obscure what happened after the first click.

The route began on what appeared to be a standard Google search page. The top result led to km.chpc.ac.th, a legitimate domain belonging to a Thai college in the .ac.th education zone, where attackers had placed a casino-related page indexed by Google. When users clicked the result, they were sent to a gambling site advertising a product that is illegal to promote in Thailand.

The finding points to a shift in how some operators try to evade scrutiny in digital advertising. Instead of showing one page to a moderator and another to a user through code hosted on their own systems, they can place the deceptive step later in the chain, outside the destination URL initially reviewed.

How it works

The method creates a gap in standard moderation because the submitted landing page can appear neutral. If a reviewer or crawler checks only the first destination, they may see a harmless search page, while the problematic material sits behind a trusted domain that has already been compromised.

According to ADEX, the use of .gov and .edu-style domains changes the risk calculation for ad platforms and marketers that may still view such addresses as inherently safer than less familiar web properties. Here, the issue did not stem from a fake website, but from a real institutional domain altered by attackers.

Public reporting from several countries suggests the technique is not limited to one market. In Thailand, the Ministry of Digital Economy and Society has reported about 30 million gambling-related URLs across roughly 1,000 public-sector sites, with the Ministry of Public Health accounting for about 8 million injected scripts.

Elsewhere in Southeast Asia, Indonesia's Ministry of Communication and Informatics has blocked 683 government and educational sites injected with gambling content. Of those, 461 were in the .go.id government zone and 222 in the .ac.id academic zone.

An academic study published in August 2025 and cited by ADEX found 147 compromised Indonesian domains and 346 pages carrying gambling keywords. It identified the .ac.id academic zone as the hardest hit, with 65 compromised sites.

Researchers have also documented similar patterns beyond the region. Netcraft has tracked an underground marketplace offering access to more than 15,000 compromised .gov, .edu and country-code domains for this type of use, with activity focused on Turkey's gambling market. Separate research from cSide identified an injection campaign affecting more than 500 government and university websites globally, where gambling and adult links were hidden from human visitors but visible to search engine crawlers.

Industry response

Google has already tightened parts of its search spam rules around what it calls site reputation abuse, targeting cases in which third-party material is published on trusted sites to benefit from their ranking. ADEX said those measures do not fully address hacked public-sector or academic websites because the site owners are victims, not willing participants.

ADEX argued that ad networks should not treat restricted domain zones as automatic proof that traffic is legitimate when those domains appear in a redirect chain. It said checks should extend beyond the first landing page and continue after campaign approval because the route can change later.

"One of the first things we tell ad networks and advertisers is to treat restricted domain zones, ac.*, .gov, .edu, .mi.*, .go.* as a flag rather than a pass whenever they turn up in a redirect chain, not an automatic block, since the campaign behind them may be entirely legitimate. Checking a single landing page is not enough, because in a case like this one, the landing page itself breaks no rule at all. Whatever is malicious sits behind it," said ADEX.

ADEX also urged site owners to monitor forgotten subdomains and search for their own domains the way an attacker might, since injected pages are often designed to remain invisible to ordinary visitors. It added that a valid TLS certificate should not be treated as evidence that a destination is safe.

"The domain as a trust signal stopped working long before this, back when malware started being distributed through the CDNs of major players," said ADEX.