Listen to this Post

Introduction
For more than a decade, a sophisticated Indonesian-language cybercriminal network quietly expanded across the global internet. What began as a modest gambling operation mutated into a sprawling digital empire, blending large-scale domain hijacking, malware distribution, covert command-and-control channels, and data theft. The newly published investigation by cybersecurity firm Malanta lifts the curtain on this hidden ecosystem, revealing a threat actor whose operations resemble state-sponsored capabilities rather than ordinary cybercrime. The scale, persistence, and engineering behind this network paint a startling picture of how deeply entrenched illicit gambling and espionage-grade tactics have become in Southeast Asia’s cyber underworld.
Summary of the Original
A Fourteen-Year Shadow Infrastructure Uncovered
Malanta’s investigation exposes an Indonesian-speaking cybercrime group that has been active for more than 14 years. The operation initially started as a small gambling network but has now evolved into one of the world’s most complex criminal infrastructures, reaching a scale commonly associated with state-backed actors. Malanta identified more than 328,000 controlled domains, including 90,125 hijacked domains, 1,481 hijacked subdomains, and over 236,000 purchased gambling assets. Many were shielded behind Cloudflare and U.S.-based hosting providers, masking the true origins of the activity.
A Decade of Exploits and Hijacks
The group relied heavily on exploiting common weaknesses in WordPress sites, PHP applications, expired DNS records, and abandoned cloud services. These weaknesses enabled them to take control of enterprise domains and even government subdomains. Some hijacked government infrastructure hosted sophisticated TLS-terminating NGINX reverse proxies, allowing the attackers to decrypt traffic, steal cookies, and route command-and-control activity through trusted environments. These techniques made their presence exceptionally difficult to detect.
Malware Distribution at Massive Scale
Beyond gambling, the actors constructed a stealthy command-and-control network that distributed malicious Android APKs, exploit kits, and droppers. Over 7,700 domains were connected to AWS S3 buckets containing thousands of Android malware droppers. These apps used Firebase Cloud Messaging for remote control and shared a central C2 endpoint, jp-api.namesvr[.]dev, revealing a coordinated distribution architecture.
Automation, AI, and Social Platform Abuse
Malanta also discovered signs of automated content generation and AI-assisted scaling mechanisms. The group abused burner GitHub accounts, Docker Hub repositories, Scribd uploads, and other platforms to host malware, templates, and SEO-boosting artifacts. In parallel, 51,000 stolen credentials were traded across dark-web markets, many tied to gambling accounts and infected devices. The actors also created more than 480 impersonation domains mimicking Amazon, Slack, Facebook, and similar brands to harvest credentials.
Financial Backing and Possible State Ties
The infrastructure required an estimated $725,000 to $5 million in annual maintenance, indicating substantial financial resources. While the language and victims strongly suggest an Indonesian nexus, fragments of Chinese-language code were discovered, adding ambiguity to the actor’s origins. Malanta has released the full list of associated domains and urges organizations to review DNS settings, monitor new certificates, and secure abandoned cloud assets. The research demonstrates how illicit gambling schemes and espionage-level techniques are merging into a hybridized cyber threat within Indonesia’s rapidly evolving digital underground.
What Undercode Say:
This investigation exposes a threat model that cybersecurity teams can no longer dismiss as ordinary online fraud. The operation’s architecture resembles a long-term, well-funded campaign, built slowly and patiently like an intelligence agency project rather than a gambling scam. Each layer of the infrastructure reveals an intent to persist, camouflage, and scale without triggering alarms. This is the hallmark of an Advanced Persistent Threat, not a traditional cybercriminal syndicate.
The scale of the domain hijacking campaign is particularly alarming. Controlling more than 90,000 hijacked domains means the attackers essentially weaponized the neglected corners of the internet. Enterprises often forget about old domains, dormant cloud objects, or unused DNS records. This group turned those forgotten digital assets into silent carriers for malware, phishing, and C2 channels. It points to a systemic failure in global domain hygiene, one that attackers are exploiting with increasing precision.
What stands out further is the seamless blend of illicit gambling with advanced cyber espionage tooling. Gambling platforms have long been a magnet for cybercriminal funds, but here they served a dual purpose: monetization and concealment. By embedding their activity within a massive gambling ecosystem, the actors created natural traffic noise. Security products are far less likely to flag domains whose traffic resembles entertainment platforms, especially when they sit behind reputable CDNs like Cloudflare.
The Android malware distribution mechanism reflects a growing trend across the APAC region. Mobile-first populations generate lucrative opportunities for threat actors, who use dropper apps and repackaged APKs to infect devices at scale. The shared C2 endpoint found across thousands of droppers indicates centralized operations, suggesting an organized developer team rather than lone actors or small crews.
Automation and AI content generation add another layer of sophistication. Maintaining 328,000 domains manually would be impossible. Automated scripts, possibly enhanced with generative AI tools, allowed the operation to create, update, and camouflage sites at a pace no human team could match. By leveraging GitHub, Docker, Scribd, and other platforms that security teams typically trust, the actors smuggled malicious components through the very channels the industry relies upon for open collaboration.
Financial estimates pointing to millions in annual costs should be taken seriously. Such sustained funding rarely comes from freelance cybercriminal groups. It is far more consistent with organized crime syndicates, politically connected networks, or covert state intelligence projects seeking plausible deniability. Although Indonesian-language indicators dominate, the traces of Chinese code cannot be ignored. Southeast Asia is a hotbed of hybridized cyber operations where criminal groups, nation-state contractors, and rogue operators often intersect.
The main takeaway for defenders is clear: the attack surface extends far beyond active assets. Dangling DNS records, abandoned cloud buckets, expired subdomains, and forgotten web apps are now prime targets. The fact that government subdomains were repurposed into TLS-terminating proxies should be a wake-up call. Attackers are not only stealing domains, they are weaponizing them into trusted malware hubs that bypass traditional security filters.
Organizations must rethink their external asset management strategies. Regular DNS audits, automated certificate monitoring, cloud posture checks, and abandonment prevention policies are no longer optional. They are essential. Malanta’s findings underscore that the most dangerous threats are often the ones hiding in plain sight, embedded within everyday internet infrastructure.
🔍 Fact Checker Results
Malanta’s report confirms more than 328,000 domains linked to the operation. ✅
Evidence shows both gambling and malware activity operating under one infrastructure. ✅
Clear attribution to a specific state actor remains inconclusive. ❌
📊 Prediction
This network is unlikely to vanish soon. 🔮
Expect more APAC-based APTs to merge gambling platforms with espionage infrastructure, especially as mobile malware and cloud hijacking continue rising. Future campaigns may expand into AI-generated fake brands, automated phishing kits, and deeper impersonation of SaaS providers. Organizations that fail to monitor abandoned digital assets may become the next silent victims.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




