Indonesia’s Gambling Industry Reveals Clues of Nationwide Cyber Involvement
A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified. The operation demonstrates advanced infrastructure and methods typically associated with state-sponsored threat actors.
A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified. The operation demonstrates advanced infrastructure and methods typically associated with state-sponsored threat actors.
Security researchers at Malanta have uncovered a significant cyber operation involving illegal gambling, malware distribution, domain hijacking, and infiltration of enterprise and government networks globally. This ecosystem has been operational since at least 2011.
The operation manages over 328,000 domains, including 236,433 domains purchased for gambling, 90,125 hijacked legitimate domains, and 1,481 compromised subdomains.
This extensive infrastructure utilizes cloud platforms such as AWS and Azure, with hosting mainly via Cloudflare and U.S.-based IP addresses. The operation exploits vulnerabilities in WordPress, PHP components, DNS records, and expired cloud resources to misuse trusted domains.
Some compromised government subdomains in Western countries are configured with TLS-terminating reverse proxies, disguising malicious traffic as legitimate HTTPS connections and facilitating session cookie theft.
A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified.
Researchers identified approximately 7,700 domains linked to AWS S3 buckets hosting malicious Android applications with gambling-themed names. These sites are geo-restricted to Indonesian IPs and require registration with local banking details.
These applications function as droppers, downloading additional malicious payloads and using Firebase Cloud Messaging for remote command delivery. Hardcoded credentials and API keys within the apps allow telemetry and management, with communications directed to specific command-and-control domains.
The operation's domain and subdomain hijacking notably impact Western government entities, exploiting session cookies from these domains for potential credential theft. NGINX-based reverse proxies are used for stealthy cybercrime activities.
Supporting Infrastructure and Attribution
The operation includes 38 GitHub accounts hosting malicious content. The threat actor has hijacked at least 1,481 subdomains, primarily hosted on AWS, Azure, and GitHub.
Approximately 480 domain lookalikes impersonate major organizations, with registrations dating back to 2020. Over 51,000 stolen credentials associated with this operation have appeared in dark web forums.
The estimated annual cost for domain registration, hosting, and certificates ranges from $725,000 to $5.3 million, suggesting resources beyond typical cybercriminal enterprises. The operation's longevity and sophistication are indicative of state-sponsored activity rather than conventional financial cybercrime.
Based on reporting by GBHackers.
