Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Indonesia’s Gambling Industry Reveals Clues of Nationwide Cyber Involvement

A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified. The operation demonstrates advanced infrastructure and methods typically associated with state-sponsored threat actors.

A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified. The operation demonstrates advanced infrastructure and methods typically associated with state-sponsored threat actors.

Security researchers at Malanta have uncovered a significant cyber operation involving illegal gambling, malware distribution, domain hijacking, and infiltration of enterprise and government networks globally. This ecosystem has been operational since at least 2011.

The operation manages over 328,000 domains, including 236,433 domains purchased for gambling, 90,125 hijacked legitimate domains, and 1,481 compromised subdomains.

This extensive infrastructure utilizes cloud platforms such as AWS and Azure, with hosting mainly via Cloudflare and U.S.-based IP addresses. The operation exploits vulnerabilities in WordPress, PHP components, DNS records, and expired cloud resources to misuse trusted domains.

Some compromised government subdomains in Western countries are configured with TLS-terminating reverse proxies, disguising malicious traffic as legitimate HTTPS connections and facilitating session cookie theft.

A comprehensive Indonesian-speaking cybercrime operation, active for over 14 years, has been identified.
Anna Fields · Thehackingpost

Researchers identified approximately 7,700 domains linked to AWS S3 buckets hosting malicious Android applications with gambling-themed names. These sites are geo-restricted to Indonesian IPs and require registration with local banking details.

These applications function as droppers, downloading additional malicious payloads and using Firebase Cloud Messaging for remote command delivery. Hardcoded credentials and API keys within the apps allow telemetry and management, with communications directed to specific command-and-control domains.

The operation's domain and subdomain hijacking notably impact Western government entities, exploiting session cookies from these domains for potential credential theft. NGINX-based reverse proxies are used for stealthy cybercrime activities.

Supporting Infrastructure and Attribution

The operation includes 38 GitHub accounts hosting malicious content. The threat actor has hijacked at least 1,481 subdomains, primarily hosted on AWS, Azure, and GitHub.

Advertisement

Approximately 480 domain lookalikes impersonate major organizations, with registrations dating back to 2020. Over 51,000 stolen credentials associated with this operation have appeared in dark web forums.

The estimated annual cost for domain registration, hosting, and certificates ranges from $725,000 to $5.3 million, suggesting resources beyond typical cybercriminal enterprises. The operation's longevity and sophistication are indicative of state-sponsored activity rather than conventional financial cybercrime.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories