Attackers Exploit Google Search and Compromised Thai Domain to Evade Ad Moderation
Security researchers from the ADEX lab have uncovered a novel cloaking method that sidesteps traditional ad‑filtering mechanisms without deploying any custom code on the attacker’s servers. The technique, dubbed “Zero‑Code Cloaking,” leverages a chain of three legitimate web components—a Google search results page, a compromised .ac.th domain, and a standard redirection service—to present different content to users and to the platforms that enforce ad policies.
In the reported scheme, a malicious actor initiates a query that returns a Google search results page containing a link to a hijacked academic domain ending in .ac.th. That domain, which appears to belong to a Thai educational institution, has been compromised to host a benign landing page for search engine crawlers while serving malicious or policy‑violating ads to regular browsers. The final link in the chain points to a conventional URL shortener or redirect service, which forwards the visitor to the target site, effectively masking the true destination from automated moderation tools.
The researchers noted that because each step of the chain uses services that are widely trusted and regularly indexed by search engines, existing detection systems that rely on user‑agent sniffing or server‑side code analysis are easily fooled. Traditional cloaking detection looks for scripts that serve different HTML based on the visitor’s identity; in this case, the content variation occurs across separate, legitimate web properties, eliminating the need for any hidden code on the attacker’s infrastructure.
GBHackers first reported the method, prompting ADEX to conduct a deeper investigation. Their analysis revealed that the compromised .ac.th domain was obtained through a phishing attack on the institution’s administrative staff, allowing the attackers to modify DNS records without raising immediate suspicion. Once in control, the domain could be used to host the benign version of the page that satisfies Google’s crawler, while the malicious payload is delivered only to end users.
Experts warn that the approach could be adopted broadly, especially as advertisers and platforms continue to rely on automated moderation that may not fully account for multi‑step delivery chains. Mitigation may require more sophisticated cross‑domain verification and tighter monitoring of domain ownership changes, particularly for educational and government‑affiliated top‑level domains. ADEX recommends that ad networks incorporate behavioral analysis of redirect patterns and consider the provenance of linked domains when assessing compliance.
While the full scope of the abuse remains under investigation, the discovery underscores the evolving tactics of threat actors who exploit the trust inherent in major internet services. As defenders adapt, the arms race between ad moderation technologies and cloaking strategies is likely to intensify, prompting calls for industry‑wide collaboration to strengthen detection across the entire web ecosystem.
Comments (0)
Be the first to comment.
Join the discussion