Attackers Have Hijacked Trusted Domains to Cloak Ad Traffic
A new cloaking technique is weaponizing government and academic websites to bypass automated ad moderation.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you still trust the legitimacy of government or educational websites you visit online?
Security researchers have identified a sophisticated cloaking method that routes advertisement traffic through compromised public-sector and university websites. By hosting malicious content on trusted domains, attackers effectively mask the final destination of illicit traffic from automated security crawlers.
Why it matters
The tactic exploits the inherent trust that ad moderation systems place in government and educational domains, allowing malicious campaigns to evade detection. This exploitation of institutional infrastructure has created an underground marketplace for high-reputation domains, complicating efforts to maintain secure digital environments.
Netcraft identified 15,000 government and academic domains for sale on underground marketplaces. This infrastructure facilitates campaigns like that reported in Thailand, where 30 million gambling-related URLs were injected into 1,000 public-sector sites.
The players
ADEX
A cybersecurity research firm focused on identifying and reporting novel ad-fraud and traffic-cloaking methodologies.
Netcraft
A cybersecurity services company providing threat intelligence through domain monitoring and web analytics.
Thai Ministry of Digital Economy and Society
The national government body responsible for regulating Thailand's digital infrastructure and responding to cyber incidents.
Indonesian Ministry of Communication and Informatics
The Indonesian government agency tasked with managing public internet safety and blocking unauthorized web activity.
The details
Attackers gain entry to legitimate institutional websites and inject casino-related pages or scripts to redirect unsuspecting users. By funneling traffic through these high-reputation domains, the method tricks automated ad moderators into treating the traffic as safe. The process involves a multi-step redirection where the user follows an ad link to a compromised legitimate site, which then silently hands them off to the intended malicious destination.
Timeline
August 2025: An academic study documented compromised Indonesian domains.
September 29, 2026: ADEX identified and reported the cloaking tactic.
The Tech Race
This development represents a shift in the cat-and-mouse race between ad moderators and fraud syndicates. As automated crawlers become more adept at blacklisting known malicious domains, attackers are forced to compromise high-trust institutional infrastructure to keep their operations active.
Users interacting with government or academic portals may be redirected without notice if those sites have been compromised. While organizations are actively blocking and remediating these sites, the scale of the injections means that site visitors should remain cautious of unexpected redirects from trusted sources.
The takeaway
The weaponization of institutional domains illustrates that high-authority URLs are now primary targets for sophisticated ad-cloaking syndicates. Organizations must monitor for unauthorized scripts and external traffic redirects on their subdomains to prevent being used as vehicles for malicious ad campaigns.
Further reading
For more on evolving threat vectors and digital defense, visit our Cybersecurity section.
Source note: This article includes information reported by SecurityBrief Asia.
Live Poll
Do you still trust the legitimacy of government or educational websites you visit online?







