Gambling and Governance Intersect in Indonesia Amid Rising Cyber Concerns

A recently published investigation by cybersecurity firm Malanta has revealed a vast Indonesian-speaking cybercrime operation that has been operating for more than 14 years.

What started as a small-scale gambling activity has evolved into one of the world’s most complex state‑sponsored‑level infrastructures, combining gambling, malware distribution, domain hijacking, and large-scale data theft.

A Decade-Long Hidden Infrastructure

According to Malanta, the threat actor controls over 328,000 domains, including 90,125 hijacked domains, 1,481 hijacked subdomains, and over 236,000 purchased gambling sites, many of which are hosted behind Cloudflare with U.S.-based IPs.

The operation’s scale and persistence indicate a well-funded, APAC-based Advanced Persistent Threat (APT) active since at least 2011.

The attackers systematically exploited WordPress and PHP vulnerabilities, dangling DNS records, and expired cloud assets to hijack legitimate domains from enterprises and government agencies.

Some hijacked government subdomains were found to host TLS-terminating NGINX reverse proxies, allowing the attackers to decrypt traffic, steal cookies, and tunnel command‑and‑control (C2) traffic through trusted websites, making detection extremely difficult.

In addition to building gambling networks, the infrastructure functions as a stealth C2 ecosystem, delivering malicious Android APKs and distributing exploit kits.

Over 7,700 domains were linked to public AWS S3 buckets hosting thousands of Android droppers that install further malware, access external storage, and use Google Firebase Cloud Messaging for remote control.

Many APKs shared the same C2 domain, jp-api. namesvr[.]dev, revealing a coordinated distribution mechanism.

Social Media, Automation, and State‑Level Capabilities

Malanta’s researchers found evidence of automation and AI-generated content used to maintain the ecosystem’s growth and persistence.

The actor also leveraged burner GitHub accounts, Docker Hub profiles, and Scribd uploads to host malicious files, templates, and verification artifacts often used to boost search rankings and legitimize hijacked sites.

Gambling governance Indonesia
Gambling governance in Indonesia

Over 51,000 stolen credentials linked to the gambling sites and infected devices were found traded across dark‑web forums.

Researchers also uncovered 480 domain lookalikes impersonating major companies such as Slack, Amazon, and Facebook, likely to support phishing and credential harvesting.

The infrastructure’s estimated annual maintenance cost, ranging from $725,000 to $5 million, suggests organized financial backing consistent with state-level operations.

While the content and victims strongly indicate Indonesian connections, traces of Chinese-language elements were occasionally found in the codebase.

Malanta has publicly released the complete list of domains associated with this APT and urged organizations to audit their DNS settings, monitor new certificate issuances, and remediate dangling cloud resources.

The research underscores how illicit gambling operations can intertwine with espionage‑level cyber tactics, blurring the line between digital crime and state‑sponsored activity in Indonesia’s growing cyber underworld.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

Priya
Priya
Priya is a Security Reporter who tracks malware campaigns, exploit kits, and ransomware operations. Her reporting highlights technical indicators and attack patterns that matter to defenders

Trending News

Related Stories