A 4-Month Planned Dual-Leverage
SEO Poisoning Attack Against
a Japanese Medical Corporation
PHP Webshell Intrusion · Brand-Impersonation Cloudflare Pages · Google Search Console Hijacking ·
Triple-API Geo-Cloaking — Complete Technical Dissection of an Organized Multi-Stage Campaign
Keywords: Medi Face, 医療法人鳳應会, Toru Chikazawa, 近澤徹, FRAISE CLINIC, SEO poisoning, PHP webshell, geo-cloaking, AMP abuse, Google Search Console hijacking, Judi Online, bulletproof hosting, dual-leverage attack, game theory, von Neumann, Indonesia, medical website hack, Cloudflare Pages abuse
🌐 To Security Researchers, Engineers & White-Hat Hackers Worldwide — An Open Invitation for Volunteer Analysis
Thank you for reading this document. Medi Face, Ltd. (医療法人鳳應会グループ) is publishing the details of this ongoing cyberattack in the interest of public benefit. This is not intended as accusation or retaliation. Our purpose is to share information so that similar attacks do not reach other medical institutions, clinics, or organizations who may be unaware they are already targeted.
| Where Your Expertise Would Help | Context & Background |
|---|---|
| Finding Other Victimized Organizations Medical institutions and companies in Japan / Asia targeted by the same infrastructure |
The same Cloudflare accounts, NameCheap domains, and affiliate IDs may be reused across other active campaigns. Anything you find could be directly handed to an organization that does not yet know it has been compromised. |
| Pointing Out What We Have Missed Independent review of our analysis — corrections, additions, alternate interpretations |
In-house analysis always has limits. If you see a gap in our reasoning, a technique we misidentified, or a layer of the infrastructure we overlooked, we genuinely want to hear it. There is no ego here — only the goal of getting it right. |
| Access Verification from Within Indonesia Cloaking bypass test using Android / iPhone with an Indonesian IP |
Geo-cloaking makes the gambling content structurally invisible from Japan. Only a mobile device physically inside Indonesia can confirm the redirect destination — which is essential for legal proceedings. |
| OSINT on Attacker Infrastructure Passive DNS, WHOIS history, and certificate transparency for each IoC listed below |
The same registrant almost certainly controls additional domains and IPs not yet on our radar. Historical records may reveal the full scale of the operation. |
| Affiliate ID & Payment Chain Analysis Tracing cSyJDyLy and MKPA2AD00002 across prior campaigns |
These IDs connect directly to whoever is collecting the financial proceeds of this crime. Linking them to past campaigns is the fastest path to attribution. |
Republication, citation, and sharing of this document are very welcome (attribution appreciated).
The attackers have already deleted the backdoor files — fgh.php, yomanx498.php, n0bgxdjskd.php, mails.php, follder.php, carrier/sshy.php — and are presumably confident that the evidence has been eliminated.
It has not. The Medi Face legal team has already completed rapid digital forensics on all file remnants.
Filesystem metadata, timestamps, hash values, and 223,701 lines of server access logs are fully preserved. The act of deletion itself constitutes additional evidence of consciousness of guilt.
Forensic analysis of payment-linked IP addresses and tokens associated with the following identifiers has detected the suspected principal organizer's (mastermind's) connection-origin IP address — behind the Indonesian proxy and bulletproof hosting — as originating within Japan: specifically within Tokyo, in the Nagatacho / Roppongi area.
Note: Specific IP addresses and personally identifying information are withheld from this document while the investigation is ongoing. All information is held by the legal team and relevant law enforcement authorities.
A footnote worth recording: it remains unclear whether the attacker was unaware that recovering deleted files from filesystem residues, cache fragments, journal logs, and metadata remnants is standard forensic practice — or simply chose to discount it. Whether ignorance or overconfidence, the distinction hardly matters at this point. Either way, it was the one miscalculation that made attribution possible.
Legal Action The Medi Face, Ltd. legal team is currently considering the filing of criminal charges against the identified mastermind. Applicable statutes under consideration include Japan's Unauthorized Computer Access Law (不正アクセス禁止法), Electronic Business Interference (電子計算機損壊等業務妨害罪), and Defamation (名誉毀損罪), directed at the Tokyo-based connection origin. Parallel MLAT (Mutual Legal Assistance Treaty) requests for international investigative cooperation targeting the Indonesia-based operators are also being prepared by Japanese law enforcement.
On April 4, 2026, an Indonesia-based criminal organization began constructing attack infrastructure targeting Medi Face, Ltd. (株式会社メディフェイス / 医療法人鳳應会グループ), a Japanese medical information services company — more than 120 days before the attack was executed. At 19:33 JST on August 12, 2026, the attack was triggered: PHP webshells were used to seize server-wide control, and SEO redirect code directing users to Indonesian illegal online gambling sites was injected into more than 130 pages across 21 domains.
This paper analyzes the attack in technical detail. What sets this campaign apart is that it was not simply "financially motivated SEO spam." It was a dual-leverage design: simultaneously generating affiliate revenue and constructing permanent false evidence that the victim corporation operates an illegal online casino — a structural threat of a qualitatively different order. Moreover, the technical sophistication of the attacker's infrastructure demands the kind of grudging professional respect that security researchers reserve for genuinely impressive — if criminal — engineering.
The sole purpose is public education and cross-organizational defense.
Why a Medical Corporation Was Targeted
Medi Face, Ltd. and the 医療法人鳳應会グループ (Houokai Medical Group), led by CEO Toru Chikazawa (近澤徹), operate medical information services and online clinic platforms including medi-face.co.jp and FRAISE CLINIC. The attackers conducted detailed reconnaissance more than 120 days in advance, pre-built counterfeit sites impersonating the group's brand names ("medi-face," "fraise-clinic"), and only then executed the attack. This was not an opportunistic compromise or an automated scan — it was a high-sophistication, target-specific organized crime operation.
1.1 Why We Are Publishing This
We publish this document for a single reason: we do not want this to happen to anyone else. Identifying perpetrators, prosecution, and legal remedies are not the purpose of this paper. The facts documented here are a knowledge asset for every medical institution, website operator, and security researcher who needs to be prepared for this class of attack.
The attackers' cloaking architecture was specifically designed so that investigation from within Japan can confirm almost none of the evidence (see Section 5). The eyes and knowledge of the global security community are the only effective countermeasure against this class of crime.
Why This Is Targeted Organized Crime — Not an Opportunistic Attack
Six independent evidence items establish that this was a planned, targeted operation.
| # | Evidence | Significance |
|---|---|---|
| E1 | Cloudflare Pages sites impersonating the victim's brand names (medi-face, fraise-clinic) were created before the attack was executed |
The attacker researched the target's brand names and built impersonation infrastructure months in advance. Impossible in an indiscriminate attack. |
| E2 | Attack domain m4udd0syastvp1d.online registered 2026-04-04; bringmetolife.store registered the following day by the same registrant |
Criminal infrastructure was built in stages beginning 4 months before the attack. Extreme premeditation. |
| E3 | terreagoodboy.store was updated and a new SSL certificate issued exactly 3 days before the attack (August 9, 2026) |
The attack date was determined in advance. Direct forensic evidence of a pre-scheduled operation. |
| E4 | Landing page images uploaded to Imgur 3.5 months before the attack (April 28, 2026) | Visual impersonation content was prepared far in advance. Confirmed via HTTP Last-Modified response headers. |
| E5 | Attacker registered medi-face.pages.dev in Google Search Console using their own Google account (verification token confirmed) |
Manual, deliberate registration of the victim's impersonated brand in Google's own management system. Requires specific target awareness. |
| E6 | First webshell access was a direct URL hit with no preceding reconnaissance (19:33:27 JST) | The attacker already knew the shell URL. Prior access or pre-positioned intelligence had been established. |
2.1 Attack Timeline (Second-Level Precision)
| Timestamp (JST) | Attacker Action | Confidence |
|---|---|---|
| 2026-04-04 | Criminal infrastructure domain registration begins (120 days before attack) | Confirmed |
| 2026-04-05 | Second domain registered consecutively by same registrant | Confirmed |
| 2026-04-28 | Landing page images uploaded to Imgur | Confirmed |
| 2026-08-09 | Attack domain final update / SSL certificate renewal (3 days pre-attack) | Confirmed |
| 2026-08-12 19:33:27 | 🔴 Attack begins — IP 182.10.98.57 (Indonesia) directly activates webshell | Confirmed |
| 19:33:32+ | Server-wide control seized via sustained POST requests | Confirmed |
| 19:41–20:06 | Redundant backdoors deployed across multiple filenames and directories | Confirmed |
| 20:00–20:24 | Simultaneous backdoor deployment across all primary domains | Confirmed |
| 20:24:31 | SEO poisoning content injection begins (page sizes balloon from 6 KB to 80+ KB) | Confirmed |
| 20:37–22:44 | Additional IPs join: 31.56.30.60 (Iran), 103.141.164.246. Multi-operator division-of-labor confirmed. | Confirmed |
| 2026-08-13 04:10–04:52 | Google-InspectionTool + attacker IPs force-crawl defaced pages (forcing Google index registration) | Confirmed |
| 05:03 | Attacker's final confirmation access | Confirmed |
The 5-Layer Attack Infrastructure: Bulletproof Design and Redundant Architecture
One of the most technically notable features of this attack is the precision of its infrastructure design. Rather than relying on any single server or service, the attackers adopted a "bulletproof" architecture with multiple layers and two independent redundant chains. If any one node is taken down or reported, the remaining chain continues operating.
3.1 Chain A — medi-face Route
3.2 Chain B — fraise-clinic Route (Independent Redundant System)
3.3 Logical Layer Architecture
| Layer | Role | Assets Used | Technical Purpose |
|---|---|---|---|
| L0 Victim Sites | SEO authority extraction | Legitimate medical domains | Exploit existing domain authority and backlinks to manipulate Google rankings |
| L1 Brand Impersonation Pages | Visual legitimacy fabrication | medi-face.pages.dev / fraise-clinic.pages.dev | Mimic victim brand; make counterfeit pages indistinguishable from official services |
| L2 Cloaking Engine | Target filtering / evidence destruction | jutsu-seribu-bayangan.pages.dev / wewillrockyou.pages.dev | Pass only Indonesian mobile users; route all others to harmless loop |
| L3 Final Gambling Sites | Monetization | terreagoodboy.store / bringmetolife.store | User registration at illegal gambling sites; affiliate revenue generation |
| L4 C2 Command & Control | Attacker coordination | Telegram (web.telegram.org) | Share shell URLs, divide tasks, confirm progress |
Technical Analysis of Brand-Impersonation Cloudflare Pages
The attackers created brand-impersonating Pages (medi-face.pages.dev, fraise-clinic.pages.dev) using a Cloudflare account entirely separate from — and unknown to — the victim corporation, specifically designed to be mistaken for the victim's official online presence.
4.1 medi-face.pages.dev — Technical Analysis
| Attribute | Observed Value | Technical Intent |
|---|---|---|
| HTML Format | <html amp lang="id"> |
AMP (Accelerated Mobile Pages) format. Using Google's official spec simultaneously achieves: Google mobile search priority ranking, AMP CDN distribution, and the visual legitimacy of a "Google-optimized page." See Section 6. |
| Language / Region | lang="id", content-language: id |
Indonesian language targeting. The intended victim population is precisely defined. |
| Google Site Verification | 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc |
Attacker has already registered this counterfeit page in Google Search Console. Querying Google with this token can identify the attacker's Google account — critical forensic evidence. |
| OG Image Host | ik.imagekit.io/dewi11/d44d164b-… |
ImageKit.io CDN — account name "dewi11". An additional service account under attacker control. |
| Robots Directive | content="index, follow" |
Actively instructs search engines to index. SEO contamination intent is unambiguous. |
| All Link Destinations | jutsu-seribu-bayangan.pages.dev (3 locations) |
Every user interaction — including the "login" button — routes to the cloaking engine. |
| Page Title | "🛡️ Halaman Resmi x Medi Face Pelembut Wajah" | "Official Medi Face page" in Indonesian. Direct brand impersonation. |
| Nawala Mention | "anti nawala" in meta description | Nawala is the Indonesian government's illegal-site filtering system. Advertising bypass capability explicitly targets Indonesian users — a sophisticated localization strategy demonstrating deep knowledge of the Indonesian regulatory environment. |
4.2 fraise-clinic.pages.dev/DETIKBET — Technical Analysis
| Attribute | Observed Value | Technical Intent |
|---|---|---|
| HTML Format | <html ⚡ lang="id"> |
AMP format (⚡ is the alternate AMP notation) |
| Image Host | https://i.imgur.com/lyf87zA.pngLast-Modified: 2026-04-28 |
Uploaded to Imgur approximately 3.5 months before the attack. Direct evidence that the attack template was prepared far in advance. Confirmed via HTTP response headers. |
| All Link Destinations | https://wewillrockyou.pages.dev/ |
Routes to Chain B's independent cloaking engine. |
Complete Code Analysis of the Cloaking Engine
jutsu-seribu-bayangan.pages.dev (an attacker-controlled Cloudflare Pages instance). This code completely explains why Japanese investigators and security researchers are unable to observe any gambling content whatsoever. It was obtained from a publicly accessible endpoint on the open internet.
// ===================== CLOAKING ENGINE (actual source code) ===================== // Source: jutsu-seribu-bayangan.pages.dev (attacker-controlled Cloudflare Pages) // Retrieved: 2026-08-13 // Design: 3-layer filtering — Layer1: Device → Layer2: Country → Layer3: Routing (function() { // ★ Configuration values (this is the attacker's "evidence") const TARGET_URL = "https://terreagoodboy.store/register?ref=MKPA2AD00002"; const FALLBACK_URL = "https://jutsu-seribu-bayangan.pages.dev/"; // loops to itself = evidence destruction // ─── Layer 1: Device Detection ───────────────────────────────────────────── // Only Android / iPhone pass. PCs, tablets, and bots are immediately // sent to fallback without country detection. // → An investigator accessing via PC is routed to the harmless loop instantly. function detectDevice() { const ua = navigator.userAgent || navigator.vendor || window.opera || ''; if (/android/i.test(ua)) return 'Android'; if (/iPhone|iPod/i.test(ua)) return 'iPhone'; if (/iPad/i.test(ua)) return 'iPad'; return 'Other'; // PC → immediate fallback } // ─── Layer 2: Country Detection (Triple Failover + 3-Second Timeout) ─────── // Only Indonesia ("ID") passes. Japan, US, Europe, VPN users → fallback. // Three IP geolocation APIs tried in cascade; if all fail → fallback. // → Even a researcher using a VPN cannot pass unless the IP reads as Indonesia. function detectCountryWithTimeout(callback) { let isResolved = false; let timeoutId = null; function resolveCountry(code) { if (isResolved) return; isResolved = true; if (timeoutId) clearTimeout(timeoutId); callback(code); } // If no determination within 3 seconds → "unknown" → fallback (fail-safe) timeoutId = setTimeout(() => resolveCountry('unknown'), 3000); // API ①: ipapi.co (primary) fetch('https://ipapi.co/json/') .then(r => r.json()).then(d => resolveCountry(d.country_code || '')) .catch(() => { // API ②: ip-api.com (fallback 1) fetch('https://ip-api.com/json/') .then(r => r.json()).then(d => resolveCountry(d.countryCode || '')) .catch(() => { // API ③: ipinfo.io (fallback 2) fetch('https://ipinfo.io/json') .then(r => r.json()).then(d => resolveCountry(d.country || '')) .catch(() => resolveCountry('unknown')); // all APIs down → fallback }); }); } // ─── Layer 3: Final Routing Decision ────────────────────────────────────── function processCloaking() { const device = detectDevice(); // All PCs (including iPad) → immediate fallback (investigators / researchers cannot pass) if (device !== 'Android' && device !== 'iPhone') { window.location.replace(FALLBACK_URL); return; } // Mobile only: run country check detectCountryWithTimeout(function(countryCode) { const isIndonesia = (countryCode.toUpperCase() === 'ID'); if (isIndonesia) { // ✅ Indonesian mobile → gambling site (affiliate revenue generated) window.location.replace(TARGET_URL); } else { // ⛔ Japanese / Western / unknown → loops to itself (leaves no evidence) window.location.replace(FALLBACK_URL); } }); } processCloaking(); // entry point })();Figure 3: Cloaking engine — complete source code (retrieved from jutsu-seribu-bayangan.pages.dev)
5.1 Behavior by Visitor Type
| Visitor Type | Layer 1 — Device | Layer 2 — Country | Outcome |
|---|---|---|---|
| Indonesian smartphone user | Android/iPhone ✓ | ID ✓ | → Redirected to illegal gambling site |
| Japanese law enforcement (PC) | Other → immediate fallback | Not evaluated | → Harmless loop (no evidence visible) |
| Japanese police (smartphone) | iPhone ✓ | JP → non-ID | → Harmless loop (no evidence visible) |
| Googlebot (crawler) | Other (bot UA) | Not evaluated | → Harmless loop |
| Security researcher (VPN) | Passes Layer 1 | VPN IP → non-ID | → Harmless loop (no evidence visible) |
| API failure / timeout (>3 seconds) | Passes Layer 1 | unknown | → Harmless loop (fail-safe) |
Ten Advanced Anti-Detection and Evasion Techniques
We analyze each technique employed in this attack from a security engineering perspective. Those demonstrating particularly high technical craftsmanship are marked ★ Grudging Respect — a professional acknowledgment of the adversary's engineering even while condemning the application.
ipapi.co → ip-api.com → ipinfo.io) are used in a cascaded failover with a 3-second timeout. If the primary API is unavailable, the secondary and tertiary take over. If all APIs fail, the result defaults to fallback (= evidence destruction). This eliminates single-API dependency risk — an industrial-grade engineering decision.
<html amp lang="id">), the attackers simultaneously achieved: ① priority placement in Google mobile search results, ② distribution via Google's AMP CDN (cdn.ampproject.org) — requiring no independent infrastructure, and ③ the visual legitimacy of a "page optimized and recognized by Google." Weaponizing Google's own trusted infrastructure is a remarkably refined technique.
medi-face.pages.dev and fraise-clinic.pages.dev using the victim's exact brand names. End users see a URL reading "medi-face.pages.dev," which is visually indistinguishable from an official service. Additionally, by serving through Cloudflare's CDN, the attacker's origin IP is masked, making infrastructure attribution difficult.
medi-face.pages.dev in Google Search Console using their own Google account (verification token: 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc). This grants: ① the ability to submit sitemaps and force index registration, ② monitoring and management of the page's Google search presence, and ③ the search-engine credibility of a "verified site owner." The attacker effectively seized SEO management rights over the victim's brand namespace on Google.
medi-face.pages.dev explicitly state "anti nawala." Nawala is the Indonesian government's illegal-site blocking system — gambling sites are blocked within Indonesia via Nawala. The attackers bypassed this filter via Cloudflare CDN, and then actively advertised this bypass capability as a selling point to the target audience. This demonstrates deep understanding of the Indonesian regulatory environment and an aggressive localization strategy.
wp-admin/js/widgets/media-widgets.php, wp-includes/images/image-data.php, wp-includes/js/tinymce/skins/lightgray/fonts/tinymce.php, etc. Visual inspection and directory listings make these difficult to distinguish from legitimate files, providing a key persistence mechanism.
dewi11); landing page images on Imgur (a legitimate image-sharing service). By avoiding the attackers' own infrastructure for these assets, URL-based blocklist inclusion is made significantly harder, and IP-based attribution of the image host is neutralized.
Referer: https://web.telegram.org/ entries. The attacker group coordinated the attack via a private Telegram channel — sharing webshell URLs, dividing tasks, and confirming progress in real time. Telegram's end-to-end encryption and low traceability make it an effective C2 channel that is very difficult for law enforcement to access.
Game-Theoretic Analysis: The Dual-Leverage Dominant Strategy
Analyzing this attack within the framework of John von Neumann's (1903–1957) extensive-form game theory reveals that the attackers' strategy is a design that transcends simple financial theft. We describe this in purely mathematical terms, free of emotional framing.
7.1 Dual Leverage: A Dominant Strategy With Two Independent Payoff Streams
This attack was designed to generate two independent revenue streams from a single infrastructure investment:
| Payoff Stream | Mechanism | Properties |
|---|---|---|
| Stream 1: Immediate Financial Revenue | Route Indonesian users to illegal gambling sites → affiliate revenue (IDs: cSyJDyLy, MKPA2AD00002) |
Certain · Immediate · Ongoing |
| Stream 2: Long-Term Legal Leverage | Build gambling content under victim's brand (medi-face.pages.dev) → create the appearance that the victim operates an illegal casino → hold the option of a false report to authorities |
Optional · Long-term · Attack-controlled timing |
7.2 Cloaking as Artificial Information Asymmetry
In Harsanyi's (1967) incomplete information game theory, information asymmetry fundamentally alters the structure of a game. The cloaking system in this attack artificially constructed the following asymmetry:
7.3 The Defender's Optimal Response: Complete Public Disclosure as the Equilibrium Strategy
| D: Silence / Concealment | D: Partial Response | D: Full Disclosure + Legal Action | |
|---|---|---|---|
| A: Exercise Nuclear Button (false report to authorities) |
A: High, D: −∞ | A: High, D: −Large | A: Minimum, D: −Minimum |
| A: Continue Revenue | A: Medium, D: −Medium | A: Medium, D: −Medium | A: Minimum, D: −Minimum ← Equilibrium |
Table 1: Payoff matrix (subgame perfect equilibrium analysis) — Defender's dominant response is "Full Disclosure + Legal Action"
By backward induction, the defender's dominant strategy is complete public disclosure. The attacker's "nuclear button" — the option to falsely report the victim as an illegal casino operator to authorities — loses all its leverage value the moment its existence becomes fully public knowledge. The publication of this paper is the execution of that equilibrium strategy.
Confirmed IoCs — Full Indicator List
The following IoCs are released to the security community. Free use for defensive, research, and investigative purposes is explicitly permitted.
182.10.98.57 # Indonesia — Primary operator, initial webshell activation (19:33:27 JST) 103.20.83.86 # Indonesia — Highest frequency access throughout attack 114.10.65.118 # Indonesia — Telkom Indonesia 103.236.188.241 # Indonesia 180.243.11.97 # Indonesia — Telkom Indonesia (Telkomsel) 31.56.30.60 # Iran — Secondary operator (joined 20:37 JST) 103.141.164.246 # Unknown — Additional participant 2400:9800::/32 # Telkomsel IPv6 range (Indonesia)
m4udd0syastvp1d.online # NameCheap · 2026-04-04 · IP: 198.54.120.152 · Redirect node bringmetolife.store # NameCheap · 2026-04-05 · Gambling dest · Affiliate: cSyJDyLy terreagoodboy.store # NameCheap · updated 2026-08-09 · IPs: 45.194.53.52 / 45.194.53.26 jutsu-seribu-bayangan.pages.dev # Cloudflare Pages (attacker acct) · Cloaking engine A wewillrockyou.pages.dev # Cloudflare Pages (attacker acct) · Cloaking engine B medi-face.pages.dev # Cloudflare Pages (attacker acct) · BRAND IMPERSONATION A fraise-clinic.pages.dev # Cloudflare Pages (attacker acct) · BRAND IMPERSONATION B
Gambling Affiliate ID #1: cSyJDyLy (bringmetolife.store) Gambling Affiliate ID #2: MKPA2AD00002 (terreagoodboy.store) Google Search Console Token: 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc ImageKit.io Account: dewi11 (ik.imagekit.io/dewi11/) Imgur Image ID: lyf87zA.png (uploaded 2026-04-28) Registrar Privacy Shield: Withheld for Privacy ehf (Reykjavik, Iceland) Common Nameserver: nile.ns.cloudflare.com / sasha.ns.cloudflare.com C2 Channel: Telegram (confirmed via Referer: web.telegram.org)
fgh.php # Initial shell — direct access without reconnaissance yomanx498.php # Secondary shell (redundancy) n0bgxdjskd.php # Secondary shell mails.php # Shell with mail-mimicking filename follder.php # Shell with typo-based obfuscation carrier/sshy.php # Shell in subdirectory
nile.ns / sasha.ns.cloudflare.com). All use Withheld for Privacy ehf (Iceland) for privacy protection. These form a consistent "criminal infrastructure template" established by the same threat actor. Additional domains matching this pattern are highly likely to exist.
Conclusion: What This Case Demonstrates About 2020s Cybercrime
This incident represents an archetypal case study in the evolution of cybercrime, notable in the following respects:
- Democratization of APT-grade Techniques: Advance reconnaissance, premeditated planning, staged infrastructure construction, and multi-operator division of labor — previously associated with nation-state actors — are now routinely adopted by financially motivated criminal organizations.
- Weaponization of Legitimate Infrastructure: Cloudflare Pages, Google AMP, ImageKit, Imgur, and Telegram are all legitimate, highly-reputable services. Traditional IP-reputation-based defenses are structurally ineffective against this class of attack.
- Investigative Neutralization by Design: A cloaking architecture that makes evidence structurally invisible to Japanese investigators is a new challenge that requires international investigative cooperation across internet boundaries. This is not a technical gap that can be closed unilaterally.
- Dual-Use Threat Structure: Simultaneously realizing SEO revenue and legal leverage from a single infrastructure is a new threat category that transcends conventional cybercrime taxonomies.
And finally: complete transparency is the optimal defense. The leverage value of the "false evidence" the attackers constructed evaporates the moment it becomes fully public knowledge. This document is the record of that moment — and a public-benefit gift intended to prevent the next victim.
References & Theoretical Frameworks
- von Neumann, J. & Morgenstern, O. (1944). Theory of Games and Economic Behavior. Princeton University Press.
- Harsanyi, J.C. (1967). Games with incomplete information played by "Bayesian" players. Management Science, 14(3), 159–182.
- Schelling, T.C. (1960). The Strategy of Conflict. Harvard University Press.
- MITRE ATT&CK Framework v14 — T1505.003 (Web Shell), T1027 (Obfuscated Files), T1583 (Acquire Infrastructure), T1036 (Masquerading), T1491.002 (External Defacement).
- Google AMP Project. (2026). AMP HTML Specification. ampproject.org.
- Netcraft Phishing Reports: UUID
dPORnP7rYNAeVqvZgbexk6difZ5ukR7N,URyTgd5sZ8tjF0ogh2EspK7SdyRz816J. - JPCERT/CC. (2026). Incident Report MF-2026-0812.
- ID-SIRTII/CC. (2026). Cross-border IoC sharing — Case MF-2026-0812.