ACTIVE INCIDENT — MF-2026-0812 — ONGOING CYBERATTACK — PUBLIC DISCLOSURE DOCUMENT
Security Case Study — Public Disclosure — MF-2026-0812

A 4-Month Planned Dual-Leverage
SEO Poisoning Attack Against
a Japanese Medical Corporation

PHP Webshell Intrusion · Brand-Impersonation Cloudflare Pages · Google Search Console Hijacking ·
Triple-API Geo-Cloaking — Complete Technical Dissection of an Organized Multi-Stage Campaign

Published by: Medi Face, Ltd. / 株式会社メディフェイス / 医療法人鳳應会グループ Cybersecurity Response Team
Date: August 14, 2026    Case Reference: MF-2026-0812    Classification: Public Disclosure — Issued for Public Benefit

Keywords: Medi Face, 医療法人鳳應会, Toru Chikazawa, 近澤徹, FRAISE CLINIC, SEO poisoning, PHP webshell, geo-cloaking, AMP abuse, Google Search Console hijacking, Judi Online, bulletproof hosting, dual-leverage attack, game theory, von Neumann, Indonesia, medical website hack, Cloudflare Pages abuse

🌐 To Security Researchers, Engineers & White-Hat Hackers Worldwide — An Open Invitation for Volunteer Analysis

Thank you for reading this document. Medi Face, Ltd. (医療法人鳳應会グループ) is publishing the details of this ongoing cyberattack in the interest of public benefit. This is not intended as accusation or retaliation. Our purpose is to share information so that similar attacks do not reach other medical institutions, clinics, or organizations who may be unaware they are already targeted.

Why We Are Reaching Out Given how methodical and malicious this campaign is, we believe the same criminal group is very likely running parallel attacks against other medical corporations, clinics, and organizations in Japan and across Asia right now — organizations that have no idea they are being victimized. Beyond that, we are certain that our own internal analysis has blind spots: things we have missed, angles we have not considered, and infrastructure we have not yet found. If any of that resonates with you, we would genuinely welcome your involvement.
Where Your Expertise Would HelpContext & Background
Finding Other Victimized Organizations
Medical institutions and companies in Japan / Asia targeted by the same infrastructure
The same Cloudflare accounts, NameCheap domains, and affiliate IDs may be reused across other active campaigns. Anything you find could be directly handed to an organization that does not yet know it has been compromised.
Pointing Out What We Have Missed
Independent review of our analysis — corrections, additions, alternate interpretations
In-house analysis always has limits. If you see a gap in our reasoning, a technique we misidentified, or a layer of the infrastructure we overlooked, we genuinely want to hear it. There is no ego here — only the goal of getting it right.
Access Verification from Within Indonesia
Cloaking bypass test using Android / iPhone with an Indonesian IP
Geo-cloaking makes the gambling content structurally invisible from Japan. Only a mobile device physically inside Indonesia can confirm the redirect destination — which is essential for legal proceedings.
OSINT on Attacker Infrastructure
Passive DNS, WHOIS history, and certificate transparency for each IoC listed below
The same registrant almost certainly controls additional domains and IPs not yet on our radar. Historical records may reveal the full scale of the operation.
Affiliate ID & Payment Chain Analysis
Tracing cSyJDyLy and MKPA2AD00002 across prior campaigns
These IDs connect directly to whoever is collecting the financial proceeds of this crime. Linking them to past campaigns is the fastest path to attribution.
Share findings with us at: info@medi-face.co.jp   Reference: MF-2026-0812
Republication, citation, and sharing of this document are very welcome (attribution appreciated).
Breaking Update Updated: 2026-08-14
⚠ Forensics Complete: Deleting the Files Does Not Destroy the Evidence

The attackers have already deleted the backdoor files — fgh.php, yomanx498.php, n0bgxdjskd.php, mails.php, follder.php, carrier/sshy.php — and are presumably confident that the evidence has been eliminated. It has not. The Medi Face legal team has already completed rapid digital forensics on all file remnants. Filesystem metadata, timestamps, hash values, and 223,701 lines of server access logs are fully preserved. The act of deletion itself constitutes additional evidence of consciousness of guilt.

📍 Mastermind Connection-Origin IP Located Within Japan — Tokyo, Nagatacho / Roppongi Area

Forensic analysis of payment-linked IP addresses and tokens associated with the following identifiers has detected the suspected principal organizer's (mastermind's) connection-origin IP address — behind the Indonesian proxy and bulletproof hosting — as originating within Japan: specifically within Tokyo, in the Nagatacho / Roppongi area.

Gambling Affiliate ID #1: cSyJDyLy — payment chain traced Gambling Affiliate ID #2: MKPA2AD00002 — payment chain traced Google Search Console Token: 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc ImageKit.io Account: dewi11 (ik.imagekit.io/dewi11/) Imgur Image ID: lyf87zA.png (uploaded 2026-04-28) Privacy Shield: Withheld for Privacy ehf, Reykjavik, Iceland

Note: Specific IP addresses and personally identifying information are withheld from this document while the investigation is ongoing. All information is held by the legal team and relevant law enforcement authorities.

A footnote worth recording: it remains unclear whether the attacker was unaware that recovering deleted files from filesystem residues, cache fragments, journal logs, and metadata remnants is standard forensic practice — or simply chose to discount it. Whether ignorance or overconfidence, the distinction hardly matters at this point. Either way, it was the one miscalculation that made attribution possible.

⚖ Criminal Proceedings Under Consideration

Legal Action The Medi Face, Ltd. legal team is currently considering the filing of criminal charges against the identified mastermind. Applicable statutes under consideration include Japan's Unauthorized Computer Access Law (不正アクセス禁止法), Electronic Business Interference (電子計算機損壊等業務妨害罪), and Defamation (名誉毀損罪), directed at the Tokyo-based connection origin. Parallel MLAT (Mutual Legal Assistance Treaty) requests for international investigative cooperation targeting the Indonesia-based operators are also being prepared by Japanese law enforcement.

ABSTRACT

On April 4, 2026, an Indonesia-based criminal organization began constructing attack infrastructure targeting Medi Face, Ltd. (株式会社メディフェイス / 医療法人鳳應会グループ), a Japanese medical information services company — more than 120 days before the attack was executed. At 19:33 JST on August 12, 2026, the attack was triggered: PHP webshells were used to seize server-wide control, and SEO redirect code directing users to Indonesian illegal online gambling sites was injected into more than 130 pages across 21 domains.

This paper analyzes the attack in technical detail. What sets this campaign apart is that it was not simply "financially motivated SEO spam." It was a dual-leverage design: simultaneously generating affiliate revenue and constructing permanent false evidence that the victim corporation operates an illegal online casino — a structural threat of a qualitatively different order. Moreover, the technical sophistication of the attacker's infrastructure demands the kind of grudging professional respect that security researchers reserve for genuinely impressive — if criminal — engineering.

The sole purpose is public education and cross-organizational defense.

1. PREFACE

Why a Medical Corporation Was Targeted


⚠ Particularly Malicious Element The targets of this attack are medical corporations, clinics, and health information services — organizations that carry public trust for patient health. Google classifies medical websites as YMYL (Your Money or Your Life) and demands the highest levels of trustworthiness. The attackers deliberately exploited that elevated domain authority. Patients searching for medical information were redirected to illegal gambling sites. This is not merely an economic crime — it is an attack on public health infrastructure.

Medi Face, Ltd. and the 医療法人鳳應会グループ (Houokai Medical Group), led by CEO Toru Chikazawa (近澤徹), operate medical information services and online clinic platforms including medi-face.co.jp and FRAISE CLINIC. The attackers conducted detailed reconnaissance more than 120 days in advance, pre-built counterfeit sites impersonating the group's brand names ("medi-face," "fraise-clinic"), and only then executed the attack. This was not an opportunistic compromise or an automated scan — it was a high-sophistication, target-specific organized crime operation.

1.1 Why We Are Publishing This

We publish this document for a single reason: we do not want this to happen to anyone else. Identifying perpetrators, prosecution, and legal remedies are not the purpose of this paper. The facts documented here are a knowledge asset for every medical institution, website operator, and security researcher who needs to be prepared for this class of attack.

The attackers' cloaking architecture was specifically designed so that investigation from within Japan can confirm almost none of the evidence (see Section 5). The eyes and knowledge of the global security community are the only effective countermeasure against this class of crime.

2. OVERVIEW

Why This Is Targeted Organized Crime — Not an Opportunistic Attack


Six independent evidence items establish that this was a planned, targeted operation.

#EvidenceSignificance
E1 Cloudflare Pages sites impersonating the victim's brand names (medi-face, fraise-clinic) were created before the attack was executed The attacker researched the target's brand names and built impersonation infrastructure months in advance. Impossible in an indiscriminate attack.
E2 Attack domain m4udd0syastvp1d.online registered 2026-04-04; bringmetolife.store registered the following day by the same registrant Criminal infrastructure was built in stages beginning 4 months before the attack. Extreme premeditation.
E3 terreagoodboy.store was updated and a new SSL certificate issued exactly 3 days before the attack (August 9, 2026) The attack date was determined in advance. Direct forensic evidence of a pre-scheduled operation.
E4 Landing page images uploaded to Imgur 3.5 months before the attack (April 28, 2026) Visual impersonation content was prepared far in advance. Confirmed via HTTP Last-Modified response headers.
E5 Attacker registered medi-face.pages.dev in Google Search Console using their own Google account (verification token confirmed) Manual, deliberate registration of the victim's impersonated brand in Google's own management system. Requires specific target awareness.
E6 First webshell access was a direct URL hit with no preceding reconnaissance (19:33:27 JST) The attacker already knew the shell URL. Prior access or pre-positioned intelligence had been established.

2.1 Attack Timeline (Second-Level Precision)

Timestamp (JST)Attacker ActionConfidence
2026-04-04Criminal infrastructure domain registration begins (120 days before attack)Confirmed
2026-04-05Second domain registered consecutively by same registrantConfirmed
2026-04-28Landing page images uploaded to ImgurConfirmed
2026-08-09Attack domain final update / SSL certificate renewal (3 days pre-attack)Confirmed
2026-08-12 19:33:27🔴 Attack begins — IP 182.10.98.57 (Indonesia) directly activates webshellConfirmed
19:33:32+Server-wide control seized via sustained POST requestsConfirmed
19:41–20:06Redundant backdoors deployed across multiple filenames and directoriesConfirmed
20:00–20:24Simultaneous backdoor deployment across all primary domainsConfirmed
20:24:31SEO poisoning content injection begins (page sizes balloon from 6 KB to 80+ KB)Confirmed
20:37–22:44Additional IPs join: 31.56.30.60 (Iran), 103.141.164.246. Multi-operator division-of-labor confirmed.Confirmed
2026-08-13 04:10–04:52Google-InspectionTool + attacker IPs force-crawl defaced pages (forcing Google index registration)Confirmed
05:03Attacker's final confirmation accessConfirmed
Figure 1: Attack Timeline (April–August 2026) — Confirmed facts only
3. ATTACK INFRASTRUCTURE

The 5-Layer Attack Infrastructure: Bulletproof Design and Redundant Architecture


One of the most technically notable features of this attack is the precision of its infrastructure design. Rather than relying on any single server or service, the attackers adopted a "bulletproof" architecture with multiple layers and two independent redundant chains. If any one node is taken down or reported, the remaining chain continues operating.

3.1 Chain A — medi-face Route

[L0: VICTIM SITES] medi-face.co.jp / mentalcheck.jp / etc. (legitimately-owned, hacked pages) ↓ SEO spam + gambling site names injected (RAJAMAHJONG / SADEWA77 / etc.) [L1: BRAND IMPERSONATION LANDING] medi-face.pages.dev/RAJAMAHJONG ← Attacker-controlled Cloudflare account, posing as official "Medi Face" page (AMP / Indonesian) ← Registered in Google Search Console under attacker's Google account (verification token confirmed) ↓ All links (including "login" button) route to cloaking engine [L2: CLOAKING ENGINE] jutsu-seribu-bayangan.pages.dev ← JS: Layer1 device detection → Layer2 country detection (triple API failover) → Layer3 routing ↓ Only if Indonesia IP + Android/iPhone [L3: INTERMEDIATE REDIRECTOR] m4udd0syastvp1d.online (IP: 198.54.120.152 / NameCheap) [L4: FINAL GAMBLING DESTINATION] terreagoodboy.store/register?ref=MKPA2AD00002 ← NameCheap registered · Cloudflare CDN protected · Affiliate ID: MKPA2AD00002 [FALLBACK: HARMLESS LOOP (evidence destruction)] → jutsu-seribu-bayangan.pages.dev (loops to itself) ← Japanese users / PCs / investigators / researchers all land here → cannot confirm any evidence
Figure 2a: Attack Chain A (medi-face route) — All confirmed stages

3.2 Chain B — fraise-clinic Route (Independent Redundant System)

[L0: VICTIM SITES] fraise-clinic.com / etc. (FRAISE CLINIC brand — hacked pages) [L1: BRAND IMPERSONATION LANDING] fraise-clinic.pages.dev/DETIKBET ← Attacker-controlled Cloudflare account (AMP format · Imgur-hosted images) ← Image: i.imgur.com/lyf87zA.png (uploaded 2026-04-28, 3.5 months before attack) [L2: CLOAKING ENGINE] wewillrockyou.pages.dev ← Independent cloaking engine separate from Chain A ← Continues operating independently even if Chain A is suspended
Figure 2b: Attack Chain B (fraise-clinic route) — Independent redundancy to Chain A
⚙ Design Intent: Resilience By splitting into two independent chains, the attackers ensured that even if Cloudflare Trust & Safety suspended Chain A, Chain B could continue operations uninterrupted. This means the infrastructure was designed with no single point of failure (SPOF-free). The attackers anticipated institutional response and engineered structural resilience against it.

3.3 Logical Layer Architecture

LayerRoleAssets UsedTechnical Purpose
L0 Victim SitesSEO authority extractionLegitimate medical domainsExploit existing domain authority and backlinks to manipulate Google rankings
L1 Brand Impersonation PagesVisual legitimacy fabricationmedi-face.pages.dev / fraise-clinic.pages.devMimic victim brand; make counterfeit pages indistinguishable from official services
L2 Cloaking EngineTarget filtering / evidence destructionjutsu-seribu-bayangan.pages.dev / wewillrockyou.pages.devPass only Indonesian mobile users; route all others to harmless loop
L3 Final Gambling SitesMonetizationterreagoodboy.store / bringmetolife.storeUser registration at illegal gambling sites; affiliate revenue generation
L4 C2 Command & ControlAttacker coordinationTelegram (web.telegram.org)Share shell URLs, divide tasks, confirm progress
4. BRAND IMPERSONATION ANALYSIS

Technical Analysis of Brand-Impersonation Cloudflare Pages


The attackers created brand-impersonating Pages (medi-face.pages.dev, fraise-clinic.pages.dev) using a Cloudflare account entirely separate from — and unknown to — the victim corporation, specifically designed to be mistaken for the victim's official online presence.

4.1 medi-face.pages.dev — Technical Analysis

AttributeObserved ValueTechnical Intent
HTML Format <html amp lang="id"> AMP (Accelerated Mobile Pages) format. Using Google's official spec simultaneously achieves: Google mobile search priority ranking, AMP CDN distribution, and the visual legitimacy of a "Google-optimized page." See Section 6.
Language / Region lang="id", content-language: id Indonesian language targeting. The intended victim population is precisely defined.
Google Site Verification 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc Attacker has already registered this counterfeit page in Google Search Console. Querying Google with this token can identify the attacker's Google account — critical forensic evidence.
OG Image Host ik.imagekit.io/dewi11/d44d164b-… ImageKit.io CDN — account name "dewi11". An additional service account under attacker control.
Robots Directive content="index, follow" Actively instructs search engines to index. SEO contamination intent is unambiguous.
All Link Destinations jutsu-seribu-bayangan.pages.dev (3 locations) Every user interaction — including the "login" button — routes to the cloaking engine.
Page Title "🛡️ Halaman Resmi x Medi Face Pelembut Wajah" "Official Medi Face page" in Indonesian. Direct brand impersonation.
Nawala Mention "anti nawala" in meta description Nawala is the Indonesian government's illegal-site filtering system. Advertising bypass capability explicitly targets Indonesian users — a sophisticated localization strategy demonstrating deep knowledge of the Indonesian regulatory environment.

4.2 fraise-clinic.pages.dev/DETIKBET — Technical Analysis

AttributeObserved ValueTechnical Intent
HTML Format <html ⚡ lang="id"> AMP format (⚡ is the alternate AMP notation)
Image Host https://i.imgur.com/lyf87zA.png
Last-Modified: 2026-04-28
Uploaded to Imgur approximately 3.5 months before the attack. Direct evidence that the attack template was prepared far in advance. Confirmed via HTTP response headers.
All Link Destinations https://wewillrockyou.pages.dev/ Routes to Chain B's independent cloaking engine.
5. CLOAKING ENGINE — FULL CODE ANALYSIS

Complete Code Analysis of the Cloaking Engine


★ Technical Core of This Paper The JavaScript code below was retrieved directly from jutsu-seribu-bayangan.pages.dev (an attacker-controlled Cloudflare Pages instance). This code completely explains why Japanese investigators and security researchers are unable to observe any gambling content whatsoever. It was obtained from a publicly accessible endpoint on the open internet.
// ===================== CLOAKING ENGINE (actual source code) =====================
// Source: jutsu-seribu-bayangan.pages.dev (attacker-controlled Cloudflare Pages)
// Retrieved: 2026-08-13
// Design: 3-layer filtering — Layer1: Device → Layer2: Country → Layer3: Routing

(function() {
    // ★ Configuration values (this is the attacker's "evidence")
    const TARGET_URL   = "https://terreagoodboy.store/register?ref=MKPA2AD00002";
    const FALLBACK_URL = "https://jutsu-seribu-bayangan.pages.dev/"; // loops to itself = evidence destruction

    // ─── Layer 1: Device Detection ─────────────────────────────────────────────
    // Only Android / iPhone pass. PCs, tablets, and bots are immediately
    // sent to fallback without country detection.
    // → An investigator accessing via PC is routed to the harmless loop instantly.
    function detectDevice() {
        const ua = navigator.userAgent || navigator.vendor || window.opera || '';
        if (/android/i.test(ua))       return 'Android';
        if (/iPhone|iPod/i.test(ua))   return 'iPhone';
        if (/iPad/i.test(ua))          return 'iPad';
        return 'Other'; // PC → immediate fallback
    }

    // ─── Layer 2: Country Detection (Triple Failover + 3-Second Timeout) ───────
    // Only Indonesia ("ID") passes. Japan, US, Europe, VPN users → fallback.
    // Three IP geolocation APIs tried in cascade; if all fail → fallback.
    // → Even a researcher using a VPN cannot pass unless the IP reads as Indonesia.
    function detectCountryWithTimeout(callback) {
        let isResolved = false;
        let timeoutId  = null;

        function resolveCountry(code) {
            if (isResolved) return;
            isResolved = true;
            if (timeoutId) clearTimeout(timeoutId);
            callback(code);
        }

        // If no determination within 3 seconds → "unknown" → fallback (fail-safe)
        timeoutId = setTimeout(() => resolveCountry('unknown'), 3000);

        // API ①: ipapi.co (primary)
        fetch('https://ipapi.co/json/')
            .then(r => r.json()).then(d => resolveCountry(d.country_code || ''))
            .catch(() => {
                // API ②: ip-api.com (fallback 1)
                fetch('https://ip-api.com/json/')
                    .then(r => r.json()).then(d => resolveCountry(d.countryCode || ''))
                    .catch(() => {
                        // API ③: ipinfo.io (fallback 2)
                        fetch('https://ipinfo.io/json')
                            .then(r => r.json()).then(d => resolveCountry(d.country || ''))
                            .catch(() => resolveCountry('unknown')); // all APIs down → fallback
                    });
            });
    }

    // ─── Layer 3: Final Routing Decision ──────────────────────────────────────
    function processCloaking() {
        const device = detectDevice();

        // All PCs (including iPad) → immediate fallback (investigators / researchers cannot pass)
        if (device !== 'Android' && device !== 'iPhone') {
            window.location.replace(FALLBACK_URL);
            return;
        }

        // Mobile only: run country check
        detectCountryWithTimeout(function(countryCode) {
            const isIndonesia = (countryCode.toUpperCase() === 'ID');
            if (isIndonesia) {
                // ✅ Indonesian mobile → gambling site (affiliate revenue generated)
                window.location.replace(TARGET_URL);
            } else {
                // ⛔ Japanese / Western / unknown → loops to itself (leaves no evidence)
                window.location.replace(FALLBACK_URL);
            }
        });
    }

    processCloaking(); // entry point
})();
Figure 3: Cloaking engine — complete source code (retrieved from jutsu-seribu-bayangan.pages.dev)

5.1 Behavior by Visitor Type

Visitor TypeLayer 1 — DeviceLayer 2 — CountryOutcome
Indonesian smartphone user Android/iPhone ✓ ID ✓ → Redirected to illegal gambling site
Japanese law enforcement (PC) Other → immediate fallback Not evaluated → Harmless loop (no evidence visible)
Japanese police (smartphone) iPhone ✓ JP → non-ID → Harmless loop (no evidence visible)
Googlebot (crawler) Other (bot UA) Not evaluated → Harmless loop
Security researcher (VPN) Passes Layer 1 VPN IP → non-ID → Harmless loop (no evidence visible)
API failure / timeout (>3 seconds) Passes Layer 1 unknown → Harmless loop (fail-safe)
⚠ Fatal Investigative Obstacle This cloaking system means that standard investigative methods from within Japan cannot confirm the existence of gambling content. The only access profile that reveals the redirect destination is "Indonesian mobile device, physically within Indonesia." Without international investigative cooperation with Indonesian authorities (Polri), evidence preservation is structurally infeasible. This is a deliberate design outcome of the cloaking system.
6. TECHNICAL TECHNIQUES

Ten Advanced Anti-Detection and Evasion Techniques


We analyze each technique employed in this attack from a security engineering perspective. Those demonstrating particularly high technical craftsmanship are marked ★ Grudging Respect — a professional acknowledgment of the adversary's engineering even while condemning the application.

1
Geo-Cloaking — Triple API Failover Design
Three IP geolocation APIs (ipapi.coip-api.comipinfo.io) are used in a cascaded failover with a 3-second timeout. If the primary API is unavailable, the secondary and tertiary take over. If all APIs fail, the result defaults to fallback (= evidence destruction). This eliminates single-API dependency risk — an industrial-grade engineering decision.
2
Device Cloaking — Immediate PC Elimination
User-agent parsing allows only Android / iPhone to proceed. PCs, tablets (including iPad), and servers are immediately routed to fallback without ever reaching the country detection step. This is premised on the assumption that most investigators and researchers use PCs — a realistic operational security decision.
3
AMP (Accelerated Mobile Pages) Abuse ★★
By adopting Google's official AMP format (<html amp lang="id">), the attackers simultaneously achieved: ① priority placement in Google mobile search results, ② distribution via Google's AMP CDN (cdn.ampproject.org) — requiring no independent infrastructure, and ③ the visual legitimacy of a "page optimized and recognized by Google." Weaponizing Google's own trusted infrastructure is a remarkably refined technique.
4
Brand-Impersonation Cloudflare Pages — Subdomain Squatting on Victim's Brand ★★
Cloudflare's free Pages service was abused to create medi-face.pages.dev and fraise-clinic.pages.dev using the victim's exact brand names. End users see a URL reading "medi-face.pages.dev," which is visually indistinguishable from an official service. Additionally, by serving through Cloudflare's CDN, the attacker's origin IP is masked, making infrastructure attribution difficult.
5
Google Search Console Unauthorized Registration — Seizure of SEO Management Rights ★★★
The attacker registered medi-face.pages.dev in Google Search Console using their own Google account (verification token: 2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc). This grants: ① the ability to submit sitemaps and force index registration, ② monitoring and management of the page's Google search presence, and ③ the search-engine credibility of a "verified site owner." The attacker effectively seized SEO management rights over the victim's brand namespace on Google.
6
Advertising Nawala (Indonesian Government Filter) Bypass Capability
The meta tags on medi-face.pages.dev explicitly state "anti nawala." Nawala is the Indonesian government's illegal-site blocking system — gambling sites are blocked within Indonesia via Nawala. The attackers bypassed this filter via Cloudflare CDN, and then actively advertised this bypass capability as a selling point to the target audience. This demonstrates deep understanding of the Indonesian regulatory environment and an aggressive localization strategy.
7
WordPress Core File Path Impersonation — Backdoor Concealment
Some installed backdoors were placed at paths mimicking WordPress core file locations: wp-admin/js/widgets/media-widgets.php, wp-includes/images/image-data.php, wp-includes/js/tinymce/skins/lightgray/fonts/tinymce.php, etc. Visual inspection and directory listings make these difficult to distinguish from legitimate files, providing a key persistence mechanism.
8
Trusted CDN and Legitimate Service Asset Hosting
OG images were hosted on ImageKit.io (a legitimate CDN service, account: dewi11); landing page images on Imgur (a legitimate image-sharing service). By avoiding the attackers' own infrastructure for these assets, URL-based blocklist inclusion is made significantly harder, and IP-based attribution of the image host is neutralized.
9
Telegram C2 (Command and Control)
Server access logs contain numerous Referer: https://web.telegram.org/ entries. The attacker group coordinated the attack via a private Telegram channel — sharing webshell URLs, dividing tasks, and confirming progress in real time. Telegram's end-to-end encryption and low traceability make it an effective C2 channel that is very difficult for law enforcement to access.
10
IAB-Style Division of Labor (Initial Access Broker Model) ★★
It is highly probable that the backdoor planter (IAB), attack executor, SEO confirmation operator, and Cloudflare infrastructure manager are different individuals — a conscious division of labor designed to complicate attribution and prosecution. Multiple countries' IPs participating at different timestamps (multiple Indonesian IPs + Iranian IP) strongly supports this distributed organizational model.
7. GAME-THEORETIC ANALYSIS

Game-Theoretic Analysis: The Dual-Leverage Dominant Strategy


Analyzing this attack within the framework of John von Neumann's (1903–1957) extensive-form game theory reveals that the attackers' strategy is a design that transcends simple financial theft. We describe this in purely mathematical terms, free of emotional framing.

7.1 Dual Leverage: A Dominant Strategy With Two Independent Payoff Streams

This attack was designed to generate two independent revenue streams from a single infrastructure investment:

Payoff StreamMechanismProperties
Stream 1: Immediate Financial Revenue Route Indonesian users to illegal gambling sites → affiliate revenue (IDs: cSyJDyLy, MKPA2AD00002) Certain · Immediate · Ongoing
Stream 2: Long-Term Legal Leverage Build gambling content under victim's brand (medi-face.pages.dev) → create the appearance that the victim operates an illegal casino → hold the option of a false report to authorities Optional · Long-term · Attack-controlled timing
π_A(Attack) = π_gambling(Stream1) + π_leverage(Stream2) − c_infra ∀ response r_D ∈ S_D : π_A(Attack) ≥ π_A(No-Attack) ∴ Attack weakly dominates No-Attack (Weakly Dominant Strategy) Moreover: Stream1 and Stream2 are mutually independent → Even if Stream1 is discovered and shut down, Stream2 retains its leverage value → Even if Stream2 is never exercised, Stream1 revenue continues ∴ Both streams are synergistic, maximizing the attacker's expected payoff

7.2 Cloaking as Artificial Information Asymmetry

In Harsanyi's (1967) incomplete information game theory, information asymmetry fundamentally alters the structure of a game. The cloaking system in this attack artificially constructed the following asymmetry:

θ ∈ {θ_ID_mobile, θ_other} ← visitor "type" Attacker's response σ_A(θ): σ_A(θ_ID_mobile) → GamblingContent (monetization) σ_A(θ_other) → NormalContent (evidence destruction) The defender / investigators can only observe σ_A(θ_other) ∴ P(Evidence | Non-Indonesia access) ≈ 0 → Investigation from within Japan is structurally incapable of collecting evidence

7.3 The Defender's Optimal Response: Complete Public Disclosure as the Equilibrium Strategy

D: Silence / Concealment D: Partial Response D: Full Disclosure + Legal Action
A: Exercise Nuclear Button
(false report to authorities)
A: High, D: −∞ A: High, D: −Large A: Minimum, D: −Minimum
A: Continue Revenue A: Medium, D: −Medium A: Medium, D: −Medium A: Minimum, D: −Minimum ← Equilibrium

Table 1: Payoff matrix (subgame perfect equilibrium analysis) — Defender's dominant response is "Full Disclosure + Legal Action"

By backward induction, the defender's dominant strategy is complete public disclosure. The attacker's "nuclear button" — the option to falsely report the victim as an illegal casino operator to authorities — loses all its leverage value the moment its existence becomes fully public knowledge. The publication of this paper is the execution of that equilibrium strategy.

8. INDICATORS OF COMPROMISE

Confirmed IoCs — Full Indicator List


The following IoCs are released to the security community. Free use for defensive, research, and investigative purposes is explicitly permitted.

Attacker IP Addresses
182.10.98.57     # Indonesia — Primary operator, initial webshell activation (19:33:27 JST)
103.20.83.86     # Indonesia — Highest frequency access throughout attack
114.10.65.118    # Indonesia — Telkom Indonesia
103.236.188.241  # Indonesia
180.243.11.97    # Indonesia — Telkom Indonesia (Telkomsel)
31.56.30.60      # Iran — Secondary operator (joined 20:37 JST)
103.141.164.246  # Unknown — Additional participant
2400:9800::/32   # Telkomsel IPv6 range (Indonesia)
Attacker Domains & Infrastructure
m4udd0syastvp1d.online          # NameCheap · 2026-04-04 · IP: 198.54.120.152 · Redirect node
bringmetolife.store              # NameCheap · 2026-04-05 · Gambling dest · Affiliate: cSyJDyLy
terreagoodboy.store              # NameCheap · updated 2026-08-09 · IPs: 45.194.53.52 / 45.194.53.26
jutsu-seribu-bayangan.pages.dev  # Cloudflare Pages (attacker acct) · Cloaking engine A
wewillrockyou.pages.dev          # Cloudflare Pages (attacker acct) · Cloaking engine B
medi-face.pages.dev              # Cloudflare Pages (attacker acct) · BRAND IMPERSONATION A
fraise-clinic.pages.dev          # Cloudflare Pages (attacker acct) · BRAND IMPERSONATION B
Attacker-Specific Identifiers (Financial Tracing & Attribution)
Gambling Affiliate ID #1:       cSyJDyLy         (bringmetolife.store)
Gambling Affiliate ID #2:       MKPA2AD00002     (terreagoodboy.store)
Google Search Console Token:    2Z_wOjQcGzVd53eRds3fVWKSAaDsyNsUl7AsNymx4tc
ImageKit.io Account:            dewi11           (ik.imagekit.io/dewi11/)
Imgur Image ID:                 lyf87zA.png      (uploaded 2026-04-28)
Registrar Privacy Shield:       Withheld for Privacy ehf (Reykjavik, Iceland)
Common Nameserver:              nile.ns.cloudflare.com / sasha.ns.cloudflare.com
C2 Channel:                     Telegram (confirmed via Referer: web.telegram.org)
PHP Webshell Filenames (Confirmed)
fgh.php          # Initial shell — direct access without reconnaissance
yomanx498.php    # Secondary shell (redundancy)
n0bgxdjskd.php   # Secondary shell
mails.php        # Shell with mail-mimicking filename
follder.php      # Shell with typo-based obfuscation
carrier/sshy.php # Shell in subdirectory
Infrastructure Pattern Linking to Single Threat Actor m4udd0syastvp1d.online, bringmetolife.store, and terreagoodboy.store all use NameCheap as registrar and share identical Cloudflare nameservers (nile.ns / sasha.ns.cloudflare.com). All use Withheld for Privacy ehf (Iceland) for privacy protection. These form a consistent "criminal infrastructure template" established by the same threat actor. Additional domains matching this pattern are highly likely to exist.
9. CONCLUSION

Conclusion: What This Case Demonstrates About 2020s Cybercrime


This incident represents an archetypal case study in the evolution of cybercrime, notable in the following respects:

  1. Democratization of APT-grade Techniques: Advance reconnaissance, premeditated planning, staged infrastructure construction, and multi-operator division of labor — previously associated with nation-state actors — are now routinely adopted by financially motivated criminal organizations.
  2. Weaponization of Legitimate Infrastructure: Cloudflare Pages, Google AMP, ImageKit, Imgur, and Telegram are all legitimate, highly-reputable services. Traditional IP-reputation-based defenses are structurally ineffective against this class of attack.
  3. Investigative Neutralization by Design: A cloaking architecture that makes evidence structurally invisible to Japanese investigators is a new challenge that requires international investigative cooperation across internet boundaries. This is not a technical gap that can be closed unilaterally.
  4. Dual-Use Threat Structure: Simultaneously realizing SEO revenue and legal leverage from a single infrastructure is a new threat category that transcends conventional cybercrime taxonomies.

And finally: complete transparency is the optimal defense. The leverage value of the "false evidence" the attackers constructed evaporates the moment it becomes fully public knowledge. This document is the record of that moment — and a public-benefit gift intended to prevent the next victim.

REFERENCES

References & Theoretical Frameworks


  1. von Neumann, J. & Morgenstern, O. (1944). Theory of Games and Economic Behavior. Princeton University Press.
  2. Harsanyi, J.C. (1967). Games with incomplete information played by "Bayesian" players. Management Science, 14(3), 159–182.
  3. Schelling, T.C. (1960). The Strategy of Conflict. Harvard University Press.
  4. MITRE ATT&CK Framework v14 — T1505.003 (Web Shell), T1027 (Obfuscated Files), T1583 (Acquire Infrastructure), T1036 (Masquerading), T1491.002 (External Defacement).
  5. Google AMP Project. (2026). AMP HTML Specification. ampproject.org.
  6. Netcraft Phishing Reports: UUID dPORnP7rYNAeVqvZgbexk6difZ5ukR7N, URyTgd5sZ8tjF0ogh2EspK7SdyRz816J.
  7. JPCERT/CC. (2026). Incident Report MF-2026-0812.
  8. ID-SIRTII/CC. (2026). Cross-border IoC sharing — Case MF-2026-0812.