A Roblox Scam Page Led to a Botnet Built to Hijack Your Router
This investigation started with a scammy Roblox page that's still live right now. Follow the redirects far enough, and it leads to a hosting provider that's also hosting malware built to hijack home routers and security cameras into a botnet.
Where this started
I ran into this scam page when I was researching some shady looking YouTube channels running redirects to possible malicious sites. Out of roughly 200 checked, I found 4 running their own link-redirect instead of renting one from a service like Bitly. That's legal. But smells fishy as hell.
Open it and you land behind a real scammy offerwall: finish a survey or a download, the site owner gets paid per completion, and the visitor gets nothing. A security research group had already logged this same domain running a completely different scam months earlier, a fake Apple ID login page, under the same registration. As usual practice, they reskinned it and continued uninterrupted.
This is maintained, reused infrastructure, not a page thrown up once and abandoned. Tracing the redirect is where this stopped being a story about one scammy giveaway page and gets much bigger.
Where it led
The page's host buys its own internet connectivity from a hosting provider that sits on two separate criminal-infrastructure blocklists. Routing data ties that backbone's address space to the router-and-camera botnet malware, distributed one IP address away from dozens of other scam pages, all inside that backbone's own controlled territory. While that doesn't prove the backbone's operators run the malware themselves, it proves bad actors feel confident hosting here, assuming they won't get caught or shut down by law enforcement.
What a scan of the cluster found
A full scan of everything that has touched this hosting cluster since December 2023 found:
- 1,589 domains total
- 196 of them still live and answering today
- neighbors on the backbone include a large Turkish illegal-gambling redirect network with real reported victim losses, a fake Adobe update page built to deliver malware rather than steal a password, a professionally built fake investment firm (pig butchering anyone?), and a run of pre-launch meme-coin hype sites
The paper trail
The ownership trail is where this got interesting in a different way. The host is registered in the Seychelles and the address is shared with at least fifteen other unrelated companies, clearly shell-mill traffic.
Of the companies identified, one is used by only five organizations in the entire global internet registry. Together, they tie this stack of companies to entities in Hong Kong, Amsterdam, Bulgaria and the UK. So this is clearly a multinational effort.
This structure shows very clearly that threat actors are organized, have a multi level org structure and are adaptive.
If you ever shut down a scam page and felt really good about yourself, this research should make you doubt that.
This is the same tracing work behind our investigations engagements: read-only first, every claim tied to a source, nothing called confirmed on one crosslink alone. If your business is sitting on infrastructure nobody has actually mapped, that's fixable faster than you'd think.
Start with one thing: $1,000, one weekMore work: the orders that stopped going missing · the analyst that refuses to guess