Nigerian Air Force subdomain hijacked to host 101K spam pages for ad revenue
thejasminejade · x · 2026-10-07
Security researcher thejasminejade found that a subdomain of the Nigerian Air Force's official site (awc.airforce.mil.ng) appears hijacked.
- It points to a rented DigitalOcean server hosting 101,164 spam pages — how-tos, US local services, even adult content — with ads running, seemingly to monetize the .mil.ng domain authority.
- Every page loads an ad script from nina.bisniskini.biz.id, sets up a 300x250 banner, and overlays invisible links; some clicks open the article, others redirect to another site.
- Sitemap dates run from Nov 2024 to Jan 2027, with 1,000+ future dates, suggesting fabricated timestamps; about half cluster on Sept 19-21.
- Two likely causes: a hijacked DNS-editing account, or an abandoned record whose IP was later reassigned to a stranger. The pattern fits classic DNS hijack or forgotten-record takeover.
Related event: Nigerian Air Force Subdomain Hijacked with 100K+ Spam Pages(3 posts)→
More from Infra
- ANVIL III Optimizer Claims 62% Pretraining Cost Cut at Frontier Scale, Beats Tuned Muon — kellerjordan0 · 2026-10-07
- H100 Supply Crunch: 4-Year-Old Servers Are Scarce, Not Cheap, Says Compute Exchange — ns123abc · 2026-10-07
- Omnigent's four-point playbook tames runaway LLM bills with smart model routing — matei_zaharia · 2026-10-07
- brrr: Open-Source GPU Stress Test for BF16, FP8, MXFP4 and NVFP4 — ypatil125 · 2026-10-07
- Kalshi bets on 'Silicon Spread': trading power-in, compute-out as AI's key commodity spread — nima_owji · 2026-10-07
- "Just give me 1.5MW": the power bill for running 10,000 Opus-quality models at home — generativist · 2026-10-07