Skip to main content

September 2026 On Tap: Cloud Bucket Redirection Surge & Regional DGA Subdomain Telemetry

· 8 min read

September 2026 Threat Landscape Abstract​

In September 2026, across 148 verified malicious messages, threat actors demonstrated a sharp escalation in public cloud bucket redirection—with Google Cloud Storage (storage.googleapis.com) links jumping to 901 instances-while distributing payloads through high-entropy regional subdomains (.web.id, .my.id, .biz.id, .com.de) and DGA .us domains.

MITRE ATT&CK Techniques Observed This Month​

Top Risks & Findings This Month​

Google Cloud Storage Link Surge (storage.googleapis.com)

Our link extraction identified 901 total hyperlink references pointing to storage.googleapis.com across 148 messages (averaging ~6 redirector links per email across buttons, images, and footer anchors).

Focus: deep link unwrapping, public cloud storage gateway rules

Health & Medical Supplement Spam Dominance (43.2%)

Over 43% of September spam payloads promoted erectile dysfunction remedies, weight loss hacks, and cognitive supplement claims.

Focus: content filtering, domain reputation reputation rules

Regional Subdomain & DGA Infrastructure Exploitation

Heavy reliance on free or low-cost regional subdomains (.web.id, .my.id, .biz.id, .com.de) combined with random string .us domains.

Focus: high-entropy TLD blocking, dynamic DNS inspection

Cloud Storage Account Deletion Threat Influx (32.4%)

High volume of alerts alleging imminent cloud storage capacity limits or photo/video deletion unless billing details are updated.

Focus: security awareness training, external sender banners

The September dataset demonstrated a dramatic surge in links pointing to static Google Cloud Storage buckets (storage.googleapis.com), which threat actors use to host intermediate static HTML redirectors. Additionally, attackers routinely hotlink remote images from legitimate public hosts like Imgur (i.imgur.com) to bypass inline attachment filters:

Hostname / ServiceExtracted LinksRole in TelemetryInfrastructure Type
storage.googleapis.com901Static HTML bucket redirectorsThreat-Controlled Staging
i.imgur.com109Remote logo & banner image hotlinkingAbused Legitimate Service
d3k81ch9hvuctc.cloudfront.net10Content Delivery Network (CDN) assetsAbused Legitimate Service

Primary Sender Registrar TLDs & Full URL Structure​

Threat actors heavily utilized dynamic subdomains and hash-appended bucket URLs to deliver payloads:

  • Indonesian & Regional Subdomains (.web.id, .my.id, .biz.id):
    • xhtwlhmd.markif.lightworksa.web.id
    • xpysjlaa.teleso.barviko.my.id
    • pfgvdpzh.soibm.pravento.biz.id
    • vwwdtqtw.allied.metanova.biz.id
    • olyamzcr.samsung.kalqima.my.id
  • Random String DGA .us Domains:
    • aax.lbxrvtstbtbdw.us
    • saq.hcdwqozyylqgc.us
    • mhz.kmvhompywgibm.us
    • 628mqiak.us

Every extracted storage.googleapis.com URL in the September telemetry mapped to one of eight distinct bucket/object paths:

Bucket & Object PathLink CountTarget Redirector Role
worklinks/evrtinggood.html500Primary intermediate static HTML redirector
smalbus/salaminka.html383Secondary intermediate static HTML redirector
hmdbox/hmd-v1-cl3.html9Campaign variant redirector
yassales/hreflyass.html2Campaign variant redirector
strow/strw_v3.html2Staging variant redirector
strow/strw-v1-cl2.html2Staging variant redirector
bowly/bowly.html2Campaign variant redirector
sndrr/nobotgogomailbali_v2.html1Anti-bot detection staging script

Intercepted Phishing Case Studies & Evidence​

Below are key case studies highlighting major true phishing campaigns observed during the September collection window. Use the provided Gmail search terms to locate these exact lures in your spam folder.

Case Study A: Norton Anti-Virus Expiration & Infection Lure​

  • Gmail Search Query: Your NORTON Subscription Has or Your device has been infected with (22) viruses
  • Sender Domain: ukb.zhukxkxqvbeey.us
  • Subject: Your NORTON Subscription Has Expired — Your device has been infected with (22) viruses
  • Technique: Displays a fake urgent virus infection alert and subscriber ID, embedding static Google Cloud Storage redirector links (storage.googleapis.com/smalbus/salaminka.html).

Norton Anti-Virus Expiration Lure


Case Study B: Cloud Storage Deletion Extortion Threat​

  • Gmail Search Query: ACCOUNT SUSPENDED YOUR ACCOUNT AND ALL DATA WILL BE DELETED or Claim your free renewal today
  • Sender Domain: dawrnjdv.whatsapp.norquell.my.id
  • Subject: Your account has been suspended! All your files and memories will be erased on 09-26-2026
  • Technique: Leverages high-urgency loss-aversion threats claiming cloud storage backup files will be permanently erased, routing to static HTML buckets.

CloudDrive Account Deletion Threat Lure


Case Study C: "VapoCept" 15-Second Vicks Memory Restoration Lure​

  • Gmail Search Query: "I remembered my bank password again" — The 15-second Vicks video
  • Sender Domain: udzeuwhi.info.guzojsone.biz
  • Subject: "I remembered my bank password again" — The 15-second Vicks video
  • Technique: Promotes an absurd pseudoscience "Vicks-based protocol" by "VapoCept Research" claiming to cure memory loss and restore bank passwords in 15 seconds.

Vicks Memory Restoration Lure - Header & Sender Info

Vicks Memory Restoration Lure - Body & Presentation CTA


Threat Community & Sandbox Correlation​

Our telemetry findings correlate directly with external threat intelligence repositories, automated sandbox submissions, and active phishing feeds tracking these exact Google Cloud Storage bucket redirectors:

storage.googleapis.com/worklinks/evrtinggood.html

Classification & Role: Primary intermediate HTML redirector actively observed dynamically routing targets via client-side URL hash parameters (#...).

storage.googleapis.com/smalbus/salaminka.html

Classification & Role: High-volume static HTML redirector landing page flagged across multiple credential harvesting and tech support submissions.

storage.googleapis.com/sndrr/nobotgogomailbali_v2.html

Classification & Role: Anti-bot evasion script and kit identifier (nobot-gogo-mail-bali) designed to detect and filter automated security crawlers before routing human victims.

storage.googleapis.com/yassales/hreflyass.html

Classification & Role: Tech support, browser locker, and urgency alert redirector variants (also observed alongside strow/strw_v3.html).


🍻 The Defensive Playbook​

Apply these four security controls to protect organizational inboxes against cloud bucket redirection and DGA subdomain lures:

Inspect Public Cloud Bucket Links

Enforce gateway URL inspection for links pointing to storage.googleapis.com and s3.amazonaws.com to resolve final payload destinations before delivery.

Restrict Dynamic Regional Subdomains

Flag or score inbound email containing URLs or sender domains hosted on high-entropy .web.id, .my.id, .biz.id, and random .us subdomains.

Enforce FIDO2 / Passkey Authentication

Deploy phishing-resistant MFA (FIDO2 / WebAuthn / Passkeys) to neutralize credential harvesting portals accessed via email links.

Maintain Safe Sender Allowlists

Review spam gateway rules to ensure legitimate vendor communications (rewards updates, event bulletins) avoid automated spam folder placement.