Just wrapped at the GASA Summit. A lot to think about from the last few days, but one session has been sticking with me: The Silicon Valley of Crime: Understanding Southeast Asia’s Scam Ecosystem and What Tech Can Do About It.
By the end, that title didn’t feel like much of a stretch. Jacob Sims, who studies transnational crime and scam compounds in Southeast Asia, laid out how integrated these operations have become. Cyber fraud, human trafficking, money laundering, political protection… all one system.
Mollie Zapata of C4ADS added the technology layer: translation systems, workforce management tools, automation, and now AI. Savanna Slaughter of TRM Labs talked about following activity from the victim back to the compound, on-chain and off-chain.
Raid one compound and the operation can move. Break up a large site and smaller ones appear. Staff, equipment and infrastructure get relocated. The physical footprint changes faster than the network behind it.
Digital advertising is only one part of that machinery, but it is one place where the broader operation becomes observable. For many scam groups, paid media is part of the acquisition infrastructure. It helps find victims, test messages, move people through landing pages and eventually into messaging apps, fraudulent investment platforms or other parts of the scam funnel, as documented by InfoBlox in their February research piece.
That makes malvertising more than an incident to block. It can be an observable point in a much larger attack chain. Yet the industry’s response still tends to begin with the ad: remove the creative, block the domain, suspend the advertiser account. Those actions matter because they stop harm, but attackers expect to lose those pieces.
A creative is replaceable, and so is a domain or landing page. AI makes that replacement cycle faster. None of that necessarily requires rebuilding the infrastructure underneath. So the investigation has to move backward.
Where did the demand enter the ecosystem? Which accounts were involved? Which intermediaries carried it? What infrastructure was reused? Have we seen the same redirect behavior or cloaking pattern before? Did another campaign show up through the same route after the first one was removed?
That is what we mean by the demand path: the route a campaign took through the advertising ecosystem. From a security perspective, that route is threat intel material.
If the same demand source, redirect chain, cloaking infrastructure, hosting or intermediary keeps appearing across campaigns, the indicators start to connect. You are looking at persistence, reuse and infrastructure. Attackers rotate indicators. Domains burn. Accounts disappear. Payloads change. What matters is what they had to keep using in order to stay operational.
These operations run through legitimate systems: advertising, hosting, payments, messaging, cloud services, AI. They only need enough of that infrastructure to keep functioning.
So when one piece gets taken down, the harder question is: what part of the operation did we actually disrupt?