The Missing Signal: What DNS Data Can Tell Us About Scam Compounds
DNS traffic spikes could help trace scam compound infrastructure — an underused signal that could reshape how these operations are found

Scam compounds across Southeast Asia, run out of large-scale operations that rely on a trafficked workforce, now generate tens of billions of dollars annually. Dismantling them has proven difficult: Takedowns tend to be reactive, targeting one domain or one raid at a time, while the underlying infrastructure — and the compounds producing it — regenerate almost as fast as they’re disrupted.

This piece looks at an underused signal in that fight: DNS query data. Much like spikes in power or water usage have helped investigators locate other illicit operations, unusual DNS traffic patterns may offer a similar tell for scam compounds scaling their infrastructure. One recent investigation suggests the approach has real potential, even if it remains closer to a proof of concept than an established practice.

July 30, 2026

The people who investigate large-scale cyber scam operations and the people who investigate instances of DNS abuse are, most of the time, working in separate rooms, even though they’re often looking at the same underlying activity. Journalists, human rights researchers, and international and regional organizations are spending an increasing amount of time in recent years documenting the human cost of scam compounds — the human trafficking, forced labor, and politically connected patrons who shield operation leaders. A separate community of internet registrars, registries, and threat researchers have spent that same stretch of time mapping malicious domain registrations, largely as a technical and contractual problem. Both groups are describing the same phenomenon, just from opposite ends, but they rarely find themselves in the same room. The collaborative work between the Stimson Center’s Cyber and Southeast Asia programs has explored the laws and frameworks surrounding this issue and continues to examine the technologies underlying these operations.  

Scam operations cannot function without domains. Fraudulent government portals, spoofed banking logins, and fake investment platforms all require registered digital infrastructure, and a great deal of that infrastructure is registered maliciously or abusively from the outset. The body that coordinates the domain name system globally is the Internet Corporation for Assigned Names and Numbers (ICANN). ICANN sets the contractual rules that registrars and registries operate under, largely through its GNSO Council, which develops binding policy for generic top-level domains via a consensus-driven process. That process is the main lever available for changing how abuse gets handled contractually across the entire gTLD space — which is what makes it relevant to a problem moving as fast as scam infrastructure. 

ICANN’s community has been trying to address the ongoing problem of maliciously registered domains through its ongoing Policy Development Process (PDP) on DNS Abuse Mitigation. The GNSO Council adopted the charter for PDP1, focused on associated domain checks in January 2026, with a second track on API access for high-volume registration still to come. The logic behind the first PDP is that when a registrar identifies an abusive domain, they have no obligation to check whether the same registrant or account is running other domains. Cyber scam operations exploit that gap by design, cycling through disposable domains faster than any “one-at-a-time” takedown process can keep up with. 

But associated domain checks only address one side of the problem: how domains get registered. The question then becomes what a domain does once it’s active. That’s where a second, much less discussed category of DNS data comes in. DNS query signals — patterns of unusual, anomalous, or spiking traffic, regardless of where that traffic ultimately resolves — are a lesser-known but potentially powerful indicator of scam compound activity itself, distinct from the domains being abused. The comparison that keeps coming up among researchers is utility usage: Just as investigators have used spikes in power or water consumption to help locate illicit scam operations or other illegal facilities, unusual DNS query volume from a cluster of infrastructure might function as a similar tell for scam operations trying to scale. On its own, a DNS anomaly proves little. But layered against other signals such as device tracking, malware telemetry, victim reports, and satellite imagery of compound construction, it becomes one more thread in a much larger picture of how cyber scam operations industrialize. 

The clearest public example of this approach so far comes from Infoblox’s collaboration with the Vietnamese non-profit Chong Lua Dao. As part of a broader investigation, the two organizations identified a spike in DNS queries across Infoblox’s cloud customer environments and followed that signal to a previously undocumented malware-as-a-service platform. That platform turned out to be capable of real-time surveillance, credential theft, data exfiltration, and financial fraud, and it was ultimately tied to an Android banking trojan likely operated from multiple locations, including the K99 Triumph City compound in Cambodia. Thousands of lure domains were used to impersonate government institutions across at least 21 countries, with roughly 35 new domains registered every month to replace those taken down. These domains were registered in a small handful of Hong Kong-based registrars and a narrow set of top-level domains.  

That investigation is still active, and the more granular technical findings live in Infoblox’s published report. This being said, it raises broader questions about the utilities of DNS spikes as a tool for scam operations. DNS abuse takedowns are, almost by definition, reactive and domain-specific. The harder and more interesting problem is how DNS signals get folded into investigations of large-scale scam operations as a whole — not just to kill infrastructure, but to help locate and characterize the compounds generating it. 

Further research is needed to understand why the use of DNS signals as an indicator of scam compound activity is not a more prominent part of broader efforts to prevent and respond to cyber scams. Research should seek to understand whether a lack of inclusion of DNS signaling is a matter of institutional silos, a data-sharing problem, or simply that no one has yet built up the literature connecting “unusual query volume” to “operational compound” with enough confidence to act on it at scale. National and international law enforcement agencies should consider whether DNS query-pattern analysis is worth testing on a pilot basis alongside the signals already in use to see whether it holds up as a reliable indicator in practice. Doing so would likely mean working through barriers such as data-sharing issues and enabling the right people to communicate to ensure DNS abuse and scam-compound investigations as overlapping lines of work rather than separate ones.  

Within ICANN itself, the second PDP track on API access for high-volume registration is the more obvious near-term venue for the technical conversation about DNS abuse, but it’s also worth exploring the ways in which the community could contribute to future conversations on traffic-based signals rather than registration-based ones alone. On the research side, the existing literature on DNS anomaly detection is almost entirely built around botnets and command-and-control traffic; adapting those methods to the specific signatures of scam-compound infrastructure, rather than assuming the same baselines apply, is worth studying. Whether this becomes a real tool or stays a research footnote depends less on the technology than on who decides to pick it up. 

Find an Expert

Home to more than 100 scholars and global affiliates, the Stimson Center is proud to be a magnet for the world’s leading experts on the most pressing foreign policy and national security issues of our time. Explore our experts and their work.

Allison Pytlak
James Siebens