ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 2 sources: “China-Aligned PeckBirdy Malware Hides C2 Infrastructure Inside Chinese-Language Casino and Adult Websites” — merged summary and timeline →

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

highThreat actorimportance 63
AI summary · glm-5.3-flash

Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.

Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.

  • PeckBirdy is a JavaScript C2 framework used by China-aligned APTs since 2023
  • Casino and adult sites act as cover for WebSocket C2 and service-worker persistence
  • Fake browser-update prompts deliver backdoors with credential theft and remote access
  • ~3% of enterprise customers resolved at least one PeckBirdy C2 domain
  • Defenders urged to correlate DNS, proxy, and browser telemetry; single-domain blocking ineffective
VendorsInfoblox
ProductsPeckBirdy
OrganizationsInfoblox
CountriesChina

Indicators of compromiseAll →

TypeIndicatorContext
domain11168833.comersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding Casino
domain11170011.comhe researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated bra
domain1862.ccently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected them
domain312zym001.ccntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples
domain80074.ccom Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different
domain843470.ccdifferent branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino dom
domainam125.ccites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirectin
domainappcasino.onlinesite promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gambling
domainasg78.commbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciou
domaincache-cdn.orgated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal dete
domaincache-mcp.comm/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pag
domaindollycasino.coming 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdra
domaindragobet.neth complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam R
domaingithubassets.netVirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidenta
domainjs.cache-mcp.comng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain c
domainmcp-source.onlinemmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connecti
domainpuqxr.comino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80
domainrealz.comambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoy
domainvip311.ccoperators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associa
domainzenplay77-x.spacecasino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infob
domainzzyud.comn hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with Peck
ipv4146.103.91.133en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a Ja
ipv4157.185.143.150printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a Ho
Full article1,038 words · extracted from cybersecuritynews.com · click to collapse

Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some quietly connect visitors and compromised systems to attacker-controlled servers.

The pages are built to appear disposable and harmless, which can lower the chance that they receive security scrutiny. The activity centers on PeckBirdy, a JavaScript-based command-and-control framework used by China-aligned advanced persistent threat groups since 2023.

The campaigns have targeted corporate and government organizations across Asia, with education, IT, banking, financial services, and government among the sectors observed. Infoblox analysts identified the latest expansion while tracking a vast ecosystem of illegal casino domains.

Infoblox said in a report shared with Cyber Security News (CSN) that the same disguise now extends to Chinese-language adult sites, widening the places where the operators can hide.

Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source - Infoblox)
Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infoblox)

It also underlines how criminal web ecosystems can give espionage operators a cover story, and not only that even the danger is not a casino page alone.

Attackers use pages that look unimportant to host or embed code, establish background web connections, and blend their traffic into a crowded and frequently ignored corner of the internet. That approach can leave defenders focused on the lure while the real espionage channel remains unseen.

Hackers Are Hiding Espionage Infrastructure

Researchers separate this activity from two broader casino-abuse models: illegal gambling and money laundering operations, and scam gambling sites that prevent victims from withdrawing funds.

PeckBirdy sites are different because the casino is set dressing, not a service intended to attract or retain real players. One observed page registered a JavaScript service worker and loaded a suspicious script resembling earlier PeckBirdy code.

Service workers can run in the background, making them useful for maintaining contact after a page visit. Similar abuse has appeared in service worker credential theft campaigns, where background browser code can intercept or persist beyond normal browsing.

The report highlighted a casino-themed decoy that embedded a command server behind familiar branding. Investigators then found that live WebSocket connections reached another domain, while related adult websites used the same pattern.

This layered design makes quick reputation checks less reliable, particularly when automated scanners do not fully capture browser-side behavior.

Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source - Infoblox)
Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source – Infoblox)

PeckBirdy can also lead victims to false browser-update prompts that deliver backdoors, a familiar social-engineering route that deserves closer review alongside reports of fake browser update malware.

The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access, raising the potential impact from a single web visit to a wider network intrusion.

Detection Gaps Demand Context

The researchers found that just over 3% of their enterprise customers resolved at least one PeckBirdy C2 domain. A lone lookup is not always proof of compromise because one historical domain resembles a possible typo.

But repeated resolution of three to ten distinct C2 domains is a meaningful warning sign that warrants investigation, rather than a single alert viewed in isolation.

Detection coverage varied sharply. A known PeckBirdy domain had 13 detections in VirusTotal, another had three, and the WebSocket-related domain had none at the time of publication.

That gap shows why defenders should not treat a clean reputation result as clearance, especially when investigating Chinese threat actor infrastructure that is designed to blend into common web services.

Security teams should review DNS, proxy, and browser telemetry for the indicators below, then correlate connections with endpoint events and unusual service-worker registrations.

They should prioritize hosts contacting several distinct domains, preserve relevant logs, and examine whether users were sent to fake updates or unfamiliar gambling and adult pages.

Blocking one domain at a time is unlikely to solve the problem because operators rotate domains and infrastructure quickly.

Organizations should instead combine domain monitoring with web filtering, timely browser and endpoint updates, least-privilege controls, and incident-response checks that look for related activity across the network.

That layered approach also helps uncover covert C2 communication methods that do not resemble conventional malware traffic.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Decoy casino domainvip311.ccCasino-themed site identified as embedding PeckBirdy C2 infrastructure
Casino comparison domainzzyud.comCasino site shown in the researchers’ comparison of lookalike pages
Casino comparison domainzenplay77-x.spaceCasino site shown in the researchers’ comparison of lookalike pages
Casino domain11170011.comIllegal Chinese-language casino site using impersonated branding
Investment scam domainpuqxr.comSite impersonating an investment platform
Casino domains80074.cc, 11168833.comNear-identical casino sites using different branding
Casino domains312zym001.cc, am125.cc, 843470.ccRecently active casino-site examples
Redirecting casino domain1862.ccCasino site that fingerprinted visitors and redirected them by location
IP address157.185.143.150Final destination observed when accessing 1862.cc from a Hong Kong IP address
IP address146.103.91.133Final destination observed when accessing 1862.cc from a Japanese IP address
Scam gambling domaindollycasino.comScam gambling site associated with complaints about withdrawal problems
Scam gambling domaindragobet.netScam gambling site promoted through injected comment spam
Redirect domainappcasino.onlineDomain reached through clicks on dragobet.net
Scam gambling domainsummer138.tJoker-branded scam gambling site
Scam gambling domainstorebet77.supportJoker-branded scam gambling site using misleading branding
Scam gambling domainrealz.comScam gambling site advertising a deposit bonus
Casino decoy domainasg78.comChinese-language casino domain observed loading a suspicious JavaScript payload
Malicious JavaScript URLjs.cache-mcp.com/layer.jsSuspicious payload loaded by asg78.com
C2 domaincache-mcp.comPeckBirdy command-and-control domain embedded in casino pages
C2 domainmcp-source.onlineWebSocket-related PeckBirdy domain used to collect connections
C2 domaincache-cdn.orgPreviously identified PeckBirdy domain with VirusTotal detections
Possible typosquat/C2-related domaingithubassets.netHistorical PeckBirdy domain that may also receive accidental typo-related queries

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/espionage-infrastructure/