Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.
Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.
- PeckBirdy is a JavaScript C2 framework used by China-aligned APTs since 2023
- Casino and adult sites act as cover for WebSocket C2 and service-worker persistence
- Fake browser-update prompts deliver backdoors with credential theft and remote access
- ~3% of enterprise customers resolved at least one PeckBirdy C2 domain
- Defenders urged to correlate DNS, proxy, and browser telemetry; single-domain blocking ineffective
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 11168833.com | ersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different branding Casino |
| domain | 11170011.com | he researchers’ comparison of lookalike pages Casino domain 11170011.com Illegal Chinese-language casino site using impersonated bra |
| domain | 1862.cc | ently active casino-site examples Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected them |
| domain | 312zym001.cc | ntical casino sites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples |
| domain | 80074.cc | om Site impersonating an investment platform Casino domains 80074.cc , 11168833.com Near-identical casino sites using different |
| domain | 843470.cc | different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirecting casino dom |
| domain | am125.cc | ites using different branding Casino domains 312zym001.cc , am125.cc , 843470.cc Recently active casino-site examples Redirectin |
| domain | appcasino.online | site promoted through injected comment spam Redirect domain appcasino.online Domain reached through clicks on dragobet.net Scam gambling |
| domain | asg78.com | mbling site advertising a deposit bonus Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspiciou |
| domain | cache-cdn.org | ated PeckBirdy domain used to collect connections C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal dete |
| domain | cache-mcp.com | m/layer.js Suspicious payload loaded by asg78.com C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pag |
| domain | dollycasino.com | ing 1862.cc from a Japanese IP address Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdra |
| domain | dragobet.net | h complaints about withdrawal problems Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam R |
| domain | githubassets.net | VirusTotal detections Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidenta |
| domain | js.cache-mcp.com | ng a suspicious JavaScript payload Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com C2 domain c |
| domain | mcp-source.online | mmand-and-control domain embedded in casino pages C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connecti |
| domain | puqxr.com | ino site using impersonated branding Investment scam domain puqxr.com Site impersonating an investment platform Casino domains 80 |
| domain | realz.com | ambling site using misleading branding Scam gambling domain realz.com Scam gambling site advertising a deposit bonus Casino decoy |
| domain | vip311.cc | operators can hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associa |
| domain | zenplay77-x.space | casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infob |
| domain | zzyud.com | n hide. Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with Peck |
| ipv4 | 146.103.91.133 | en accessing 1862.cc from a Hong Kong IP address IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a Ja |
| ipv4 | 157.185.143.150 | printed visitors and redirected them by location IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a Ho |
Full article1,038 words · extracted from cybersecuritynews.com · click to collapse
Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some quietly connect visitors and compromised systems to attacker-controlled servers.
The pages are built to appear disposable and harmless, which can lower the chance that they receive security scrutiny. The activity centers on PeckBirdy, a JavaScript-based command-and-control framework used by China-aligned advanced persistent threat groups since 2023.
The campaigns have targeted corporate and government organizations across Asia, with education, IT, banking, financial services, and government among the sectors observed. Infoblox analysts identified the latest expansion while tracking a vast ecosystem of illegal casino domains.
Infoblox said in a report shared with Cyber Security News (CSN) that the same disguise now extends to Chinese-language adult sites, widening the places where the operators can hide.
![Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source - Infoblox)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQTSm7_m5CC6954tb2UPd-6mwgJp_ePkYRkNDdXayKurJLKiM5PP1SytYKNaM8y4pH_c2cfF8N0nN7K9L1ey1a1Grd5uL_MyzQR5DDe0uKDJXagPC0KQe26MYpjEAumOEDIm93NDr1b5Eil1gus8QsfU55FhZteq00E1lBdbai9FHhdQES9-H9WYQuslo/s1600/Three%20casino%20sites%20from%20left%20to%20right,%20vip311%5B.%5Dcc,%20zzyud%5B.%5Dcom,%20zenplay77-x%5B.%5Dspace;%20vip311%5B.%5Dcc%20is%20associated%20with%20PeckBirdy%20(Source%20-%20Infoblox).jpg)
It also underlines how criminal web ecosystems can give espionage operators a cover story, and not only that even the danger is not a casino page alone.
Attackers use pages that look unimportant to host or embed code, establish background web connections, and blend their traffic into a crowded and frequently ignored corner of the internet. That approach can leave defenders focused on the lure while the real espionage channel remains unseen.
Hackers Are Hiding Espionage Infrastructure
Researchers separate this activity from two broader casino-abuse models: illegal gambling and money laundering operations, and scam gambling sites that prevent victims from withdrawing funds.
PeckBirdy sites are different because the casino is set dressing, not a service intended to attract or retain real players. One observed page registered a JavaScript service worker and loaded a suspicious script resembling earlier PeckBirdy code.
Service workers can run in the background, making them useful for maintaining contact after a page visit. Similar abuse has appeared in service worker credential theft campaigns, where background browser code can intercept or persist beyond normal browsing.
The report highlighted a casino-themed decoy that embedded a command server behind familiar branding. Investigators then found that live WebSocket connections reached another domain, while related adult websites used the same pattern.
This layered design makes quick reputation checks less reliable, particularly when automated scanners do not fully capture browser-side behavior.
![Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source - Infoblox)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAMZD1oYveHXSbXMV45cYXPhOXOt3igerI-jt9Wtlwud0fGqi4iCIoS6sQhR98bo4J-keujZ1KjjKqGajfwqjhc5BIaYJFHkGxFJguhHGg6Pf5fO30RhqRvVNP9ruN_vNX3r442yVwnW4I1iCXQ48M6NY4u-ILtmmk5wRfYauJXaxjLoNup6FgiB0rqMg/s1600/Screenshot%20of%20a%20Chinese-language%20casino%20domain%20(vip311%5B.%5Dcc)%20(Source%20-%20Infoblox).webp)
PeckBirdy can also lead victims to false browser-update prompts that deliver backdoors, a familiar social-engineering route that deserves closer review alongside reports of fake browser update malware.
The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access, raising the potential impact from a single web visit to a wider network intrusion.
Detection Gaps Demand Context
The researchers found that just over 3% of their enterprise customers resolved at least one PeckBirdy C2 domain. A lone lookup is not always proof of compromise because one historical domain resembles a possible typo.
But repeated resolution of three to ten distinct C2 domains is a meaningful warning sign that warrants investigation, rather than a single alert viewed in isolation.
Detection coverage varied sharply. A known PeckBirdy domain had 13 detections in VirusTotal, another had three, and the WebSocket-related domain had none at the time of publication.
That gap shows why defenders should not treat a clean reputation result as clearance, especially when investigating Chinese threat actor infrastructure that is designed to blend into common web services.
Security teams should review DNS, proxy, and browser telemetry for the indicators below, then correlate connections with endpoint events and unusual service-worker registrations.
They should prioritize hosts contacting several distinct domains, preserve relevant logs, and examine whether users were sent to fake updates or unfamiliar gambling and adult pages.
Blocking one domain at a time is unlikely to solve the problem because operators rotate domains and infrastructure quickly.
Organizations should instead combine domain monitoring with web filtering, timely browser and endpoint updates, least-privilege controls, and incident-response checks that look for related activity across the network.
That layered approach also helps uncover covert C2 communication methods that do not resemble conventional malware traffic.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Decoy casino domain | vip311.cc | Casino-themed site identified as embedding PeckBirdy C2 infrastructure |
| Casino comparison domain | zzyud.com | Casino site shown in the researchers’ comparison of lookalike pages |
| Casino comparison domain | zenplay77-x.space | Casino site shown in the researchers’ comparison of lookalike pages |
| Casino domain | 11170011.com | Illegal Chinese-language casino site using impersonated branding |
| Investment scam domain | puqxr.com | Site impersonating an investment platform |
| Casino domains | 80074.cc, 11168833.com | Near-identical casino sites using different branding |
| Casino domains | 312zym001.cc, am125.cc, 843470.cc | Recently active casino-site examples |
| Redirecting casino domain | 1862.cc | Casino site that fingerprinted visitors and redirected them by location |
| IP address | 157.185.143.150 | Final destination observed when accessing 1862.cc from a Hong Kong IP address |
| IP address | 146.103.91.133 | Final destination observed when accessing 1862.cc from a Japanese IP address |
| Scam gambling domain | dollycasino.com | Scam gambling site associated with complaints about withdrawal problems |
| Scam gambling domain | dragobet.net | Scam gambling site promoted through injected comment spam |
| Redirect domain | appcasino.online | Domain reached through clicks on dragobet.net |
| Scam gambling domain | summer138.t | Joker-branded scam gambling site |
| Scam gambling domain | storebet77.support | Joker-branded scam gambling site using misleading branding |
| Scam gambling domain | realz.com | Scam gambling site advertising a deposit bonus |
| Casino decoy domain | asg78.com | Chinese-language casino domain observed loading a suspicious JavaScript payload |
| Malicious JavaScript URL | js.cache-mcp.com/layer.js | Suspicious payload loaded by asg78.com |
| C2 domain | cache-mcp.com | PeckBirdy command-and-control domain embedded in casino pages |
| C2 domain | mcp-source.online | WebSocket-related PeckBirdy domain used to collect connections |
| C2 domain | cache-cdn.org | Previously identified PeckBirdy domain with VirusTotal detections |
| Possible typosquat/C2-related domain | githubassets.net | Historical PeckBirdy domain that may also receive accidental typo-related queries |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/espionage-infrastructure/