Low-quality casino sites conceal highly dangerous threat actors
Infoblox reveals China-aligned APT groups hiding PeckBirdy malware C2 domains inside roughly 1.7 million Chinese-language illegal casino websites.
An Infoblox report says it tracks about 1.7 million Chinese-language casino sites enabling illegal gambling, some of which double as command-and-control infrastructure. China-aligned APT groups have hidden PeckBirdy framework C2 domains inside these low-quality casino sites since 2023, injecting scripts that display fake software update pages to deliver malware. Over 3 percent of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, and some sites rely on US cloud providers via 'infrastructure laundering.' Infoblox urges defenders not to dismiss casino-domain alerts as mere employee browsing violations.
- China-aligned APTs hide PeckBirdy C2 in Chinese-language casino sites since 2023
- Over 3% of Infoblox enterprise customers resolved a PeckBirdy C2 domain
- Injected scripts display fake update pages to deliver malware
- Some malicious sites rely on US cloud providers via 'infrastructure laundering'
- Defenders should not dismiss casino-domain alerts as browsing violations
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | vip311.cc | e. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc ass |
| domain | zenplay77-x.space | o sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem i |
| domain | zzyud.com | s of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with |
Full article562 words · extracted from theregister.com · click to collapse
security
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance.
A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution.
Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing.
REG AD
Infoblox says it tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other dubious activities.
REG AD
And these casino sites can be difficult to distinguish from one another. They tend to use variations of common templates in terms of design and function. Many operate like a legal casino would, just relying on the advantage of house odds to profit.
While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure.
"Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report explains. "One likely explanation is account theft at those providers, a practice documented previously as 'infrastructure laundering.'"
That refers to hosting companies like Funnull that have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities.
According to a July 2026 report from the UN Office on Drugs and Crime (UNODC), disparate crime syndicates increasingly use common infrastructure for cybercrime, while online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand.
A subset of casino sites offer scam gambling, or "scambling." Visitors place bets but can't get their money out if they win.
And then there's a subset of sites used by China-aligned threat groups.
"China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites," Infoblox said.
REG AD
PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware.
The problem is that each of these three types of sites, though they change frequently, looks similar. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain.
"The most important thing for defenders to do is stop ignoring casino domains," Infoblox argues. "An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable – these domains genuinely are, most of the time, exactly what they appear to be."
Security analysts who review suspicious network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652