Post

Low-quality Casino Sites Conceal Highly Dangerous Threat Actors

Low-quality Casino Sites Conceal Highly Dangerous Threat Actors

Low-quality Casino Sites Conceal Highly Dangerous Threat Actors

If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance. A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution. Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing.

Infoblox tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other dubious activities. While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure. The Infoblox report explains that major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains. One likely explanation is account theft at those providers, a practice documented previously as ‘infrastructure laundering.’ According to a July 2026 report from the UN Office on Drugs and Crime (UNODOC), online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand.

A subset of these sites are used by China-aligned threat groups. “China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites,” Infoblox stated. PeckBirdy, as noted by Trend Micro researchers, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware. Infoblox identified three casino sites–vip311.cc, zzyud.com and zenplay77-x.space–with vip311.cc associated with PeckBirdy. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain.

“The most important thing for defenders to do is stop ignoring casino domains,” Infoblox argues. An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. Security analysts who review suspicious network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket.

Read full article

This post is licensed under CC BY 4.0 by the author.