Low-quality casino sites conceal highly dangerous threat actors
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance.
A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution.
Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing.
REG AD
Infoblox says it tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other dubious activities.
REG AD
And these casino sites can be difficult to distinguish from one another. They tend to use variations of common templates in terms of design and function. Many operate like a legal casino would, just relying on the advantage of house odds to profit.
While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure.
"Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report explains. "One likely explanation is account theft at those providers, a practice documented previously as 'infrastructure laundering.'"
That refers to hosting companies like Funnull that have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities.
According to a July 2026 report from the UN Office on Drugs and Crime (UNODC), disparate crime syndicates increasingly use common infrastructure for cybercrime, while online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand.
A subset of casino sites offer scam gambling, or "scambling." Visitors place bets but can't get their money out if they win.
And then there's a subset of sites used by China-aligned threat groups.
"China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites," Infoblox said.
REG AD
PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware.
The problem is that each of these three types of sites, though they change frequently, looks similar. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain.
"The most important thing for defenders to do is stop ignoring casino domains," Infoblox argues. "An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable – these domains genuinely are, most of the time, exactly what they appear to be."
Security analysts who review suspicious network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket. ®
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.