Low-quality casino sites conceal highly dangerous threat actors
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
Chinese-language gambling and adult websites may not only be a waste of time and money for employees, but they could also expose their employers to serious malware. Infoblox, a security company, has highlighted that these sites can act as command-and-control (C2) infrastructure for espionage and malware distribution. Infoblox tracks approximately 1.7 million Chinese-language casino websites that engage in illegal gambling, money laundering, tax avoidance, and various other illicit activities.
These casino sites can be challenging to distinguish from legitimate ones due to their use of common design and function templates. Many operate as legitimate casinos, profiting from house odds. However, some of these sites rely on US cloud providers for their computing infrastructure, often through account theft at major US hosting companies such as Amazon, Microsoft, Cloudflare, and Google. This practice, known as infrastructure laundering, enables these sites to carry out illegal activities.
UNODC's 2025 report reveals that various crime syndicates are increasingly using common infrastructure for cybercrime, resulting in significant financial losses across East Asia, Southeast Asia, Australia, and New Zealand. Among these sites, some offer scam gambling, where visitors place bets but cannot withdraw winnings if they win. Additionally, there are sites used by China-aligned threat groups.
China-aligned Advanced Persistent Threat (APT) groups have been utilizing the PeckBirdy framework since 2023, hiding their malware C2 domains within low-quality Chinese-language casino websites. PeckBirdy is a script-based framework that attackers can load onto compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages to lure victims into downloading malware.
Despite the prevalence of these malicious sites, security professionals often dismiss them as routine employee browsing violations. Infoblox urges security analysts to reevaluate these sites and check for malicious payloads before closing review tickets. This caution is crucial, as these seemingly harmless domains are precisely what threat actors rely on to successfully execute their attacks.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Low-quality casino sites conceal highly dangerous threat actors theregister.com