PeckBirdy traffic reaches enterprise networks through casino decoys
China-aligned threat actors are using Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure, with Infoblox telemetry showing the framework touching networks across a broad range of enterprise customers. Infoblox Threat Intelligence said just over 3% of its enterprise customers resolved at least one domain associated with PeckBirdy, indicating that…
China-linked threat actors are concealing PeckBirdy command-and-control infrastructure by exploiting Chinese-language casino and adult websites, according to Infoblox telemetry. The framework has been detected across a wide range of enterprise customers, with just over 3% of Infoblox's enterprise customers resolving at least one domain associated with PeckBirdy.
This tactic takes advantage of the fact that gambling and adult domains are often dismissed as policy violations instead of being investigated as potential malware infrastructure. Infoblox tracks about 1.7 million Chinese-language casino domains, providing ample background noise for malicious infrastructure to blend in. Researchers discovered casino pages loading PeckBirdy-related JavaScript and establishing connections to command-and-control systems through WebSockets.
Some domains, such as mcp-source[.]online, remained undetected by VirusTotal despite checks, while others like cache-mcp[.]com and cache-cdn[.]org had multiple detections. Defenders should be cautious not to automatically dismiss alerts involving such sites, as the same traffic may conceal malware communications or indicate a compromised host.
PeckBirdy, a JScript-based command-and-control framework used by China-aligned advanced persistent threat actors since 2023, has been linked to attacks against Chinese gambling businesses, government entities, and private organizations in Asia. The operators' identities remain unclear, but they are generally described as China-aligned rather than naming a specific state-sponsored group.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.