{
  "id": 7632566,
  "title": "Low-quality casino sites conceal highly dangerous threat actors",
  "url": "https://urgent.news/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors-7632566",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-15T19:38:58.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652"
  },
  "original_language": "en",
  "account": "Chinese-language gambling and adult websites may not only be a waste of time and money for employees, but they could also expose their employers to serious malware. Infoblox, a security company, has highlighted that these sites can act as command-and-control (C2) infrastructure for espionage and malware distribution. Infoblox tracks approximately 1.7 million Chinese-language casino websites that engage in illegal gambling, money laundering, tax avoidance, and various other illicit activities.\n\nThese casino sites can be challenging to distinguish from legitimate ones due to their use of common design and function templates. Many operate as legitimate casinos, profiting from house odds. However, some of these sites rely on US cloud providers for their computing infrastructure, often through account theft at major US hosting companies such as Amazon, Microsoft, Cloudflare, and Google. This practice, known as infrastructure laundering, enables these sites to carry out illegal activities.\n\nUNODC's 2025 report reveals that various crime syndicates are increasingly using common infrastructure for cybercrime, resulting in significant financial losses across East Asia, Southeast Asia, Australia, and New Zealand. Among these sites, some offer scam gambling, where visitors place bets but cannot withdraw winnings if they win. Additionally, there are sites used by China-aligned threat groups.\n\nChina-aligned Advanced Persistent Threat (APT) groups have been utilizing the PeckBirdy framework since 2023, hiding their malware C2 domains within low-quality Chinese-language casino websites. PeckBirdy is a script-based framework that attackers can load onto compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages to lure victims into downloading malware.\n\nDespite the prevalence of these malicious sites, security professionals often dismiss them as routine employee browsing violations. Infoblox urges security analysts to reevaluate these sites and check for malicious payloads before closing review tickets. This caution is crucial, as these seemingly harmless domains are precisely what threat actors rely on to successfully execute their attacks.",
  "summary": "Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Low-quality casino sites conceal highly dangerous threat actors",
        "url": "https://urgent.news/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors",
        "published": "2026-09-15T19:38:58.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}