Subscribe Sign in

Low-quality casino sites conceal threat actors

2 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1×3 A3 A6 D1 D2×2 D3×4 D4×2 E3×2 F2×5 all 30 rules
  • Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
  • Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing.
  • While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure.
  • A subset of casino sites offer scam gambling, or " scambling."
  • PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

Headline as published: Low-quality casino sites conceal highly dangerous threat actors

There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.

Nothing was measured here, so nothing is claimed. How this is checked

Read the full reportHide the full report2 min

Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites

If your employees are visiting Chinese-language gambling or adult sites, they may not just be wasting time and money, but potentially encountering serious malware hidden behind domains that look like mostly harmless entertainment at first glance.

A report from Infoblox urges the security community to pay closer attention to these websites, because some double as command-and-control (C2) infrastructure for espionage and malware distribution.

Zach Edwards, staff threat researcher at Infoblox, suggests security researchers and the media have ignored these sites because the story is complicated and confusing.

Infoblox says it tracks about 1.7 million Chinese-language casino websites that facilitate illegal gambling. These support North Korean money laundering and tax avoidance, among other activities.

And these casino sites can be difficult to distinguish from one another. They tend to use variations of common templates in terms of design and function. Many operate like a legal casino would, just relying on the advantage of house odds to profit.

While these sites provide illegal gambling and adult entertainment for online visitors from China and Asia, some rely on US cloud providers for computing infrastructure.

"Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report explains. "One likely explanation is account theft at those providers, a practice documented previously as 'infrastructure laundering.'"

That refers to hosting companies like Funnull that have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities.

According to a July 2026 report from the UN Office on Drugs and Crime (UNODC), disparate crime syndicates use common infrastructure for cybercrime, while online scams resulted in estimated losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia, and New Zealand.

A subset of casino sites offer scam gambling, or " scambling." Visitors place bets but can't get their money out if they win.

And then there's a subset of sites used by China-aligned threat groups.

"China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites," Infoblox said.

PeckBirdy, as noted by Trend Micro researchers in January, is a script-based framework that attackers can load through compromised websites. In one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and displayed fake software update pages designed to entice victims to download malware.

The problem is that each of these three types of sites, though they change frequently, looks similar. Infoblox notes that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain.

"The most important thing for defenders to do is stop ignoring casino domains," Infoblox argues. "An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable – these domains genuinely are, most of the time, exactly what they appear to be."

Security analysts who review network contacts are advised to check whether these casino domains include malicious payloads before closing the review ticket. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 12.4 11 62 -0.5 44
Mundane Readneutralized from The Register 8.8 8 62 -0.1 44

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works