A sketchy casino website may be hiding much more than illegal gambling.
New research from Infoblox Threat Intel found that sprawling networks of online casino sites are being used for three very different purposes: illegal gambling and money laundering, consumer fraud, and command-and-control (C2) infrastructure linked to China-aligned cyber espionage groups.
The problem for defenders is that the sites can look remarkably similar. A domain that appears to be little more than questionable employee browsing could instead be communicating with malicious C2 infrastructure.
“Security teams see a Chinese-language gambling site, assume it's an employee browsing violation, and close the ticket,” Zach Edwards, staff threat researcher at Infoblox, told eSecurityPlanet. “That reflex is exactly what PeckBirdy is counting on.”
Edwards said the casino sites represent a potential security blind spot because China-aligned APT groups can use them to disguise malicious infrastructure. Infoblox even identified a live command-and-control domain associated with the activity, with zero detections on VirusTotal.
More than 1.7 million casino domains fuel a criminal ecosystem
Infoblox researchers divided the infrastructure into three broad categories.
The largest consists of illegal Chinese-language casino sites. Infoblox said it tracks more than 1.7 million domains in this ecosystem, which researchers linked to illegal gambling and underground money laundering.
A relatively small number of infrastructure clusters account for most of that footprint. Infoblox attributed roughly 745,000 domains to FUNNULL and about 666,000 to Vigorish Viper, together representing approximately 81% of the Chinese-language casino domains it tracks.
The findings fit into a much larger criminal economy. The United Nations Office on Drugs and Crime has warned that illegal online gambling has become intertwined with cyber-enabled fraud, underground banking, human trafficking, and other forms of transnational organized crime.
The infrastructure is also highly resilient. Operators can maintain large numbers of domains and move users when individual sites are blocked, making domain-by-domain takedowns difficult.
That scale echoes earlier Infoblox research covered by eSecurityPlanet, which linked 236,000 scam domains to abuse of the legitimate DCloud Uni-App development framework.
‘Scambling’ sites take the money and disappear
The second category looks like gambling but operates more like conventional online fraud.
Infoblox calls the model “scambling,” or scam gambling. These sites advertise casino games, sports betting, large deposit bonuses, and other incentives designed to persuade victims to put money into the platform.
Victims may appear to accumulate winnings, but withdrawals can be delayed or blocked through unexpected fees and other tactics. Once complaints pile up and deposits slow, operators can abandon the site and move elsewhere.
Infoblox said it has seen some weeks in 2026 with roughly twice as many newly observed scambling sites as comparable weeks following reporting on the activity last year.
The campaigns also use spam and search manipulation to attract victims. Researchers found casino domains promoted through spam accounts, user profiles, and other injected content on unrelated websites, another example of how attackers can abuse otherwise legitimate web infrastructure to spread their links.
Similar infrastructure abuse has surfaced elsewhere. eSecurityPlanet previously outlined how BADIIS malware compromised more than 1,800 Windows IIS servers to manipulate search results while leaving legitimate websites functioning.
PeckBirdy hides espionage infrastructure behind casino sites
The third category carries the clearest enterprise security implications.
Infoblox found casino and adult websites being used as cover for C2 infrastructure associated with PeckBirdy, a JScript-based command-and-control framework used by China-aligned threat groups.
Trend Micro documented PeckBirdy in January, describing campaigns associated with China-aligned groups targeting organizations in Asia. Infoblox's newer research found additional infrastructure embedded behind low-quality casino and adult websites.
That camouflage can create a dangerous blind spot. Security teams may see traffic to a questionable gambling site and dismiss it as an acceptable-use problem rather than investigate it as a possible compromise.
Detection is another concern. Infoblox said one PeckBirdy C2 domain, mcp-source[.]online, had zero VirusTotal detections as of Aug. 31, while two related domains had 13 and three detections.
The researchers found that just over 3% of Infoblox enterprise customers had resolved at least one PeckBirdy C2 domain. However, organizations resolving only one or two PeckBirdy domains were dominated by requests to githubassets[.]net, a typosquat of a legitimate GitHub asset host that can be reached accidentally through manual or code-level typos and does not, on its own, indicate a compromise. Education was among the leading sectors observed, alongside IT, banking, financial services, and government.
The stronger warning sign was repeated contact. Infoblox said resolving three to 10 distinct PeckBirdy C2 domains is a meaningful signal that a network could be compromised.
The technique resembles a broader attacker strategy of hiding malicious communications inside infrastructure that defenders may initially consider ordinary. eSecurityPlanet has also examined how threat actors abuse dynamic DNS to build resilient C2 infrastructure that is harder to identify and block.
What security teams should do
The biggest mistake may be treating every casino-domain alert as nothing more than an employee browsing violation.
Infoblox’s findings suggest security teams should take several steps when suspicious gambling or adult domains appear in their environments:
- Investigate before closing the alert: Examine suspicious casino domains for additional connections and known C2 indicators. Infoblox’s PeckBirdy investigation found suspicious JavaScript payloads, service-worker activity that most web scanners may not capture, and WebSocket connections that can be blocked from some automated scanners.
- Look for repeated connections: Infoblox said resolving three to 10 distinct PeckBirdy C2 domains is a meaningful potential-compromise signal. One or two resolutions may have benign explanations, particularly requests involving the githubassets[.]net typosquat, which can result from manual or code-level typos.
- Monitor DNS activity: Review DNS telemetry for suspicious or unexpected domain resolutions, particularly repeated contact with multiple PeckBirdy C2 domains.
- Correlate with threat intelligence: Compare suspicious domains and related infrastructure against current threat intelligence, rather than relying exclusively on reputation scores or existing blocklists.
- Investigate clusters, not just individual domains: Related requests and infrastructure patterns may reveal malicious activity that would be easy to miss when alerts are examined in isolation.
As Edwards put it, “If defenders aren't triaging casino domains as a distinct threat category, they're leaving a door wide open for nation-state actors.”
The casino page may be nothing more than scenery. For defenders, what the browser or endpoint communicates to or from behind that page could reveal the actual threat.
Related reading: Microsoft recently linked more than 30 domains to MacSync Stealer by tracking behavior across the malware’s attack chain.





