Infoblox Threat Intel has sorted the flood of low-quality casino websites into three categories — and one of them serves China-aligned APT groups as camouflaged command-and-control infrastructure. Security teams that dismiss gambling domains as a browsing policy issue are doing exactly what the attackers expect.

For most security teams, a casino domain in the DNS log is a nuisance at worst — an employee browsing where they should not. New research from Infoblox Threat Intel argues that this reflex is exactly what a China-aligned espionage operation counts on. In a report published on 15 September 2026, the DNS security specialist sorts low-quality gambling websites into three categories: illegal gambling and money laundering across more than 1.7 million domains, consumer fraud through rigged betting platforms, and malware command-and-control (C2) infrastructure disguised as a casino.

Three purposes, one appearance

The practical problem, according to the company, is that the three types are almost impossible to tell apart in a browser. The report opens with screenshots of three sites and asks readers to identify the one used in an espionage campaign; the answer is vip311[.]cc, a C2 domain of the PeckBirdy framework, which China-aligned advanced persistent threat (APT) groups have run since 2023 against corporate and government targets across Asia. Underneath, the researchers say, the three populations behave nothing alike: real gambling in the first case, rigged games in the second, pure set dressing in the third.

Type 1: an industrial money laundering layer

The Chinese-language casino ecosystem is by far the largest, with over 1.7 million tracked domains. Infoblox describes it as a load-bearing element of transnational organised crime, moving money out of China and other Asian jurisdictions and laundering proceeds from online criminal operations, including North Korean ones. The market is highly concentrated: the FUNNULL CDN and Vigorish Viper networks account for roughly 745,000 and 666,000 domains, about 81 per cent of the total, and the top four actors for around 99.5 per cent.

The findings align with a regional threat assessment published by the UN Office on Drugs and Crime in July 2026. UNODC put global illegal betting revenue at up to 1.7 trillion US dollars a year and estimated losses from transnational online scam operations across East and Southeast Asia, Australia and New Zealand at 88.3 to 114.1 billion dollars for 2025 alone, roughly three times the 2023 figure. It also judged domain blocking largely ineffective on its own, citing a 2024 Philippine order against more than 7,000 gambling sites that had limited effect.

One detail runs counter to defender intuition: these sites generally work. Support channels respond and withdrawals are processed, because the operators need player trust. Deposits are the pipeline the laundering depends on.

Type 2: “scambling” scales up

The second category, thousands of domains, targets mainly English-speaking and European audiences. The term “scambling” — scam gambling — is credited to journalist Brian Krebs, who in July 2025 documented more than 1,200 polished fake gaming sites where deposits could be played but winnings never withdrawn. In some weeks of 2026, Infoblox says, it saw twice as many new scambling domains as a year earlier. Typical markers are aggressive deposit bonuses, complaint clusters on platforms such as Trustpilot, and blackhat SEO campaigns injecting the domain into comment fields and user profiles on unrelated sites.

Type 3: PeckBirdy and the detection gap

The smallest population is the most sensitive. A few dozen Chinese-language casino and, newly, adult websites embed C2 domains for the PeckBirdy framework, documented by Trend Micro in January 2026. Infoblox traced a JavaScript payload from cache-mcp[.]com to a further domain, mcp-source[.]online, contacted over WebSocket connections most automated scanners never observe. At the end of August 2026 it had zero detections on VirusTotal; two related domains had 13 and three.

Just over three per cent of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with education, IT, banking and government among the leading target sectors. The decisive signal, the company argues, is not query volume but the number of distinct C2 domains resolved: a single lookup of githubassets[.]net, a typosquat of a legitimate GitHub host, may be a code-level typo, while repeated contact with three to ten different C2 domains should be treated as a possible compromise.

US providers as a point of leverage

The infrastructure analysis yields the most actionable finding for regulators and providers. All three populations depend heavily on US registrars, and Amazon, Microsoft, Cloudflare and Google host parts of the observed infrastructure, partly, Infoblox suspects, through stolen accounts, a practice known as infrastructure laundering. Around 967,000 Chinese-language casino domains are registered through US registrars but hosted in China or Hong Kong, a split the researchers call “fronting”: registration sits within reach of US abuse processes, hosting does not. Scambling infrastructure, by contrast, is almost entirely US and European.

What defenders should take away

The central recommendation is uncomfortable in its simplicity: stop ignoring casino domains. An alert closed as a browsing policy violation is, according to the researchers, exactly the outcome PeckBirdy operators expect — the camouflage works because the dismissal is usually reasonable. Security teams need a triage path that establishes whether a gambling domain carries a C2 payload before the ticket is closed; Infoblox has published the relevant indicators on GitHub. The findings rest on the vendor’s own telemetry and have not been independently verified, but they converge with UN assessments on a market too large to be treated as background noise.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner