Low-quality casino sites conceal highly dangerous threat actors
Security firm Infoblox has warned that some low-quality Chinese-language gambling and adult websites conceal command-and-control (C2) infrastructure used by espionage groups and malware distributors, meaning employees browsing such sites at work could expose networks to more than a mere productivity issue. Researchers say the topic has largely been overlooked because the picture is genuinely complex: casinos, scam sites and state-linked threat actors share near-identical templates, making it hard for defenders to tell a harmless (if illicit) gambling site from one hiding an active attack.
Infoblox tracks roughly 1.7 million such casino domains, some tied to North Korean money-laundering and tax evasion, and notes that major US cloud providers—Amazon, Microsoft, Cloudflare and Google—continue to unwittingly host associated infrastructure, likely via stolen accounts or "infrastructure laundering." A UNODC report from July 2026 estimated regional online scam losses of $88.3–114.1 billion in 2025. Separately, China-aligned APT groups have since 2023 used the PeckBirdy framework, hidden within such casino sites, to serve fake software-update pages that deliver malware; Infoblox found just over 3% of its enterprise customers had contacted a PeckBirdy C2 domain, and it is urging security teams not to dismiss alerts on these domains as simple browsing violations.
- Illegal gambling sites can hide state-linked malware C2 infrastructure
- Infoblox tracks 1.7 million such Chinese-language casino domains
- PeckBirdy malware framework hides in these sites since 2023