Why Should Anyone Care About Casino Websites?
Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Over the last decade there’s been massive growth in both gambling websites catering to Chinese audiences and similar casino sites targeting people all over the world. There’s also been growth in legal gambling and casino websites, but the scale of these compared to the malicious casinos is marginal.

This report focuses on the crime disguised by the proliferation of betting sites that litter the internet. There are three major purposes hiding behind most illicit online casino sites: facilitating illegal gambling across China and Asia, and laundering money; stealing money from customers or preventing them from cashing out (“scambling”); and operating command-and-control (C2) infrastructure under the cover of a casino website. That last category is used by little-known China-aligned advanced persistent threat (APT) actors operating since 2023 using a C2 framework known as PeckBirdy to attack corporate and government targets across Asia.
PeckBirdy is not the only actor using this approach. Sable Squirrel, documented in recent Infoblox research, uses the same technique at larger scale: controlling more than 10,000 domains and spending an estimated $7 million on expired domains to build a streaming and gambling empire that also functions as malware C2 infrastructure.
Our new casino research shows an expansion of the industries being targeted with these ongoing PeckBirdy APT campaigns, which are now also using low-quality Chinese-language adult websites as part of the ruse. We also documented a C2 domain being used by the PeckBirdy framework that had zero detections on VirusTotal at the time of this publication.
The hardest part of sorting these sites into the three categories is that they look nearly identical in a browser. From the three websites shown in Figure 1, can you guess which one is used in a PeckBirdy campaign?

Figure 1. Screenshots of three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy
The answer is vip311[.]cc—the site on the left, a PeckBirdy C2 domain used by China-aligned APT groups.
Sorting the Lookalikes
We track three distinct types of these malicious casino websites. They look similar in a browser, but behave nothing alike underneath, as Table 1 shows.
| Type 1 | Type 2 | Type 3 | |
|---|---|---|---|
| Description | Illegal Chinese-language casino websites | Scambling (scam gambling) websites | PeckBirdy Chinese-language casino decoy sites |
| Scale | Over 1.7 million domains | Thousands of domains | Dozens of domains |
| Audience (users & victims) | Mostly mainland Chinese players and money-laundering groups, occasionally other languages | Global, mostly non-Chinese-language | No real users (decoy) |
| Real gambling | Largely yes | No, it’s rigged/can’t cash out | No, it’s set dressing |
| Purpose | Illegal gambling and money laundering | Consumer fraud | Espionage, intrusion, malware C2 |
| Operators | Triad-aligned syndicates, casino junket-adjacent groups | Numerous threat actors | China-aligned APT actors |
| Customer support | Real and responsive; operators protect their reputation to keep players depositing | Oftentimes real, scripted responses to tough questions, stalls withdrawals | None: no real users |
Table 1. The three types of malicious casino websites tracked by Infoblox Threat Intel
Type 1: Illegal Chinese-Language Casinos
The most prevalent type of online casino infrastructure—the Chinese-language casino websites facilitating illegal gambling—is now a load-bearing component of transnational organized money laundering. It supports the movement of money out of China and other Asian jurisdictions to avoid taxes and oversight, and North Korea uses it to launder proceeds from its online criminal operations. These Chinese-language online casinos are one leg of the Asian underground banking economy operating across over 1.7 million domains. But as we explain throughout this research, these websites are being registered and hosted with U.S. and European companies, many for long periods of time.
Infoblox Threat Intel has been tracking gambling operations intensively since uncovering Vigorish Viper and their sponsorships of European football teams in early 2024. In July 2026, the United Nations Office on Drugs and Crime (UNODC) published a new regional threat assessment for Southeast Asia titled “An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for Southeast Asia 2026.” UNODC concluded that illegal online gambling is no longer a standalone problem for gambling regulators. Its convergence with cyber-enabled fraud, underground banking and human trafficking has made it a primary revenue source and operational enabler for organized crime across the region.
UNODC estimated global illegal betting revenue up to $1.7 trillion annually, much of it serviced by criminal infrastructure based in Southeast Asia. Separately, they estimated losses from transnational online scam operations across East Asia, Southeast Asia, Australia, and New Zealand at $88.3 billion to $114.1 billion for 2025 alone, roughly three times the $18–37 billion estimated for 2023. UNODC described the underlying shift as syndicates moving from territorially rooted, single-specialty crime toward an integrated, service-based criminal economy, with laundering, trafficking, smuggling and data harvesting operating as specialized departments plugged into one broader criminal ecosystem.
In its case study on the Vault Viper network, UNODC found that vast numbers of seemingly independent Chinese-language gambling brands ultimately rely on a small number of backend platform providers, DNS infrastructure clusters, and payment processing systems. The footnote on that passage cites our original 2025 research, “Vault Viper: High Stakes, Hidden Threats.”
UNODC was explicitly pessimistic about blocking these underground casino threats one domain at a time. They described domain redirection as a standard operational practice for these groups: they maintain thousands of active domains and rotate to a new one whenever the current one is blocked. The report concludes that this makes domain blocking largely ineffective as a standalone measure. The UNODC report also highlighted that the Philippines ordered more than 7,000 illegal gambling websites blocked in 2024, which had limited effect and was described as “practical futility.”
At Infoblox we track Chinese-language casino domains based on specific actor groups but even across these segments we see what appears to be shared best practices, infrastructure and code.
We track sixteen clusters of very different sizes, and a small number of them are behind the vast majority of these Chinese-language casino websites. The two largest clusters are the FUNNULL and Vigorish Viper networks—associated with the bulletproof CDN infrastructure that these casinos launder their hosting through—holding roughly 745,148 and 666,157 domains respectively, together about 81% of the population. A third actor holds another 265,469 domains, and a fourth holds 56,446 domains, bringing the top four to roughly 99.5% of every Chinese-language casino domain we track. The remaining actors, several now dormant, add up to only a few thousand domains between them. Most were tracked because of some unique behavior or infrastructure decision, which may in fact have been an A/B test by one of the larger groups. See Table 2.
| Actor (report label) | Domains | Status |
|---|---|---|
| FUNNULL CDN* | 745,148 | active |
| Vigorish Viper | 666,157 | active |
| Actor #3 | 265,469 | active |
| Actor #4 | 56,446 | active |
| Actor #5 | 2,632 | active |
| Actor #6 | 1,858 | active |
| Actor #7 | 1,072 | dormant |
| Actor #8 | 816 | active |
| Actor #9 | 814 | dormant |
| Actor #10 | 667 | active |
| Actor #11 | 491 | dormant |
| Actor #12 | 283 | dormant |
| Actor #13 | 179 | dormant |
| Actor #14 | 171 | dormant |
| Actor #15 | 83 | active |
| Actor #16 | 72 | dormant |
Table 2. The sixteen Chinese-language casino actors by domain count and current activity status. *FUNNULL CDN also hosts a small number of investment scam websites targeting the U.S. but the vast majority of their websites are Chinese-language casinos used for illegal gambling and money laundering.
Throughout this report we’ll talk broadly about this Chinese-language casino ecosystem, knowing that the vast majority of the sites are set up by two actors who make similar hosting decisions, and that our broader group of actors are also closely aligned.
Gambling has been illegal for people in mainland China for decades. A March 2021 criminal law amendment, covered by some Asian gambling outlets, extended that prohibition: It’s now also illegal to operate an overseas gambling establishment or to organize and solicit Chinese residents to use one. The amendment likely enabled the prosecution of SunCity Gaming executives in late 2021, including CEO Alvin Chau, who was sentenced to 18 years in a Chinese jail for facilitating over $100 billion in illegal bets.
That prohibition and even the prosecution of an executive running one of these networks did not remove demand or the willingness to serve the massive Chinese gambling audience. It did, however, move the entire Chinese gambling market into an even more underground economy served by murky Chinese operators whose money flows into better-known gambling brands that launder their reputation by sponsoring European football clubs. This laundering practice has been covered in previous Infoblox reports and extensively by “PlayTheGame” in their 2024 piece “Meet the hydras: tracing the illegal gambling operators that sponsor football.”
The Chinese-language casino websites differ from the other two types in one important respect: they run real customer support. Their contact channels work. They process withdrawals. Many of the games probably run normal house odds, because the house edge already wins over time and because the operator’s real business depends on player trust. A player who cannot cash out stops depositing, and deposits are the pipeline the broader money laundering runs through.
For most defenders, this is the counterintuitive part. They are working casino websites that happen to be illegal, run by operators who need them to keep working, because the deposits are what the laundering depends on.
Recent Examples of Illegal Chinese-Language Casinos
Across the more than 1.7 million illegal Chinese-language casino sites we track, many are online for days or weeks.
Some serve content directly, while others redirect visitors to unexpected hosts based on device details (IP address or perceived location, device type, and language). All the hosts are likely meant to be temporary because many of them are trying to facilitate illegal gambling in mainland China and face blocks and other dynamic restrictions from the Great Firewall of China.
We track this complex ecosystem of gambling through several different methods.
Some actors constantly spin up new sites with unique templates, visual layouts, and offers. We see a mix of classic casino games, slots, video games for money, sports gambling, stock investing, and some of them also mix in explicit adult offers. Other actors run near-identical websites with only cosmetic changes: switching out brands, graphics, and colors, but using identical offers and underlying language from site to site. On essentially every one of these sites you will find links to customer support portals, oftentimes hosted on new domains. These support portals are managed with a mix of stock responses, what appears to be AI chat bots, and likely human operators. Many of the systems require providing account IDs or account details when initiating a chat session, but not all.
We’re including a mix of examples below in Figures 2 through 6 to show both the diversity of sites and how often the same content appears under different branding. In all these examples it should be assumed that the brand being referenced, even if it’s a real casino brand with a physical presence in Macau or elsewhere, is unlikely to have any actual association with the low-quality casino websites in this network. Most major casino brands found on these sites are being impersonated and are victims, too.

Figure 2. Screenshot of a recently active site 11170011[.]com featuring “Venetian Macao” branding, translated into English. This is a classic illegal Chinese-language casino website with both casino games and “video games for money”—simple games with gambling mechanics bolted on.

Figure 3. Screenshot of a recently active site puqxr[.]com hosting a “Point 72” Chinese investment platform featuring a wide range of Chinese stocks on the homepage and various incentives for signup. This Chinese brand is likely impersonating the real “Point72 Asset Management” brand based in the U.S. We cannot confirm whether these investment sites are used for classic pig butchering schemes, which we would expect if they were in a different language.


Figure 4. Screenshot of three recently active sites from left to right: 80074[.]cc, 11168833[.]com, 11170011[.]com, hosting essentially identical content and games but have different branding, logos and colors. It’s common to find sites on these networks with minor differences like this.

Figure 5. Screenshots of four recently active unique casino sites (from left to right): 312zym001[.]cc, am125[.]cc, 843470[.]cc, 1862[.]cc. The fourth (1862[.]cc) redirects to raw IPs based on location as seen in the videos below. It’s still common to find some Chinese-language casino threat actors who spin up numerous versions of their sites. The site on the far right included a fake image of basketball superstar Steph Curry on their homepage, alluding to an endorsement. We found no evidence that Steph Curry has an association with this site; the image was very likely created and used without his authorization.

Figure 6. A closer view of the screenshot of Steph Curry embedded into the low-quality casino website associated with 1862[.]cc
When accessing the domain 1862[.]cc with the fake Steph Curry endorsement, a series of redirects fingerprinted the visitor’s IP address and device, then sent them to a unique IP address hosting an exact copy of the site.
When trying to visit 1862[.]cc while using a Hong Kong IP address, the site redirected to a final destination IP address, 157[.]185[.]143[.]150, hosting the website.
When trying to visit 1862[.]cc while using a Japanese IP address, the site redirected to a final destination IP address, 146[.]103[.]91[.]133, hosting the website.
The more than 1.7 million illegal Chinese-language casino websites we track come in many shapes and sizes but one thing remains across them—they are part of a fast-moving ecosystem out of China that relies on rapid deployment, marketing and spam campaigns we have not fully mapped, and credibility signals designed to convert visitors into depositors.
Type 2: “Scambling” Scaling Up in 2026
“Scambling,” or scam gambling, describes sites that appear to be online casinos or wagering platforms but are set up by threat actors who either purposefully rig the games or make it impossible to cash out winnings. The model resembles pig butchering. A large deposit bonus draws the victim in. Once they accumulate winnings, the operators stall: withdrawal delays, unexpected fees, and other tactics that ensure the money never arrives. Once complaints accumulate and the deposits slow, the operators fold up shop and disappear, which is part of why new scambling domains keep launching.
The term “scambling” is generally credited to Brian Krebs based on his July 2025 piece, “Scammers Unleash Flood of Slick Online Gaming Sites” and August 2025 follow-up “Affiliates Flock to ‘Soulless’ Scam Gambling Machine.”
Krebs’ July 2025 piece documented more than 1,200 polished scam gaming sites advertised across Discord and social media, all sharing a single chatbot API key. Many of these sites impersonated known internet personalities like Mr. Beast and were set up so that any cryptocurrency deposits could be played but winnings could never be withdrawn.
The August 2025 follow-up identified a major affiliate program, “Gambler Panel,” a Russian-language affiliate program that describes itself as a “soulless project that is made for profit,” offering affiliates up to 70% of profits and a minimum $10 per verification deposit.
The increase in scambling websites predates Krebs’ reporting, but the bump after publication was hard to miss—you could call it the “Krebs Effect.” In some weeks of 2026 we have seen twice as many new scambling sites as we saw in comparable weeks last year after his publication.
These scambling websites target primarily English-speaking audiences, but operators have also built sites aimed at people in Europe, South America and Asia. The 2025-2026 growth suggests further expansion.
Legitimate but low-quality gambling sites are common enough that a site’s poor quality is not itself evidence of fraud.
One common red flag is spam volume: searching the domain surfaces large numbers of unrelated sites where the domain has been injected as a blackhat SEO tactic.
We’ve also found that once a scambling site has been online long enough, there will typically be victims who complain on sites like Trustpilot[.]com, as seen here for dollycasino[.]com. The site claims to offer a 325% deposit bonus, up to €2,500. See Figure 7.

Figure 7. Screenshot of the homepage of dollycasino[.]com, which has numerous casino games, low-quality video games with gambling mechanics, and sports betting. The site has a prominent “welcome package” that claims to offer “325% up to €2,500”—essentially a deposit bonus offering free money.
As is common with scambling websites, there are dozens of complaints on Trustpilot about the difficulty of cashing out winnings from dollycasino[.]com casino, such as those in Figure 8:

Figure 8. Screenshots of some negative reviews on TrustPilot for dollycasino[.]com casino in 2025 and 2026 warning about problems cashing out money.
Some scambling websites will use multiple domains or have broken experiences like the live site found at dragobet[.]net (Figure 9.), which redirects most clicks to the domain appcasino[.]online but has numerous errors when trying to sign up. What made this site notable was its marketing: comment spam injected across numerous vulnerable websites.

Figure 9. Drago Bet Casino (dragobet[.]net) features numerous low-quality games and offers, but the functionality does not currently work.
If you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a blackhat SEO campaign spamming websites all over the internet with this domain earlier this year (Figure 10).

Figure 10. Screenshot of a Google search for this “dragobet[.]net” domain showing numerous recent results where the domain was added into a user profile or in some other spam location on a 3rd party domain.
One such spam account appears on Zillow, using an AI-generated photo under the name “Gideon Hellinga” and promoting dragobet[.]net in the profile (Figure 11).

Figure 11. Screenshot of a fake account promoting the scambling domain dragobet[.]net on Zillow. The text on the page reads, “My focus at https://dragobet[.]net/ depends on mobile user experience. I am always on the move: I like to skate through the city or play games on my handheld console. Accessibility and freedom, wherever I am, that’s what matters to me.”
When investigating the scambling websites it becomes quite clear that there are numerous unique threat actors making them, just based on all the unique website templates, hosting diversity and unique marketing and spam strategies.
There is currently a series of scambling websites using “Joker” branding that spans numerous domains. The sites feature some very unusual betting options, including digital cockfighting (no real animals appear to be involved), alongside slots, cards, arcade games, sport betting, and Keno. Figure 12 shows one such example.

Figure 12. Screenshot of the homepage for summer138[.]fit, which features the “Joker” casino branding and some text in Indonesian. The Joker-themed sites are notable for mixing English and Indonesian text, which is unusual among the scambling sites we track.
Another one of the Joker casino brands, also in both English and Indonesian, uses the Google “G” in some of their marketing materials, presumably to suggest legitimacy, as seen below in Figure 13. The operators appear to have no Google affiliation; the site simply uses Google fonts.

Figure 13. Screenshot of the storebet77[.]support Joker casino, which uses the Google logo in some of their marketing images under the text “OFFICIAL PARTNER”
Every scambling site we have reviewed offers a deposit bonus, and most now feature long lists of low-quality video games with gambling mechanics attached, such as the example in Figure 14.

Figure 14. Screenshot of the homepage for realz[.]com which offers a deposit bonus of 100%, up to €100. Games highlighted on the homepage include numerous low-quality video games with gambling tied into the experience.
Chinese-language casinos may well scam their customers in subtler ways, but the scambling websites are structured differently, and their games and offers are distinctly suspicious. As a rough heuristic: an obscure, non-Chinese-language site that cannot be tied to a real company is likely to be a scam gambling operation.
Type 3: PeckBirdy Malware C2 Domains Embedded into Chinese-language Casino and Adult Websites
China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites. Trend Micro documented a PeckBirdy campaign in a January 2026 report that provided indicators and hunting tips for finding the sites in the wild.
Greg Aaron of Interisle Consulting (interisle[.]net) flagged a Chinese-language casino domain, asg78[.]com, which at the time was loading a suspicious JavaScript payload from js.cache-mcp[.]com/layer.js.
The site registered a JS service worker, and the payload closely resembled past PeckBirdy payloads. Most web scanners won’t capture this behavior. Live PeckBirdy casino domains can be found through this URLscan query for the cache-mcp[.]com C2 domain—open them only if you understand the risks.
Figure 15 shows one of these casino websites (vip311[.]cc, from Figure 1), embedding a PeckBirdy C2 domain behind KY casino branding. The KY casino brand is a common brand impersonated on Chinese-language casinos. You can also see it captured here on URLscan.

Figure 15. Screenshot of a Chinese-language casino domain (vip311[.]cc), which embeds the PeckBirdy malware C2 domain cache-mcp[.]com. The site is purposely set up to appear like other low-quality Chinese-language casino domains so that it would be similarly ignored by defenders.
After investigating example sites that embed this cache-mcp[.]com domain, we found that live WebSocket connections use an additional domain, mcp-source[.]online. Figure 16 shows the portion of this code where the C2 can be found.

Figure 16. Screenshot of the JS response from cache-mcp[.]com, which includes a new domain mcp-source[.]online
Hunting for this new domain mcp-source[.]online showed that some Chinese-language sites can be captured making connections to this additional C2 URL directly, including Chinese-language adult websites being used the same way as the Chinese-language casino websites. We selected a comparatively mild example and redacted portions of the screenshot (Figure 17).

Figure 17. Redacted screenshot of a PeckBirdy C2 domain embedded into an adult website in Chinese-language, seemingly operating a similar ruse to the Chinese-language casino websites used by this campaign.
While investigating PeckBirdy domains, we spot-checked the domains we were seeing on VirusTotal to get a sense of how widely they were detected in the industry. One of the domains included in the January 2026 Trend Micro report had 13 detections on VirusTotal, shown in Figure 18.

Figure 18. Screenshot of the VirusTotal results for cache-cdn[.]org as of August 31, 2026
Detection coverage drops sharply as the domains get harder to discover. We looked up the domain cache-mcp[.]com, which is harder to surface through automated scanning, but had technical fingerprints connecting it to the previously found PeckBirdy C2 domains. There were only three detections for it in VirusTotal (Figure 19).

Figure 19. Screenshot of VirusTotal results for cache-mcp[.]com as of August 31, 2026
If we look up the domain that collects data via WebSocket connections on some of the PeckBirdy casino websites, a JS connection that is blocked from some automated scanners, that domain, mcp-source[.]online, has zero detections in VirusTotal—a noteworthy gap in detection for China-aligned APT groups, shown here in Figure 20.

Figure 20. Screenshot of VirusTotal results for mcp-source[.]online as of August 31, 2026
What Does a PeckBirdy Infection Look Like on the Network?
When trying to understand what PeckBirdy data looks like across our client networks, we quickly realized that their domain githubassets[.]net, which they’ve used for some time, also comes up in situations where people make typos manually or in code. The result is a long tail of scattered queries to that domain, most of which likely reflect typos rather than malware infections.
The other C2 domains are far more distinctive and rarely queried by accident, which makes them stronger indicators of a potential PeckBirdy attack.
We found just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain. When we look at the industries that are targeted, education has been a top target, which aligns to previous Trend Micro reporting about a July 2024 attack on a Philippines education institution. We have also seen IT, banking, financial services, and government as top targets, but also broad potential targeting of other industries. See Figure 21.

Figure 21. Industry breakdown of the just over 3% of Infoblox customers that attempted to reach out to a PeckBirdy C2 domain.
We’ve also found that what matters is not that they resolved one PeckBirdy C2 domain but how many they resolved, and the distribution splits cleanly into three groups, shown in Figure 22.

Figure 22. Breakdown of enterprise customers by number of distinct PeckBirdy C2 domains observed. The grey columns (one or two domains) are dominated by githubassets[.]net, a typosquat of a legitimate GitHub asset host that a code-level typo can reach out to without any compromise. Customers with three to ten domains observed, 23% of this subset, are more concerning because the pattern requires repeated contact with multiple live C2 domains. The few organizations reaching out to the full set were likely running security tooling or automation.
Resolving between three and ten distinct C2 domains is a meaningful signal that a network could be compromised. We found that if a client suspiciously hit one C2 domain, they would oftentimes hit multiple domains. This may reflect the malware’s connection behavior, or domains rotating on the sites themselves.
Breaking Down the Digital Infrastructure of the Three Casino Types
We track these three casino types by their distinct fingerprints, and we also examine the broader infrastructure and vendor choices behind them.
The analysis below moves from the CNAME infrastructure behind the Chinese-language casinos to a set of direct comparisons across all three populations: relative scale, hosting composition and how it has shifted over time, registrar concentration, and finally the relationship between where a domain is registered and where it is hosted. Two patterns emerge. The Chinese-language casino and PeckBirdy populations resemble each other in their hosting choices, while the scambling population looks entirely different—and all three depend on U.S. providers to a degree that creates real disruption opportunities.
Major U.S. hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host portions of the observed infrastructure associated with these casino operations. One likely explanation is account theft at those providers, a practice documented previously as “infrastructure laundering.” Along with those enterprise U.S. hosts, they are using a wide range of Asian hosting providers including the known bulletproof hosting ASN, CTG Server (myctgs[.]com).
Table 3 shows the top hosting operators and their ASN associated with the IP addresses mapped to the CNAME domains associated with the Chinese-language casino websites.
| ASN | Operator | Operator Headquarters | Distinct CNAME SLDs |
|---|---|---|---|
| AS16509 | Amazon.com | US | 44 |
| AS40065 | CNSERVERS LLC | HK | 44 |
| AS45102 | Alibaba (US) Technology | CN | 40 |
| AS152194 | CTG Server Limited | HK | 36 |
| AS8075 | Microsoft Corporation | US | 35 |
| AS209242 | Cloudflare London | US | 34 |
| AS13335 | Cloudflare | US | 29 |
| AS138415 | YANCY LIMITED | HK | 21 |
| AS45753 | Netsec Limited | HK | 20 |
| AS396982 | Google LLC | US | 20 |
| AS16276 | OVH SAS | FR | 19 |
| AS59371 | Dimension Network & Comm | HK | 18 |
| AS54600 | PEG TECH INC | US | 17 |
| AS63949 | Akamai Technologies | US | 17 |
| AS17561 | Larus Limited | HK | 17 |
| AS133199 | SonderCloud Limited | HK | 15 |
| AS201106 | Spartan Host Ltd | UK | 14 |
| AS46844 | Sharktech | US | 13 |
| AS134548 | DingFeng XinHui (Hong Kong) | HK | 13 |
| AS4134 | Chinanet | CN | 13 |
Table 3. Breakdown of the DNS CNAME domains associated with the Chinese-language casino websites and the operator headquarters of DNS A record / IP addresses mapped to those CNAME domains (one CNAME domain may be mapped to multiple IPs / ASNs): U.S. 209, Hong Kong 184, China 53, France 19
The three types differ enormously in the amount of infrastructure each requires.
The Chinese-language casino ecosystem is significantly larger than the scambling sites and PeckBirdy malware C2 casino sites. Chinese-language casino DNS infrastructure also oftentimes consists of complex CNAME chains and rapidly mapped IPs sourced from Asian hosting providers, Bulletproof Hosts, and U.S. and European enterprise hosting providers. Tracking the Chinese-language casino websites is generally more complex and chaotic than the other types due to this hosting diversity.

Figure 23. Domain volume by casino type since January 2021. At this scale, the scambling and PeckBirdy populations are barely visible compared to the Chinese-language casino websites.
PeckBirdy’s hosting closely resembles the Chinese-language casino pattern, while scambling is almost entirely hosted in the U.S. and European networks (Figure 24).

Figure 24. Hosting composition by infrastructure type. Bars are shares of hosting records; a domain that resolves to several networks over the observation window contributes to more than one segment.
If we drill into a different view of the top hosting providers mapped to the Chinese-language casino websites, Amazon remains the dominant U.S. host for these sites by a wide margin over Microsoft and Cloudflare, followed by a range of Hong Kong and other Asia-Pacific (APAC) providers (Figure 25).

Figure 25. Top hosting providers for the Chinese-language casino population, aggregated by ASN and colored by provider headquarters. Amazon leads by a wide margin, followed by a stack of Hong Kong bulletproof networks—Cloud Innovation/Starcloud, Antbox Networks, CTG Server, E-Large, Joint Power Technology, jiii and Cloudie—with Cloudflare and Microsoft the other major U.S. providers seen hosting a segment of the sites.
Among the scambling sites, which target mostly non-Chinese audiences, Cloudflare IPs dominate the A records, followed by other, mostly U.S. and European, hosting providers (Figure 26). These provider locations align with the locations of their intended targets and victims.

Figure 26. Top hosting providers for the scambling population, aggregated by ASN. Cloudflare dominates, followed by O.M.C. Computers & Communications (a single European reseller operating three distinct ASNs) then other European and U.S. networks.
PeckBirdy’s much smaller population—Chinese-language casino sites embedding C2 domains for China-aligned APT groups—again mirrors the Chinese-language casino mix, combining U.S. providers along with China, Hong Kong, and other Asian hosts. Essentially, if you aren’t tracking exactly which type of Chinese-language casino website you’re looking at, they could look very similar from a hosting perspective.

Figure 27. Top hosting providers for the PeckBirdy population. The counts are small, and the mix leans toward Hong Kong, mainland China and Singapore (Starcloud Global) hosts alongside Cloudflare, Microsoft, Amazon and Akamai.
If we break down those hosting choices by time, the two populations diverge: U.S. hosting of Chinese-language casinos has fallen from its 2025 peak, while scambling infrastructure continues to grow on U.S. hosts through 2026 (Figure 28).

Figure 28. Hosting mix over time. The Chinese-language casino operation ran heavily on U.S.-headquartered clouds through 2024 and into early 2025, then swung decisively back toward China, Hong Kong and other-APAC hosting by mid-2026. The U.S. cloud hosting fell from roughly two-thirds of new domains to under a fifth by 2026. Scambling shows the opposite trajectory, beginning mostly on European reseller hosting and migrating decisively onto U.S. clouds from 2024 onward. PeckBirdy’s quarter-to-quarter swings reflect very small domain counts and should not be read as trend.
Because the PeckBirdy population is so small, its hosting mix swings sharply: at some points entirely U.S. IPs, at others none. In 2026 they’ve used a mixture of IPs across the U.S., Europe, China and Hong Kong, and other APAC hosts.
U.S. registrars dominate all three populations, which creates an opportunity for disruption (Figure 29). One detail worth noting: a handful of scambling domains outside the top registrars use Chinese registrars, even though scambling hosting is almost entirely U.S. and European. It is a modest signal, but it may point to some operators being based in Asia.

Figure 29. Registration mix over time by registrar headquarters. U.S. registrars dominate most of the window across all three types, but the Chinese-language casino population shows a marked shift toward Chinese and Hong Kong registrars through 2026.
Many of the top registrars for each of the three casino types are well-known companies that could hunt this infrastructure themselves and are well positioned to respond to broad abuse complaints.
Registration timelines across the last five years show all three campaigns ramping up sharply in the last 12-18 months (Figure 30). Defenders need to take notice that even if you didn’t have a strategy for tracking online casinos previously, these certainly aren’t going anywhere, and serious China-aligned APT groups are taking advantage of the detection holes.

Figure 30. First-appearance timeline for all three populations, monthly. Each panel is scaled independently. The Chinese-language casino population grows steadily from 2023 and spikes to 138,077 new domains in June 2026; scambling ramps through 2025 into a 2026 peak; PeckBirdy stays flat until a sharp expansion in mid-2026.
We track the three casino types as separate operations, but when you look at a chart showing how many domains of each type are hosted on major networks, it becomes clearer that certain major providers could disrupt significant portions of the network. See Figure 31.

Figure 31. Hosting networks used by one of the three casino types. Much of the overlap is unsurprising shared use of mainstream cloud providers (Amazon, Microsoft, Cloudflare, Google).
We can also pair registration and hosting per domain to see whether the two choices move together. Because domains are tracked over multiple years, a single domain may appear in more than one registration or hosting region.
For 1.1 million of the Chinese-language casino domains, the U.S.-registered domains were also hosted on U.S.-company infrastructure. But about 967,000 domains were registered through U.S. registrars and hosted in China or Hong Kong.
We refer to this split as fronting: the registration sits with a provider subject to U.S. abuse processes, while the hosting sits outside that reach. A similar pattern can be seen with a portion of the PeckBirdy domains. From the scambling domains, the majority of European hosted domains were registered in the U.S., creating opportunities to disrupt most of the scambling sites through U.S. providers. See Figure 32.



Figure 32. Registration region (left) flowing to hosting region (right); a domain is counted in every hosting region it touches. Among Chinese-language casino domains, roughly 967,000 U.S.-registered domains resolve to China or Hong Kong networks—the fronting pattern at scale. Scambling shows a pronounced Europe registration-to-U.S. hosting crossover. PeckBirdy is small but skews toward Asian hosting regardless of registrar.
What Defenders Can Do
The practical takeaway from this research is that the three casino types demand different responses, none of which is “ignore it.” A Chinese-language casino domain appearing in DNS logs could be an illegal gambling operation, a node in a money laundering network, or a decoy wrapped around an APT C2 endpoint. As Figure 1 showed, nothing about the three sites is visually distinct, further complicating casual casino detection efforts.
The most important thing for defenders to do is stop ignoring casino domains. An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable—these domains genuinely are, most of the time, exactly what they appear to be. Analysts reviewing them need a way to check whether a given domain carries a C2 payload before closing the ticket, and the C2 domains in the indicator list below are a starting point.
The pattern of hiding malicious infrastructure inside seemingly legitimate web content is broader than any single campaign, and defenders who have not developed a strategy for casino domain triage are exposed to more than one threat using it.
For PeckBirdy specifically, a warning signal on a network can come from the count of distinct C2 domains being queried, not the volume of queries to any one of them. A single resolution of githubassets[.]net is consistent with a code-level typo and carries little weight on its own; the domain is a typosquat of a legitimate GitHub asset host, and the long tail of queries to it reflects that. But repeated resolution of multiple distinct C2 domains from the same network is a different matter, and organizations seeing that pattern should treat it as a potential compromise rather than noise. Just over 3% of the enterprise networks in our telemetry resolved at least one of these domains, which suggests the exposure is broader than the campaign’s small domain count implies.
Finally, the absence of detections on VirusTotal for some PeckBirdy C2s raises concerns about how this Chinese APT threat is being tracked across the industry. The domain mcp-source[.]online had zero detections across VirusTotal as of August 2026, despite being an active C2 endpoint reached over WebSocket connections that most automated scanners never observe. The two related domains had 13 and three detections, respectively. We’d welcome input from other defenders looking into PeckBirdy on how the campaign appears from their standpoint.
Indicators: Three Casinos and a Thousand Lookalikes
Below are the domains and IP addresses referenced throughout this research, grouped by casino type; they are a small sample of each population. This list is available in our GitHub repo here.
| Illegal Chinese-Language Casino Domains (Type 1) |
|---|
| 11170011[.]com |
| puqxr[.]com |
| 80074[.]cc |
| 11168833[.]com |
| 312zym001[.]cc |
| am125[.]cc |
| 843470[.]cc |
| 1862[.]cc |
| zzyud[.]com |
| zenplay77-x[.]space |
| Scambling Domains (Type 2) |
|---|
| dollycasino[.]com |
| dragobet[.]net |
| appcasino[.]online |
| summer138[.]fit |
| storebet77[.]support |
| realz[.]com |
| PeckBirdy C2 and Decoy Domains (Type 3) |
|---|
| vip311[.]cc – Decoy domain |
| cache-cdn[.]org |
| cache-mcp[.]com |
| mcp-source[.]online |
| asg78[.]com – Decoy domain |
| githubassets[.]net |
| Supporting IP Addresses for Illegal Chinese-Language Casino Domains (Type 1) |
|---|
| 157[.]185[.]143[.]150 |
| 146[.]103[.]91[.]133 |


