{"id":14140,"date":"2026-09-15T08:00:19","date_gmt":"2026-09-15T15:00:19","guid":{"rendered":"https:\/\/www.infoblox.com\/blog\/?p=14140"},"modified":"2026-09-15T08:23:49","modified_gmt":"2026-09-15T15:23:49","slug":"how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/","title":{"rendered":"How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage"},"content":{"rendered":"<h3>Why Should Anyone Care About Casino Websites?<\/h3>\n<p>Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Over the last decade there\u2019s been massive growth in both gambling websites catering to Chinese audiences and similar casino sites targeting people all over the world. There\u2019s also been growth in legal gambling and casino websites, but the scale of these compared to the malicious casinos is marginal.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-hero-image.jpg\"><\/p>\n<p>This report focuses on the crime disguised by the proliferation of betting sites that litter the internet. There are three major purposes hiding behind most illicit online casino sites: facilitating illegal gambling across China and Asia, and laundering money; stealing money from customers or preventing them from cashing out (\u201cscambling\u201d); and operating command-and-control (C2) infrastructure under the cover of a casino website. That last category is used by little-known China-aligned advanced persistent threat (APT) actors operating since 2023 using a C2 framework known as PeckBirdy to attack corporate and government targets across Asia.<\/p>\n<p>PeckBirdy is not the only actor using this approach. Sable Squirrel, documented in <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret\/\"><strong>recent Infoblox research<\/strong><\/a>, uses the same technique at larger scale: controlling more than 10,000 domains and spending an estimated $7 million on expired domains to build a streaming and gambling empire that also functions as malware C2 infrastructure.<\/p>\n<p>Our new casino research shows an expansion of the industries being targeted with these ongoing PeckBirdy APT campaigns, which are now also using low-quality Chinese-language adult websites as part of the ruse. We also documented a C2 domain being used by the PeckBirdy framework that had zero detections on VirusTotal at the time of this publication.<\/p>\n<p>The hardest part of sorting these sites into the three categories is that they look nearly identical in a browser. From the three websites shown in Figure 1, can you guess which one is used in a PeckBirdy campaign?<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image1.jpg\"><\/p>\n<p class=\"image-caption\">Figure 1. Screenshots of three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy<\/p>\n<p>The answer is vip311[.]cc\u2014the site on the left, a PeckBirdy C2 domain used by China-aligned APT groups.<\/p>\n<h3>Sorting the Lookalikes<\/h3>\n<p>We track three distinct types of these malicious casino websites. They look similar in a browser, but behave nothing alike underneath, as Table 1 shows.<\/p>\n<table>\n<thead>\n<tr>\n<th><\/th>\n<th>Type 1<\/th>\n<th>Type 2<\/th>\n<th>Type 3<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Description<\/strong><\/td>\n<td>Illegal Chinese-language casino websites<\/td>\n<td>Scambling (scam gambling) websites<\/td>\n<td>PeckBirdy Chinese-language casino decoy sites<\/td>\n<\/tr>\n<tr>\n<td><strong>Scale<\/strong><\/td>\n<td>Over 1.7 million domains<\/td>\n<td>Thousands of domains<\/td>\n<td>Dozens of domains<\/td>\n<\/tr>\n<tr>\n<td><strong>Audience (users &amp; victims)<\/strong><\/td>\n<td>Mostly mainland Chinese players and money-laundering groups, occasionally other languages<\/td>\n<td>Global, mostly non-Chinese-language<\/td>\n<td>No real users (decoy)<\/td>\n<\/tr>\n<tr>\n<td><strong>Real gambling<\/strong><\/td>\n<td>Largely yes<\/td>\n<td>No, it\u2019s rigged\/can\u2019t cash out<\/td>\n<td>No, it\u2019s set dressing<\/td>\n<\/tr>\n<tr>\n<td><strong>Purpose<\/strong><\/td>\n<td>Illegal gambling and money laundering<\/td>\n<td>Consumer fraud<\/td>\n<td>Espionage, intrusion, malware C2<\/td>\n<\/tr>\n<tr>\n<td><strong>Operators<\/strong><\/td>\n<td>Triad-aligned syndicates, casino junket-adjacent groups<\/td>\n<td>Numerous threat actors<\/td>\n<td>China-aligned APT actors<\/td>\n<\/tr>\n<tr>\n<td><strong>Customer support<\/strong><\/td>\n<td>Real and responsive; operators protect their reputation to keep players depositing<\/td>\n<td>Oftentimes real, scripted responses to tough questions, stalls withdrawals<\/td>\n<td>None: no real users<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"image-caption\">Table 1. The three types of malicious casino websites tracked by Infoblox Threat Intel<\/p>\n<h3>Type 1: Illegal Chinese-Language Casinos<\/h3>\n<p>The most prevalent type of online casino infrastructure\u2014the Chinese-language casino websites facilitating illegal gambling\u2014is now a load-bearing component of transnational organized money laundering. It supports the movement of money out of China and other Asian jurisdictions to avoid taxes and oversight, and North Korea uses it to launder proceeds from its online criminal operations. These Chinese-language online casinos are one leg of the Asian underground banking economy operating across over 1.7 million domains. But as we explain throughout this research, these websites are being registered and hosted with U.S. and European companies, many for long periods of time.<\/p>\n<p>Infoblox Threat Intel has been tracking gambling operations intensively since uncovering <a href=\"https:\/\/insights.infoblox.com\/resources-report\/infoblox-report-vigorish-viper-a-venomous-bet\" target=\"_blank\"><strong>Vigorish Viper<\/strong><\/a> and their sponsorships of European football teams in early 2024. In July 2026, the United Nations Office on Drugs and Crime (UNODC) published a new regional threat assessment for Southeast Asia titled \u201c<a href=\"https:\/\/www.unodc.org\/unodc\/en\/press\/releases\/2026\/July\/new-unodc-report-reveals-scale-of-south-east-asias-ever-more-interconnected-criminal-economy.html\" target=\"_blank\"><strong>An Interconnected Criminal Ecosystem: Transnational Organized Crime Threat Assessment for Southeast Asia 2026.<\/strong><\/a>\u201d UNODC concluded that illegal online gambling is no longer a standalone problem for gambling regulators. Its convergence with cyber-enabled fraud, underground banking and human trafficking has made it a primary revenue source and operational enabler for organized crime across the region.<\/p>\n<p>UNODC estimated global illegal betting revenue up to $1.7 trillion annually, much of it serviced by criminal infrastructure based in Southeast Asia. Separately, they estimated losses from transnational online scam operations across East Asia, Southeast Asia, Australia, and New Zealand at <strong>$88.3 billion to $114.1 billion for 2025 alone<\/strong>, roughly three times the $18\u201337 billion estimated for 2023. UNODC described the underlying shift as syndicates moving from territorially rooted, single-specialty crime toward an integrated, service-based criminal economy, with laundering, trafficking, smuggling and data harvesting operating as specialized departments plugged into one broader criminal ecosystem.<\/p>\n<p>In its case study on the <a href=\"https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/vault-viper\/\"><strong>Vault Viper<\/strong><\/a> network, UNODC found that vast numbers of seemingly independent Chinese-language gambling brands ultimately rely on a small number of backend platform providers, DNS infrastructure clusters, and payment processing systems. The footnote on that passage cites our original 2025 research, &#8220;<a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vault-viper-high-stakes-hidden-threats\/\"><strong>Vault Viper: High Stakes, Hidden Threats.<\/strong><\/a>\u201d<\/p>\n<p>UNODC was explicitly pessimistic about blocking these underground casino threats one domain at a time. They described domain redirection as a standard operational practice for these groups: they maintain thousands of active domains and rotate to a new one whenever the current one is blocked. The report concludes that this makes domain blocking largely ineffective as a standalone measure. The UNODC report also highlighted that the Philippines ordered more than 7,000 illegal gambling websites blocked in 2024, which had limited effect and was described as \u201cpractical futility.\u201d<\/p>\n<p>At Infoblox we track Chinese-language casino domains based on specific actor groups but even across these segments we see what appears to be shared best practices, infrastructure and code.<\/p>\n<p>We track sixteen clusters of very different sizes, and a small number of them are behind the vast majority of these Chinese-language casino websites. The two largest clusters are the FUNNULL and Vigorish Viper networks\u2014associated with the bulletproof CDN infrastructure that these casinos launder their hosting through\u2014holding roughly 745,148 and 666,157 domains respectively, together about 81% of the population. A third actor holds another 265,469 domains, and a fourth holds 56,446 domains, bringing the top four to roughly 99.5% of every Chinese-language casino domain we track. The remaining actors, several now dormant, add up to only a few thousand domains between them. Most were tracked because of some unique behavior or infrastructure decision, which may in fact have been an A\/B test by one of the larger groups. See Table 2.<\/p>\n<table>\n<thead>\n<tr>\n<th>Actor (report label)<\/th>\n<th>Domains<\/th>\n<th>Status<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>FUNNULL CDN*<\/td>\n<td>745,148<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Vigorish Viper<\/td>\n<td>666,157<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #3<\/td>\n<td>265,469<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #4<\/td>\n<td>56,446<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #5<\/td>\n<td>2,632<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #6<\/td>\n<td>1,858<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #7<\/td>\n<td>1,072<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #8<\/td>\n<td>816<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #9<\/td>\n<td>814<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #10<\/td>\n<td>667<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #11<\/td>\n<td>491<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #12<\/td>\n<td>283<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #13<\/td>\n<td>179<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #14<\/td>\n<td>171<\/td>\n<td>dormant<\/td>\n<\/tr>\n<tr>\n<td>Actor #15<\/td>\n<td>83<\/td>\n<td>active<\/td>\n<\/tr>\n<tr>\n<td>Actor #16<\/td>\n<td>72<\/td>\n<td>dormant<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"image-caption\">Table 2. The sixteen Chinese-language casino actors by domain count and current activity status. *FUNNULL CDN also hosts a small number of investment scam websites targeting the U.S. but the vast majority of their websites are Chinese-language casinos used for illegal gambling and money laundering.<\/p>\n<p>Throughout this report we\u2019ll talk broadly about this Chinese-language casino ecosystem, knowing that the vast majority of the sites are set up by two actors who make similar hosting decisions, and that our broader group of actors are also closely aligned.<\/p>\n<p>Gambling has been illegal for people in mainland China for decades. <a href=\"https:\/\/asgam.com\/2020\/12\/30\/cross-border-casinos-junkets-in-firing-line-as-china-passes-amendment-to-criminal-law\/\" target=\"_blank\"><strong>A March 2021 criminal law amendment<\/strong><\/a>, covered by some Asian gambling outlets, extended that prohibition: It\u2019s now also illegal to operate an overseas gambling establishment or to organize and solicit Chinese residents to use one. The amendment likely enabled the prosecution of SunCity Gaming executives in late 2021, including <a href=\"https:\/\/www.bbc.com\/news\/world-asia-china-64314043\" target=\"_blank\"><strong>CEO Alvin Chau, who was sentenced to 18 years in a Chinese jail<\/strong><\/a> for facilitating over $100 billion in illegal bets.<\/p>\n<p>That prohibition and even the prosecution of an executive running one of these networks did not remove demand or the willingness to serve the massive Chinese gambling audience. It did, however, move the entire Chinese gambling market into an even more underground economy served by murky Chinese operators whose money flows into better-known gambling brands that launder their reputation by sponsoring European football clubs. This laundering practice has been covered in previous Infoblox reports and extensively by \u201cPlayTheGame\u201d in their 2024 piece \u201c<a href=\"https:\/\/www.playthegame.org\/news\/meet-the-hydras-tracing-the-illegal-gambling-operators-that-sponsor-football\/\" target=\"_blank\"><strong>Meet the hydras: tracing the illegal gambling operators that sponsor football.<\/strong><\/a>\u201d<\/p>\n<p>The Chinese-language casino websites differ from the other two types in one important respect: they run real customer support. Their contact channels work. They process withdrawals. Many of the games probably run normal house odds, because the house edge already wins over time and because the operator&#8217;s real business depends on player trust. A player who cannot cash out stops depositing, and deposits are the pipeline the broader money laundering runs through.<\/p>\n<p>For most defenders, this is the counterintuitive part. They are working casino websites that happen to be illegal, run by operators who need them to keep working, because the deposits are what the laundering depends on.<\/p>\n<h3>Recent Examples of Illegal Chinese-Language Casinos<\/h3>\n<p>Across the more than 1.7 million illegal Chinese-language casino sites we track, many are online for days or weeks.<\/p>\n<p>Some serve content directly, while others redirect visitors to unexpected hosts based on device details (IP address or perceived location, device type, and language). All the hosts are likely meant to be temporary because many of them are trying to facilitate illegal gambling in mainland China and face blocks and other dynamic restrictions from the Great Firewall of China.<\/p>\n<p>We track this complex ecosystem of gambling through several different methods.<\/p>\n<p>Some actors constantly spin up new sites with unique templates, visual layouts, and offers. We see a mix of classic casino games, slots, video games for money, sports gambling, stock investing, and some of them also mix in explicit adult offers. Other actors run near-identical websites with only cosmetic changes: switching out brands, graphics, and colors, but using identical offers and underlying language from site to site. On essentially every one of these sites you will find links to customer support portals, oftentimes hosted on new domains. These support portals are managed with a mix of stock responses, what appears to be AI chat bots, and likely human operators. Many of the systems require providing account IDs or account details when initiating a chat session, but not all.<\/p>\n<p>We\u2019re including a mix of examples below in Figures 2 through 6 to show both the diversity of sites and how often the same content appears under different branding. In all these examples it should be assumed that the brand being referenced, even if it\u2019s a real casino brand with a physical presence in Macau or elsewhere, is unlikely to have any actual association with the low-quality casino websites in this network. Most major casino brands found on these sites are being impersonated and are victims, too.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image2.jpg\"><\/p>\n<p class=\"image-caption\">Figure 2. Screenshot of a recently active site 11170011[.]com featuring \u201cVenetian Macao\u201d branding, translated into English. This is a classic illegal Chinese-language casino website with both casino games and \u201cvideo games for money\u201d\u2014simple games with gambling mechanics bolted on.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image3.jpg\"><\/p>\n<p class=\"image-caption\">Figure 3. Screenshot of a recently active site puqxr[.]com hosting a \u201cPoint 72\u201d Chinese investment platform featuring a wide range of Chinese stocks on the homepage and various incentives for signup. This Chinese brand is likely impersonating the real \u201cPoint72 Asset Management\u201d brand based in the U.S. We cannot confirm whether these investment sites are used for classic pig butchering schemes, which we would expect if they were in a different language.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image4a.jpg\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image4b.jpg\"><\/p>\n<p class=\"image-caption\">Figure 4. Screenshot of three recently active sites from left to right: 80074[.]cc, 11168833[.]com, 11170011[.]com, hosting essentially identical content and games but have different branding, logos and colors. It\u2019s common to find sites on these networks with minor differences like this.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image5.jpg\"><\/p>\n<p class=\"image-caption\">Figure 5. Screenshots of four recently active unique casino sites (from left to right): 312zym001[.]cc, am125[.]cc, 843470[.]cc, 1862[.]cc. The fourth (1862[.]cc) redirects to raw IPs based on location as seen in the videos below. It\u2019s still common to find some Chinese-language casino threat actors who spin up numerous versions of their sites. The site on the far right included a fake image of basketball superstar Steph Curry on their homepage, alluding to an endorsement. We found no evidence that Steph Curry has an association with this site; the image was very likely created and used without his authorization.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image6.jpg\"><\/p>\n<p class=\"image-caption\">Figure 6. A closer view of the screenshot of Steph Curry embedded into the low-quality casino website associated with 1862[.]cc<\/p>\n<p>When accessing the domain 1862[.]cc with the fake Steph Curry endorsement, a series of redirects fingerprinted the visitor\u2019s IP address and device, then sent them to a unique IP address hosting an exact copy of the site.<\/p>\n<p>When trying to visit 1862[.]cc while using a Hong Kong IP address, the site redirected to a final destination IP address, 157[.]185[.]143[.]150, hosting the website.<\/p>\n<div class=\"youtube-responsive\">\n<iframe loading=\"lazy\" class=\"vidyard_iframe\" title=\"Mandarin Casino Threat Actor Redirection Using Hong Kong IP Address\" src=\"\/\/play.vidyard.com\/8yhCrMR6nUv9sXQdBTjTF5.html?\" width=\"640\" height=\"360\" scrolling=\"no\" frameborder=\"0\" allowtransparency=\"true\" allowfullscreen referrerpolicy=\"no-referrer-when-downgrade\"><\/iframe>\n<\/div>\n<p>When trying to visit 1862[.]cc while using a Japanese IP address, the site redirected to a final destination IP address, 146[.]103[.]91[.]133, hosting the website.<\/p>\n<div class=\"youtube-responsive\">\n<iframe loading=\"lazy\" class=\"vidyard_iframe\" title=\"Mandarin Casino Threat Actor Redirection Using Japanese IP Address\" src=\"\/\/play.vidyard.com\/7bfXqSD5HFPjQpKfANq6ze.html?\" width=\"640\" height=\"360\" scrolling=\"no\" frameborder=\"0\" allowtransparency=\"true\" allowfullscreen referrerpolicy=\"no-referrer-when-downgrade\"><\/iframe>\n<\/div>\n<p>The more than 1.7 million illegal Chinese-language casino websites we track come in many shapes and sizes but one thing remains across them\u2014they are part of a fast-moving ecosystem out of China that relies on rapid deployment, marketing and spam campaigns we have not fully mapped, and credibility signals designed to convert visitors into depositors.<\/p>\n<h3>Type 2: \u201cScambling\u201d Scaling Up in 2026<\/h3>\n<p>\u201cScambling,\u201d or scam gambling, describes sites that appear to be online casinos or wagering platforms but are set up by threat actors who either purposefully rig the games or make it impossible to cash out winnings. The model resembles pig butchering. A large deposit bonus draws the victim in. Once they accumulate winnings, the operators stall: withdrawal delays, unexpected fees, and other tactics that ensure the money never arrives. Once complaints accumulate and the deposits slow, the operators fold up shop and disappear, which is part of why new scambling domains keep launching.<\/p>\n<p>The term \u201cscambling\u201d is generally credited to Brian Krebs based on his July 2025 piece, \u201c<a href=\"https:\/\/krebsonsecurity.com\/2025\/07\/scammers-unleash-flood-of-slick-online-gaming-sites\/\" target=\"_blank\"><strong>Scammers Unleash Flood of Slick Online Gaming Sites<\/strong><\/a>\u201d and August 2025 follow-up \u201c<a href=\"https:\/\/krebsonsecurity.com\/2025\/08\/affiliates-flock-to-soulless-scam-gambling-machine\/\" target=\"_blank\"><strong>Affiliates Flock to \u2018Soulless\u2019 Scam Gambling Machine.<\/strong><\/a>\u201d<\/p>\n<p>Krebs\u2019 July 2025 piece documented more than 1,200 polished scam gaming sites advertised across Discord and social media, all sharing a single chatbot API key. Many of these sites impersonated known internet personalities like Mr. Beast and were set up so that any cryptocurrency deposits could be played but winnings could never be withdrawn.<\/p>\n<p>The August 2025 follow-up identified a major affiliate program, \u201c<strong>Gambler Panel<\/strong>,\u201d a Russian-language affiliate program that describes itself as a \u201csoulless project that is made for profit,\u201d offering affiliates up to 70% of profits and a minimum $10 per verification deposit.<\/p>\n<p>The increase in scambling websites predates Krebs\u2019 reporting, but the bump after publication was hard to miss\u2014you could call it the \u201cKrebs Effect.\u201d In some weeks of 2026 we have seen twice as many new scambling sites as we saw in comparable weeks last year after his publication.<\/p>\n<p>These scambling websites target primarily English-speaking audiences, but operators have also built sites aimed at people in Europe, South America and Asia. The 2025-2026 growth suggests further expansion.<\/p>\n<p>Legitimate but low-quality gambling sites are common enough that a site\u2019s poor quality is not itself evidence of fraud.<\/p>\n<p>One common red flag is spam volume: searching the domain surfaces large numbers of unrelated sites where the domain has been injected as a blackhat SEO tactic.<\/p>\n<p>We\u2019ve also found that once a scambling site has been online long enough, there will typically be victims who complain on sites like Trustpilot[.]com, <a href=\"https:\/\/www.trustpilot.com\/review\/dollycasino.com?stars=1\" target=\"_blank\"><strong>as seen here<\/strong><\/a> for dollycasino[.]com. The site claims to offer a 325% deposit bonus, up to \u20ac2,500. See Figure 7.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image7.jpg\"><\/p>\n<p class=\"image-caption\">Figure 7. Screenshot of the homepage of dollycasino[.]com, which has numerous casino games, low-quality video games with gambling mechanics, and sports betting. The site has a prominent \u201cwelcome package\u201d that claims to offer \u201c325% up to \u20ac2,500\u201d\u2014essentially a deposit bonus offering free money.<\/p>\n<p>As is common with scambling websites, there are dozens of complaints on Trustpilot about the difficulty of cashing out winnings from dollycasino[.]com casino, such as those in Figure 8:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image8.jpg\"><\/p>\n<p class=\"image-caption\">Figure 8. Screenshots of some negative reviews on <a href=\"https:\/\/www.trustpilot.com\/review\/dollycasino.com?stars=1\" target=\"_blank\"><strong>TrustPilot<\/strong><\/a> for dollycasino[.]com casino in 2025 and 2026 warning about problems cashing out money.<\/p>\n<p>Some scambling websites will use multiple domains or have broken experiences like the live site found at dragobet[.]net (Figure 9.), which redirects most clicks to the domain appcasino[.]online but has numerous errors when trying to sign up. What made this site notable was its marketing: comment spam injected across numerous vulnerable websites.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image9.jpg\"><\/p>\n<p class=\"image-caption\">Figure 9. Drago Bet Casino (dragobet[.]net) features numerous low-quality games and offers, but the functionality does not currently work.<\/p>\n<p>If you search this domain \u201cdragobet[.]net\u201d on Google it quickly becomes clear that someone ran a blackhat SEO campaign spamming websites all over the internet with this domain earlier this year (Figure 10).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image10.jpg\"><\/p>\n<p class=\"image-caption\">Figure 10. Screenshot of a <a href=\"https:\/\/www.google.com\/search?q=%22dragobet%5B.%5Dnet%22\" target=\"_blank\"><strong>Google search<\/strong><\/a> for this \u201cdragobet[.]net\u201d domain showing numerous recent results where the domain was added into a user profile or in some other spam location on a 3rd party domain.<\/p>\n<p>One such spam account appears <a href=\"https:\/\/www.zillow.com\/profile\/yijitos908\" target=\"_blank\"><strong>on Zillow<\/strong><\/a>, using an AI-generated photo under the name \u201cGideon Hellinga\u201d and promoting dragobet[.]net in the profile (Figure 11).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image11.jpg\"><\/p>\n<p class=\"image-caption\">Figure 11. Screenshot of a fake account promoting the scambling domain dragobet[.]net <a href=\"https:\/\/www.zillow.com\/profile\/yijitos908\" target=\"_blank\"><strong>on Zillow<\/strong><\/a>. The text on the page reads, \u201cMy focus at https:\/\/dragobet[.]net\/ depends on mobile user experience. I am always on the move: I like to skate through the city or play games on my handheld console. Accessibility and freedom, wherever I am, that&#8217;s what matters to me.\u201d<\/p>\n<p>When investigating the scambling websites it becomes quite clear that there are numerous unique threat actors making them, just based on all the unique website templates, hosting diversity and unique marketing and spam strategies.<\/p>\n<p>There is currently a series of scambling websites using \u201cJoker\u201d branding that spans numerous domains. The sites feature some very unusual betting options, including digital cockfighting (no real animals appear to be involved), alongside slots, cards, arcade games, sport betting, and Keno. Figure 12 shows one such example.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image12.jpg\"><\/p>\n<p class=\"image-caption\">Figure 12. Screenshot of the homepage for summer138[.]fit, which features the \u201cJoker\u201d casino branding and some text in Indonesian. The Joker-themed sites are notable for mixing English and Indonesian text, which is unusual among the scambling sites we track.<\/p>\n<p>Another one of the Joker casino brands, also in both English and Indonesian, uses the Google \u201cG\u201d in some of their marketing materials, presumably to suggest legitimacy, as seen below in Figure 13. The operators appear to have no Google affiliation; the site simply uses Google fonts.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image13.jpg\"><\/p>\n<p class=\"image-caption\">Figure 13. Screenshot of the storebet77[.]support Joker casino, which uses the Google logo in some of their marketing images under the text \u201cOFFICIAL PARTNER\u201d<\/p>\n<p>Every scambling site we have reviewed offers a deposit bonus, and most now feature long lists of low-quality video games with gambling mechanics attached, such as the example in Figure 14.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image14.jpg\"><\/p>\n<p class=\"image-caption\">Figure 14. Screenshot of the homepage for realz[.]com which offers a deposit bonus of 100%, up to \u20ac100. Games highlighted on the homepage include numerous low-quality video games with gambling tied into the experience.<\/p>\n<p>Chinese-language casinos may well scam their customers in subtler ways, but the scambling websites are structured differently, and their games and offers are distinctly suspicious. As a rough heuristic: an obscure, non-Chinese-language site that cannot be tied to a real company is likely to be a scam gambling operation.<\/p>\n<h3>Type 3: PeckBirdy Malware C2 Domains Embedded into Chinese-language Casino and Adult Websites<\/h3>\n<p>China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites. Trend Micro documented a PeckBirdy campaign in a <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/a\/peckbirdy-script-framework.html\" target=\"_blank\"><strong>January 2026 report that<\/strong><\/a> provided indicators and hunting tips for finding the sites in the wild.<\/p>\n<p>Greg Aaron of Interisle Consulting (interisle[.]net) flagged a Chinese-language casino domain, asg78[.]com, which at the time was loading a suspicious JavaScript payload from js.cache-mcp[.]com\/layer.js.<\/p>\n<p>The site registered a JS service worker, and the payload closely resembled past PeckBirdy payloads. Most web scanners won\u2019t capture this behavior. Live PeckBirdy casino domains can be found through <a href=\"https:\/\/urlscan.io\/search\/#domain%3Acache-mcp.com\" target=\"_blank\"><strong>this URLscan query<\/strong><\/a> for the cache-mcp[.]com C2 domain\u2014open them only if you understand the risks.<\/p>\n<p>Figure 15 shows one of these casino websites (vip311[.]cc, from Figure 1), embedding a PeckBirdy C2 domain behind KY casino branding. The KY casino brand is a common brand impersonated on Chinese-language casinos. You can also see it <a href=\"https:\/\/urlscan.io\/result\/019ffd05-446c-741a-a56c-3f9795eb88fe\" target=\"_blank\"><strong>captured here on URLscan<\/strong><\/a>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image15.jpg\"><\/p>\n<p class=\"image-caption\">Figure 15. Screenshot of a Chinese-language casino domain (vip311[.]cc), which embeds the PeckBirdy malware C2 domain cache-mcp[.]com. The site is purposely set up to appear like other low-quality Chinese-language casino domains so that it would be similarly ignored by defenders.<\/p>\n<p>After investigating example sites that embed this <strong>cache-mcp[.]com<\/strong> domain, we found that live WebSocket connections use an additional domain, <strong>mcp-source[.]online<\/strong>. Figure 16 shows the portion of this code where the C2 can be found.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image16.jpg\"><\/p>\n<p class=\"image-caption\">Figure 16. Screenshot of the JS response from cache-mcp[.]com, which includes a new domain mcp-source[.]online<\/p>\n<p>Hunting for this new domain mcp-source[.]online showed that some Chinese-language sites can be captured making connections to this additional C2 URL directly, including Chinese-language adult websites being used the same way as the Chinese-language casino websites. We selected a comparatively mild <a href=\"https:\/\/urlscan.io\/result\/01a00130-6923-71ab-b2c8-2e86a4052551\" target=\"_blank\"><strong>example<\/strong><\/a> and redacted portions of the screenshot (Figure 17).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image17.jpg\"><\/p>\n<p class=\"image-caption\">Figure 17. Redacted screenshot of a PeckBirdy C2 domain embedded into an adult website in Chinese-language, seemingly operating a similar ruse to the Chinese-language casino websites used by this campaign.<\/p>\n<p>While investigating PeckBirdy domains, we spot-checked the domains we were seeing on VirusTotal to get a sense of how widely they were detected in the industry. One of the domains included in the January 2026 Trend Micro report had 13 detections on VirusTotal, shown in Figure 18.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image18.jpg\"><\/p>\n<p class=\"image-caption\">Figure 18. Screenshot of the <a href=\"https:\/\/www.virustotal.com\/gui\/domain\/cache-cdn.org\" target=\"_blank\"><strong>VirusTotal results for cache-cdn[.]org<\/strong><\/a> as of August 31, 2026<\/p>\n<p>Detection coverage drops sharply as the domains get harder to discover. We looked up the domain cache-mcp[.]com, which is harder to surface through automated scanning, but had technical fingerprints connecting it to the previously found PeckBirdy C2 domains. There were only three detections for it in VirusTotal (Figure 19).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image19.jpg\"><\/p>\n<p class=\"image-caption\">Figure 19. Screenshot of <a href=\"https:\/\/www.virustotal.com\/gui\/domain\/cache-mcp.com\" target=\"_blank\"><strong>VirusTotal results for cache-mcp[.]com<\/strong><\/a> as of August 31, 2026<\/p>\n<p>If we look up the domain that collects data via WebSocket connections on some of the PeckBirdy casino websites, a JS connection that is blocked from some automated scanners, that domain, mcp-source[.]online, has zero detections in VirusTotal\u2014a noteworthy gap in detection for China-aligned APT groups, shown here in Figure 20.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image20.jpg\"><\/p>\n<p class=\"image-caption\">Figure 20. Screenshot of <a href=\"https:\/\/www.virustotal.com\/gui\/domain\/mcp-source.online\" target=\"_blank\"><strong>VirusTotal results for mcp-source[.]online<\/strong><\/a> as of August 31, 2026<\/p>\n<h3>What Does a PeckBirdy Infection Look Like on the Network?<\/h3>\n<p>When trying to understand what PeckBirdy data looks like across our client networks, we quickly realized that their domain githubassets[.]net, which they&#8217;ve used for some time, also comes up in situations where people make typos manually or in code. The result is a long tail of scattered queries to that domain, most of which likely reflect typos rather than malware infections.<\/p>\n<p>The other C2 domains are far more distinctive and rarely queried by accident, which makes them stronger indicators of a potential PeckBirdy attack.<\/p>\n<p>We found just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain. When we look at the industries that are targeted, education has been a top target, which aligns to previous Trend Micro reporting about a July 2024 attack on a Philippines education institution. We have also seen IT, banking, financial services, and government as top targets, but also broad potential targeting of other industries. See Figure 21.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image21.jpg\"><\/p>\n<p class=\"image-caption\">Figure 21. Industry breakdown of the just over 3% of Infoblox customers that attempted to reach out to a PeckBirdy C2 domain.<\/p>\n<p>We\u2019ve also found that what matters is not that they resolved one PeckBirdy C2 domain but how many they resolved, and the distribution splits cleanly into three groups, shown in Figure 22.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image22.jpg\"><\/p>\n<p class=\"image-caption\">Figure 22. Breakdown of enterprise customers by number of distinct PeckBirdy C2 domains observed. The grey columns (one or two domains) are dominated by githubassets[.]net, a typosquat of a legitimate GitHub asset host that a code-level typo can reach out to without any compromise. Customers with three to ten domains observed, 23% of this subset, are more concerning because the pattern requires repeated contact with multiple live C2 domains. The few organizations reaching out to the full set were likely running security tooling or automation.<\/p>\n<p>Resolving between three and ten distinct C2 domains is a meaningful signal that a network could be compromised. We found that if a client suspiciously hit one C2 domain, they would oftentimes hit multiple domains. This may reflect the malware\u2019s connection behavior, or domains rotating on the sites themselves.<\/p>\n<h3>Breaking Down the Digital Infrastructure of the Three Casino Types<\/h3>\n<p>We track these three casino types by their distinct fingerprints, and we also examine the broader infrastructure and vendor choices behind them.<\/p>\n<p>The analysis below moves from the CNAME infrastructure behind the Chinese-language casinos to a set of direct comparisons across all three populations: relative scale, hosting composition and how it has shifted over time, registrar concentration, and finally the relationship between where a domain is registered and where it is hosted. Two patterns emerge. The Chinese-language casino and PeckBirdy populations resemble each other in their hosting choices, while the scambling population looks entirely different\u2014and all three depend on U.S. providers to a degree that creates real disruption opportunities.<\/p>\n<p>Major U.S. hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host portions of the observed infrastructure associated with these casino operations. One likely explanation is account theft at those providers, a practice documented previously as \u201c<a href=\"https:\/\/www.silentpush.com\/blog\/infrastructure-laundering\/\" target=\"_blank\"><strong>infrastructure laundering.<\/strong><\/a>\u201d Along with those enterprise U.S. hosts, they are using a wide range of Asian hosting providers including the known bulletproof hosting ASN, CTG Server (myctgs[.]com).<\/p>\n<p>Table 3 shows the top hosting operators and their ASN associated with the IP addresses mapped to the CNAME domains associated with the Chinese-language casino websites.<\/p>\n<table>\n<thead>\n<tr>\n<th>ASN<\/th>\n<th>Operator<\/th>\n<th>Operator Headquarters<\/th>\n<th>Distinct CNAME SLDs<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>AS16509<\/td>\n<td>Amazon.com<\/td>\n<td>US<\/td>\n<td>44<\/td>\n<\/tr>\n<tr>\n<td>AS40065<\/td>\n<td>CNSERVERS LLC<\/td>\n<td>HK<\/td>\n<td>44<\/td>\n<\/tr>\n<tr>\n<td>AS45102<\/td>\n<td>Alibaba (US) Technology<\/td>\n<td>CN<\/td>\n<td>40<\/td>\n<\/tr>\n<tr>\n<td>AS152194<\/td>\n<td>CTG Server Limited<\/td>\n<td>HK<\/td>\n<td>36<\/td>\n<\/tr>\n<tr>\n<td>AS8075<\/td>\n<td>Microsoft Corporation<\/td>\n<td>US<\/td>\n<td>35<\/td>\n<\/tr>\n<tr>\n<td>AS209242<\/td>\n<td>Cloudflare London<\/td>\n<td>US<\/td>\n<td>34<\/td>\n<\/tr>\n<tr>\n<td>AS13335<\/td>\n<td>Cloudflare<\/td>\n<td>US<\/td>\n<td>29<\/td>\n<\/tr>\n<tr>\n<td>AS138415<\/td>\n<td>YANCY LIMITED<\/td>\n<td>HK<\/td>\n<td>21<\/td>\n<\/tr>\n<tr>\n<td>AS45753<\/td>\n<td>Netsec Limited<\/td>\n<td>HK<\/td>\n<td>20<\/td>\n<\/tr>\n<tr>\n<td>AS396982<\/td>\n<td>Google LLC<\/td>\n<td>US<\/td>\n<td>20<\/td>\n<\/tr>\n<tr>\n<td>AS16276<\/td>\n<td>OVH SAS<\/td>\n<td>FR<\/td>\n<td>19<\/td>\n<\/tr>\n<tr>\n<td>AS59371<\/td>\n<td>Dimension Network &amp; Comm<\/td>\n<td>HK<\/td>\n<td>18<\/td>\n<\/tr>\n<tr>\n<td>AS54600<\/td>\n<td>PEG TECH INC<\/td>\n<td>US<\/td>\n<td>17<\/td>\n<\/tr>\n<tr>\n<td>AS63949<\/td>\n<td>Akamai Technologies<\/td>\n<td>US<\/td>\n<td>17<\/td>\n<\/tr>\n<tr>\n<td>AS17561<\/td>\n<td>Larus Limited<\/td>\n<td>HK<\/td>\n<td>17<\/td>\n<\/tr>\n<tr>\n<td>AS133199<\/td>\n<td>SonderCloud Limited<\/td>\n<td>HK<\/td>\n<td>15<\/td>\n<\/tr>\n<tr>\n<td>AS201106<\/td>\n<td>Spartan Host Ltd<\/td>\n<td>UK<\/td>\n<td>14<\/td>\n<\/tr>\n<tr>\n<td>AS46844<\/td>\n<td>Sharktech<\/td>\n<td>US<\/td>\n<td>13<\/td>\n<\/tr>\n<tr>\n<td>AS134548<\/td>\n<td>DingFeng XinHui (Hong Kong)<\/td>\n<td>HK<\/td>\n<td>13<\/td>\n<\/tr>\n<tr>\n<td>AS4134<\/td>\n<td>Chinanet<\/td>\n<td>CN<\/td>\n<td>13<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"image-caption\">Table 3. Breakdown of the DNS CNAME domains associated with the Chinese-language casino websites and the operator headquarters of DNS A record \/ IP addresses mapped to those CNAME domains (one CNAME domain may be mapped to multiple IPs \/ ASNs): U.S. 209, Hong Kong 184, China 53, France 19<\/p>\n<p>The three types differ enormously in the amount of infrastructure each requires.<\/p>\n<p>The Chinese-language casino ecosystem is significantly larger than the scambling sites and PeckBirdy malware C2 casino sites. Chinese-language casino DNS infrastructure also oftentimes consists of complex CNAME chains and rapidly mapped IPs sourced from Asian hosting providers, Bulletproof Hosts, and U.S. and European enterprise hosting providers. Tracking the Chinese-language casino websites is generally more complex and chaotic than the other types due to this hosting diversity.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image23.jpg\"><\/p>\n<p class=\"image-caption\">Figure 23. Domain volume by casino type since January 2021. At this scale, the scambling and PeckBirdy populations are barely visible compared to the Chinese-language casino websites.<\/p>\n<p>PeckBirdy\u2019s hosting closely resembles the Chinese-language casino pattern, while scambling is almost entirely hosted in the U.S. and European networks (Figure 24).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image24.jpg\"><\/p>\n<p class=\"image-caption\">Figure 24. Hosting composition by infrastructure type. Bars are shares of hosting records; a domain that resolves to several networks over the observation window contributes to more than one segment.<\/p>\n<p>If we drill into a different view of the top hosting providers mapped to the Chinese-language casino websites, Amazon remains the dominant U.S. host for these sites by a wide margin over Microsoft and Cloudflare, followed by a range of Hong Kong and other Asia-Pacific (APAC) providers (Figure 25).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image25.jpg\"><\/p>\n<p class=\"image-caption\">Figure 25. Top hosting providers for the Chinese-language casino population, aggregated by ASN and colored by provider headquarters. Amazon leads by a wide margin, followed by a stack of Hong Kong bulletproof networks\u2014Cloud Innovation\/Starcloud, Antbox Networks, CTG Server, E-Large, Joint Power Technology, jiii and Cloudie\u2014with Cloudflare and Microsoft the other major U.S. providers seen hosting a segment of the sites.<\/p>\n<p>Among the scambling sites, which target mostly non-Chinese audiences, Cloudflare IPs dominate the A records, followed by other, mostly U.S. and European, hosting providers (Figure 26). These provider locations align with the locations of their intended targets and victims.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image26.jpg\"><\/p>\n<p class=\"image-caption\">Figure 26. Top hosting providers for the scambling population, aggregated by ASN. Cloudflare dominates, followed by O.M.C. Computers &amp; Communications (a single European reseller operating three distinct ASNs) then other European and U.S. networks.<\/p>\n<p>PeckBirdy\u2019s much smaller population\u2014Chinese-language casino sites embedding C2 domains for China-aligned APT groups\u2014again mirrors the Chinese-language casino mix, combining U.S. providers along with China, Hong Kong, and other Asian hosts. Essentially, if you aren\u2019t tracking exactly which type of Chinese-language casino website you\u2019re looking at, they could look very similar from a hosting perspective.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image27.jpg\"><\/p>\n<p class=\"image-caption\">Figure 27. Top hosting providers for the PeckBirdy population. The counts are small, and the mix leans toward Hong Kong, mainland China and Singapore (Starcloud Global) hosts alongside Cloudflare, Microsoft, Amazon and Akamai.<\/p>\n<p>If we break down those hosting choices by time, the two populations diverge: U.S. hosting of Chinese-language casinos has fallen from its 2025 peak, while scambling infrastructure continues to grow on U.S. hosts through 2026 (Figure 28).<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image28.jpg\"><\/p>\n<p class=\"image-caption\">Figure 28. Hosting mix over time. The Chinese-language casino operation ran heavily on U.S.-headquartered clouds through 2024 and into early 2025, then swung decisively back toward China, Hong Kong and other-APAC hosting by mid-2026. The U.S. cloud hosting fell from roughly two-thirds of new domains to under a fifth by 2026. Scambling shows the opposite trajectory, beginning mostly on European reseller hosting and migrating decisively onto U.S. clouds from 2024 onward. PeckBirdy&#8217;s quarter-to-quarter swings reflect very small domain counts and should not be read as trend.<\/p>\n<p>Because the PeckBirdy population is so small, its hosting mix swings sharply: at some points entirely U.S. IPs, at others none. In 2026 they&#8217;ve used a mixture of IPs across the U.S., Europe, China and Hong Kong, and other APAC hosts.<\/p>\n<p>U.S. registrars dominate all three populations, which creates an opportunity for disruption (Figure 29). One detail worth noting: a handful of scambling domains outside the top registrars use Chinese registrars, even though scambling hosting is almost entirely U.S. and European. It is a modest signal, but it may point to some operators being based in Asia.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image29.jpg\"><\/p>\n<p class=\"image-caption\">Figure 29. Registration mix over time by registrar headquarters. U.S. registrars dominate most of the window across all three types, but the Chinese-language casino population shows a marked shift toward Chinese and Hong Kong registrars through 2026.<\/p>\n<p>Many of the top registrars for each of the three casino types are well-known companies that could hunt this infrastructure themselves and are well positioned to respond to broad abuse complaints.<\/p>\n<p>Registration timelines across the last five years show all three campaigns ramping up sharply in the last 12-18 months (Figure 30). Defenders need to take notice that even if you didn\u2019t have a strategy for tracking online casinos previously, these certainly aren\u2019t going anywhere, and serious China-aligned APT groups are taking advantage of the detection holes.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image30.jpg\"><\/p>\n<p class=\"image-caption\">Figure 30. First-appearance timeline for all three populations, monthly. Each panel is scaled independently. The Chinese-language casino population grows steadily from 2023 and spikes to 138,077 new domains in June 2026; scambling ramps through 2025 into a 2026 peak; PeckBirdy stays flat until a sharp expansion in mid-2026.<\/p>\n<p>We track the three casino types as separate operations, but when you look at a chart showing how many domains of each type are hosted on major networks, it becomes clearer that certain major providers could disrupt significant portions of the network. See Figure 31.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image31.jpg\"><\/p>\n<p class=\"image-caption\">Figure 31. Hosting networks used by one of the three casino types. Much of the overlap is unsurprising shared use of mainstream cloud providers (Amazon, Microsoft, Cloudflare, Google).<\/p>\n<p>We can also pair registration and hosting per domain to see whether the two choices move together. Because domains are tracked over multiple years, a single domain may appear in more than one registration or hosting region.<\/p>\n<p>For 1.1 million of the Chinese-language casino domains, the U.S.-registered domains were also hosted on U.S.-company infrastructure. But about 967,000 domains were registered through U.S. registrars and hosted in China or Hong Kong.<\/p>\n<p>We refer to this split as fronting: the registration sits with a provider subject to U.S. abuse processes, while the hosting sits outside that reach. A similar pattern can be seen with a portion of the PeckBirdy domains. From the scambling domains, the majority of European hosted domains were registered in the U.S., creating opportunities to disrupt most of the scambling sites through U.S. providers. See Figure 32.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image32a.jpg\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image32b.jpg\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-image32c.jpg\"><\/p>\n<p class=\"image-caption\">Figure 32. Registration region (left) flowing to hosting region (right); a domain is counted in every hosting region it touches. Among Chinese-language casino domains, roughly 967,000 U.S.-registered domains resolve to China or Hong Kong networks\u2014the fronting pattern at scale. Scambling shows a pronounced Europe registration-to-U.S. hosting crossover. PeckBirdy is small but skews toward Asian hosting regardless of registrar.<\/p>\n<h3>What Defenders Can Do<\/h3>\n<p>The practical takeaway from this research is that the three casino types demand different responses, none of which is &#8220;ignore it.\u201d A Chinese-language casino domain appearing in DNS logs could be an illegal gambling operation, a node in a money laundering network, or a decoy wrapped around an APT C2 endpoint. As Figure 1 showed, nothing about the three sites is visually distinct, further complicating casual casino detection efforts.<\/p>\n<p>The most important thing for defenders to do is stop ignoring casino domains. An alert on a Chinese-language casino or adult domain that gets closed as an employee browsing violation is precisely the outcome the PeckBirdy operators are counting on. The decoy works because the dismissal is reasonable\u2014these domains genuinely are, most of the time, exactly what they appear to be. Analysts reviewing them need a way to check whether a given domain carries a C2 payload before closing the ticket, and the C2 domains in the indicator list below are a starting point.<\/p>\n<p>The pattern of hiding malicious infrastructure inside seemingly legitimate web content is broader than any single campaign, and defenders who have not developed a strategy for casino domain triage are exposed to more than one threat using it.<\/p>\n<p>For PeckBirdy specifically, a warning signal on a network can come from the count of distinct C2 domains being queried, not the volume of queries to any one of them. A single resolution of githubassets[.]net is consistent with a code-level typo and carries little weight on its own; the domain is a typosquat of a legitimate GitHub asset host, and the long tail of queries to it reflects that. But repeated resolution of multiple distinct C2 domains from the same network is a different matter, and organizations seeing that pattern should treat it as a potential compromise rather than noise. Just over 3% of the enterprise networks in our telemetry resolved at least one of these domains, which suggests the exposure is broader than the campaign\u2019s small domain count implies.<\/p>\n<p>Finally, the absence of detections on VirusTotal for some PeckBirdy C2s raises concerns about how this Chinese APT threat is being tracked across the industry. The domain mcp-source[.]online had zero detections across VirusTotal as of August 2026, despite being an active C2 endpoint reached over WebSocket connections that most automated scanners never observe. The two related domains had 13 and three detections, respectively. We\u2019d welcome input from other defenders looking into PeckBirdy on how the campaign appears from their standpoint.<\/p>\n<h3>Indicators: Three Casinos and a Thousand Lookalikes<\/h3>\n<p>Below are the domains and IP addresses referenced throughout this research, grouped by casino type; they are a small sample of each population. This list is available in our GitHub repo <a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/blob\/main\/indicators\/csv\/casino_peckbirdy_20260915.csv\" target=\"_blank\"><strong>here<\/strong><\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th>Illegal Chinese-Language Casino Domains (Type 1)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>11170011[.]com<\/td>\n<\/tr>\n<tr>\n<td>puqxr[.]com<\/td>\n<\/tr>\n<tr>\n<td>80074[.]cc<\/td>\n<\/tr>\n<tr>\n<td>11168833[.]com<\/td>\n<\/tr>\n<tr>\n<td>312zym001[.]cc<\/td>\n<\/tr>\n<tr>\n<td>am125[.]cc<\/td>\n<\/tr>\n<tr>\n<td>843470[.]cc<\/td>\n<\/tr>\n<tr>\n<td>1862[.]cc<\/td>\n<\/tr>\n<tr>\n<td>zzyud[.]com<\/td>\n<\/tr>\n<tr>\n<td>zenplay77-x[.]space<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<thead>\n<tr>\n<th>Scambling Domains (Type 2)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>dollycasino[.]com<\/td>\n<\/tr>\n<tr>\n<td>dragobet[.]net<\/td>\n<\/tr>\n<tr>\n<td>appcasino[.]online<\/td>\n<\/tr>\n<tr>\n<td>summer138[.]fit<\/td>\n<\/tr>\n<tr>\n<td>storebet77[.]support<\/td>\n<\/tr>\n<tr>\n<td>realz[.]com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<thead>\n<tr>\n<th>PeckBirdy C2 and Decoy Domains (Type 3)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>vip311[.]cc \u2013 Decoy domain<\/td>\n<\/tr>\n<tr>\n<td>cache-cdn[.]org<\/td>\n<\/tr>\n<tr>\n<td>cache-mcp[.]com<\/td>\n<\/tr>\n<tr>\n<td>mcp-source[.]online<\/td>\n<\/tr>\n<tr>\n<td>asg78[.]com \u2013 Decoy domain<\/td>\n<\/tr>\n<tr>\n<td>githubassets[.]net<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<thead>\n<tr>\n<th>Supporting IP Addresses for Illegal Chinese-Language Casino Domains (Type 1)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>157[.]185[.]143[.]150<\/td>\n<\/tr>\n<tr>\n<td>146[.]103[.]91[.]133<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<style>\n.savy-seahorse-table {\nfont-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.code-format {\/*font-family: 'Courier New';*\/}.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;flex-wrap: wrap;justify-content: space-between;}.img-container img {width: 49%;margin-bottom: 10px;}.img-container-3-col img {width: 30%;margin-bottom: 10px;object-fit: contain;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;margin-bottom: 20px;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  max-width: 100%;  height: auto;width: auto;}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n.img-400{\nmax-width: 400px; width: 100%;\n}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">How Money Laundering, Scams, and Espionage<\/span> Hide in a Web Full of Casino Garbage');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why Should Anyone Care About Casino Websites? Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Over the last decade there\u2019s been massive growth in both gambling websites catering to Chinese audiences and similar casino sites targeting people all over the world. There\u2019s also been growth in legal gambling and casino websites, [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":14216,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[1157,1878,1879,1507,1880,1881,1755,30,40,1882,1883,1222,860,339,1884,1885,1886,930,1887],"class_list":{"0":"post-14140","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-vigorish-viper","9":"tag-funnull","10":"tag-peckbirdy","11":"tag-money-laundering","12":"tag-online-gambling","13":"tag-casino-scams","14":"tag-bulletproof-hosting","15":"tag-dns","16":"tag-threat-intelligence","17":"tag-infrastructure-laundering","18":"tag-cname","19":"tag-pig-butchering","20":"tag-malware-c2","21":"tag-apt","22":"tag-espionage","23":"tag-hong-kong-hosting","24":"tag-domain-abuse","25":"tag-cybercrime","26":"tag-scambling","27":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Illegal Gambling Sites Reveal Three Types of Cybercrime<\/title>\n<meta name=\"description\" content=\"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Illegal Gambling Sites Reveal Three Types of Cybercrime\" \/>\n<meta property=\"og:description\" content=\"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T15:00:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T15:23:49+00:00\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Illegal Gambling Sites Reveal Three Types of Cybercrime\" \/>\n<meta name=\"twitter:description\" content=\"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"35 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage\",\"datePublished\":\"2026-09-15T15:00:19+00:00\",\"dateModified\":\"2026-09-15T15:23:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/\"},\"wordCount\":6069,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg\",\"keywords\":[\"Vigorish Viper\",\"FUNNULL\",\"PeckBirdy\",\"money laundering\",\"online gambling\",\"casino scams\",\"bulletproof hosting\",\"DNS\",\"Threat Intelligence\",\"infrastructure laundering\",\"CNAME\",\"pig butchering\",\"malware c2\",\"apt\",\"espionage\",\"Hong Kong hosting\",\"domain abuse\",\"Cybercrime\",\"scambling\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/\",\"name\":\"Illegal Gambling Sites Reveal Three Types of Cybercrime\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg\",\"datePublished\":\"2026-09-15T15:00:19+00:00\",\"dateModified\":\"2026-09-15T15:23:49+00:00\",\"description\":\"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg\",\"width\":612,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Illegal Gambling Sites Reveal Three Types of Cybercrime","description":"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/","og_locale":"en_US","og_type":"article","og_title":"Illegal Gambling Sites Reveal Three Types of Cybercrime","og_description":"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/","og_site_name":"Infoblox Blog","article_published_time":"2026-09-15T15:00:19+00:00","article_modified_time":"2026-09-15T15:23:49+00:00","author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"Illegal Gambling Sites Reveal Three Types of Cybercrime","twitter_description":"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"35 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage","datePublished":"2026-09-15T15:00:19+00:00","dateModified":"2026-09-15T15:23:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/"},"wordCount":6069,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg","keywords":["Vigorish Viper","FUNNULL","PeckBirdy","money laundering","online gambling","casino scams","bulletproof hosting","DNS","Threat Intelligence","infrastructure laundering","CNAME","pig butchering","malware c2","apt","espionage","Hong Kong hosting","domain abuse","Cybercrime","scambling"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/","name":"Illegal Gambling Sites Reveal Three Types of Cybercrime","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg","datePublished":"2026-09-15T15:00:19+00:00","dateModified":"2026-09-15T15:23:49+00:00","description":"Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage-thumbnail.jpg","width":612,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14140","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=14140"}],"version-history":[{"count":28,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14140\/revisions"}],"predecessor-version":[{"id":14230,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14140\/revisions\/14230"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/14216"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=14140"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=14140"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=14140"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}