Executive Summary
An Infoblox cybersecurity report, published on 15 September 2026, has revealed that online casinos are being used to disguise and deploy malicious threats targeting governments across Asia. Infoblox researchers discovered that a computer script known as PeckBirdy is being embedded into Chinese-language casino websites to avoid detection by targets and security software. These websites prompt targets to download what they believe is software for the casino experience, but the update embeds links providing China-aligned advanced persistent threat actors with persistent access to information contained within the employee’s computer system. The threat is elevated because cybersecurity teams within targeted organizations often dismiss the employees’ actions as simply violating policies relating to accessing unauthorized websites, without discovering the graver implications of their actions. Furthermore, the lack of detections on VirusTotal for some PeckBirdy C2s raises concerns about how this Chinese APT threat is being tracked across the industry.
The RH-ISAC intelligence team will continue to monitor and provide updates on the situation as more information emerges.
Key Takeaways
- In addition to the APT threat, the Infoblox report identified over 1.7 million domains related to Chinese-language gambling sites. These domains are being used as a key component of transnational organized money laundering and support the movement of money out of China and other countries across Asia.
- Scam gambling sites, known as scambling, have also begun to emerge targeting players worldwide by offering large deposit bonuses before making it impossible for players to withdraw their winnings.
- The three types of researched sites differ enormously in the amount of infrastructure each requires: Chinese-language casino ecosystems are significantly larger than scambling sites and PeckBirdy malware C2 casino sites, utilizing complex CNAME chains and rapidly mapped IPs sourced from Asian hosting providers, Bulletproof Hosts, and U.S. and European enterprise hosting providers.
- U.S. registrars dominate all three populations, creating opportunities to disrupt the networks if properly addressed. About 967,000 domains were registered through U.S. registrars and hosted in China or Hong Kong, a split referred to as fronting because the registration sits with a provider subject to U.S. abuse processes while the hosting sits outside that reach.
- Analysts reviewing alerts on casino domains need a way to check whether a given domain carries a C2 payload before closing the ticket, and repeated resolution of multiple distinct C2 domains from the same network should be treated as a potential compromise rather than noise.
Indicators of Compromise
Infoblox has provided Indicators of Compromise included with this campaign, which are included below in their entirety.
Illegal Chinese-Language Casino Domains (Type 1) |
11170011[.]com |
puqxr[.]com |
80074[.]cc |
11168833[.]com |
312zym001[.]cc |
am125[.]cc |
843470[.]cc |
1862[.]cc |
zzyud[.]com |
zenplay77-x[.]space |
Scambling Domains (Type 2) |
dollycasino[.]com |
dragobet[.]net |
appcasino[.]online |
summer138[.]fit |
storebet77[.]support |
realz[.]com |
PeckBirdy C2 and Decoy Domains (Type 3) |
vip311[.]cc – Decoy domain |
cache-cdn[.]org |
cache-mcp[.]com |
mcp-source[.]online |
asg78[.]com – Decoy domain |
githubassets[.]net |
Supporting IP Addresses for Illegal Chinese-Language Casino Domains (Type 1) |
157[.]185[.]143[.]150 |
146[.]103[.]91[.]133 |