Infoblox Finds Casino Sites Used for Money Laundering, Scams and PeckBirdy C2

· Original article ↗

Summary

Infoblox identifies illicit casino sites used for illegal gambling and money laundering, consumer scams, and PeckBirdy command-and-control. The research tracks more than 1.7 million Chinese-language casino domains and finds some C2 domains have little or no detection.

Key points

  • The report distinguishes illegal Chinese-language casinos used for gambling and money laundering, scam gambling sites that block withdrawals, and casino decoys concealing PeckBirdy C2 infrastructure.
  • Infoblox tracks more than 1.7 million Chinese-language casino domains; two clusters account for about 81% of that population.
  • Scam gambling sites target users with deposit bonuses and then delay or prevent withdrawals; the researchers observed growth in new scam sites during 2026.
  • China-aligned APT groups have used PeckBirdy since 2023, hiding C2 domains in Chinese-language casino and adult websites.
  • Some PeckBirdy C2 activity uses JavaScript service workers and WebSocket connections that automated scanners may miss; mcp-source[.]online had zero VirusTotal detections as of August 2026.
  • Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain. Repeated connections to multiple distinct C2 domains are more concerning than an isolated githubassets[.]net resolution, which may result from a typo.
  • The researchers advise defenders not to dismiss casino-domain alerts automatically and to investigate for embedded C2; domain blocking alone is unlikely to stop the rapidly rotating gambling infrastructure.

Article Details

Publisher
Infoblox Threat Intel
Report Period
2021–2026; VirusTotal checks as of 2026-08-31
Scope
Illegal Chinese-language casinos, scam gambling sites, and PeckBirdy C2 domains disguised as casino or adult sites.
Sample Size
More than 1.7 million illegal Chinese-language casino domains across 16 tracked clusters; thousands of scam gambling domains and dozens of PeckBirdy decoy domains.
Key Statistics
  • Infoblox tracks more than 1.7 million illegal Chinese-language casino domains.
  • The FUNNULL CDN and Vigorish Viper networks account for roughly 81% of the tracked Chinese-language casino domains.
  • The Chinese-language casino population reached 138,077 newly observed domains in June 2026.
  • Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain; a single resolution, particularly of githubassets[.]net, does not establish compromise.
  • Among customers that resolved PeckBirdy C2 domains, 23% resolved three to ten distinct domains—a pattern the report considers more concerning than one or two resolutions.
Recommendations
  • Triage alerts involving casino or adult domains for embedded C2 payloads before dismissing them as browsing-policy violations.
  • Investigate repeated resolution of multiple distinct PeckBirdy C2 domains from the same network as a potential compromise; do not treat a lone githubassets[.]net resolution as sufficient evidence.
  • Do not rely on blocking individual illegal casino domains as a standalone disruption measure, because operators routinely rotate domains.
  • Use broader abuse complaints to registrars and hosting providers where the tracked infrastructure permits coordinated disruption.

Indicators of compromise

TypeIndicatorContext
DOMAIN11168833[.]comIllegal Chinese-language casino domain.
DOMAIN11170011[.]comIllegal Chinese-language casino domain displaying apparently impersonated casino branding.
DOMAIN1862[.]ccIllegal Chinese-language casino domain that redirects visitors to IP-hosted copies of its site.
DOMAIN312zym001[.]ccIllegal Chinese-language casino domain.
DOMAIN80074[.]ccIllegal Chinese-language casino domain.
DOMAIN843470[.]ccIllegal Chinese-language casino domain.
DOMAINam125[.]ccIllegal Chinese-language casino domain.
DOMAINappcasino[.]onlineDomain reached through redirects from the scam gambling site dragobet[.]net.
DOMAINasg78[.]comPeckBirdy casino decoy domain observed loading a suspicious JavaScript payload.
DOMAINcache-cdn[.]orgPeckBirdy C2 domain identified in earlier research.
DOMAINcache-mcp[.]comPeckBirdy C2 domain embedded in casino decoy sites.
DOMAINdollycasino[.]comSite classified as scam gambling infrastructure; customer reviews report difficulty withdrawing winnings.
DOMAINdragobet[.]netScam gambling domain promoted through comment and profile spam.
DOMAINgithubassets[.]netPeckBirdy-used C2 domain; the report cautions that many isolated queries likely result from typos.
DOMAINmcp-source[.]onlinePeckBirdy C2 domain receiving WebSocket connections from decoy sites.
DOMAINpuqxr[.]comChinese-language investment site in the tracked illegal casino infrastructure; its branding likely impersonates Point72 Asset Management.
DOMAINrealz[.]comDomain listed by Infoblox as scam gambling infrastructure.
DOMAINstorebet77[.]supportJoker-branded scam gambling domain using Google branding without an apparent affiliation.
DOMAINsummer138[.]fitJoker-branded scam gambling domain.
DOMAINvip311[.]ccPeckBirdy casino decoy domain embedding a malware C2 domain.
DOMAINzenplay77-x[.]spaceDomain listed by Infoblox as illegal Chinese-language casino infrastructure.
DOMAINzzyud[.]comDomain listed by Infoblox as illegal Chinese-language casino infrastructure.
HOSTNAMEjs[.]cache-mcp[.]comHost serving a suspicious JavaScript payload to a PeckBirdy casino decoy site.
IPV4146[.]103[.]91[.]133IP address hosting a copy of an illegal casino site after a redirect from 1862[.]cc for a Japanese visitor IP.
IPV4157[.]185[.]143[.]150IP address hosting a copy of an illegal casino site after a redirect from 1862[.]cc for a Hong Kong visitor IP.

MITRE ATT&CK

Threat Actors

Vendors

Tools

Countries

Industries

Related Articles