Infoblox Finds Casino Sites Used for Money Laundering, Scams and PeckBirdy C2

Summary
Infoblox identifies illicit casino sites used for illegal gambling and money laundering, consumer scams, and PeckBirdy command-and-control. The research tracks more than 1.7 million Chinese-language casino domains and finds some C2 domains have little or no detection.
Key points
- The report distinguishes illegal Chinese-language casinos used for gambling and money laundering, scam gambling sites that block withdrawals, and casino decoys concealing PeckBirdy C2 infrastructure.
- Infoblox tracks more than 1.7 million Chinese-language casino domains; two clusters account for about 81% of that population.
- Scam gambling sites target users with deposit bonuses and then delay or prevent withdrawals; the researchers observed growth in new scam sites during 2026.
- China-aligned APT groups have used PeckBirdy since 2023, hiding C2 domains in Chinese-language casino and adult websites.
- Some PeckBirdy C2 activity uses JavaScript service workers and WebSocket connections that automated scanners may miss; mcp-source[.]online had zero VirusTotal detections as of August 2026.
- Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain. Repeated connections to multiple distinct C2 domains are more concerning than an isolated githubassets[.]net resolution, which may result from a typo.
- The researchers advise defenders not to dismiss casino-domain alerts automatically and to investigate for embedded C2; domain blocking alone is unlikely to stop the rapidly rotating gambling infrastructure.
Article Details
- Publisher
- Infoblox Threat Intel
- Report Period
- 2021–2026; VirusTotal checks as of 2026-08-31
- Scope
- Illegal Chinese-language casinos, scam gambling sites, and PeckBirdy C2 domains disguised as casino or adult sites.
- Sample Size
- More than 1.7 million illegal Chinese-language casino domains across 16 tracked clusters; thousands of scam gambling domains and dozens of PeckBirdy decoy domains.
- Key Statistics
- Infoblox tracks more than 1.7 million illegal Chinese-language casino domains.
- The FUNNULL CDN and Vigorish Viper networks account for roughly 81% of the tracked Chinese-language casino domains.
- The Chinese-language casino population reached 138,077 newly observed domains in June 2026.
- Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain; a single resolution, particularly of githubassets[.]net, does not establish compromise.
- Among customers that resolved PeckBirdy C2 domains, 23% resolved three to ten distinct domains—a pattern the report considers more concerning than one or two resolutions.
- Recommendations
- Triage alerts involving casino or adult domains for embedded C2 payloads before dismissing them as browsing-policy violations.
- Investigate repeated resolution of multiple distinct PeckBirdy C2 domains from the same network as a potential compromise; do not treat a lone githubassets[.]net resolution as sufficient evidence.
- Do not rely on blocking individual illegal casino domains as a standalone disruption measure, because operators routinely rotate domains.
- Use broader abuse complaints to registrars and hosting providers where the tracked infrastructure permits coordinated disruption.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 11168833[.]com | Illegal Chinese-language casino domain. |
| DOMAIN | 11170011[.]com | Illegal Chinese-language casino domain displaying apparently impersonated casino branding. |
| DOMAIN | 1862[.]cc | Illegal Chinese-language casino domain that redirects visitors to IP-hosted copies of its site. |
| DOMAIN | 312zym001[.]cc | Illegal Chinese-language casino domain. |
| DOMAIN | 80074[.]cc | Illegal Chinese-language casino domain. |
| DOMAIN | 843470[.]cc | Illegal Chinese-language casino domain. |
| DOMAIN | am125[.]cc | Illegal Chinese-language casino domain. |
| DOMAIN | appcasino[.]online | Domain reached through redirects from the scam gambling site dragobet[.]net. |
| DOMAIN | asg78[.]com | PeckBirdy casino decoy domain observed loading a suspicious JavaScript payload. |
| DOMAIN | cache-cdn[.]org | PeckBirdy C2 domain identified in earlier research. |
| DOMAIN | cache-mcp[.]com | PeckBirdy C2 domain embedded in casino decoy sites. |
| DOMAIN | dollycasino[.]com | Site classified as scam gambling infrastructure; customer reviews report difficulty withdrawing winnings. |
| DOMAIN | dragobet[.]net | Scam gambling domain promoted through comment and profile spam. |
| DOMAIN | githubassets[.]net | PeckBirdy-used C2 domain; the report cautions that many isolated queries likely result from typos. |
| DOMAIN | mcp-source[.]online | PeckBirdy C2 domain receiving WebSocket connections from decoy sites. |
| DOMAIN | puqxr[.]com | Chinese-language investment site in the tracked illegal casino infrastructure; its branding likely impersonates Point72 Asset Management. |
| DOMAIN | realz[.]com | Domain listed by Infoblox as scam gambling infrastructure. |
| DOMAIN | storebet77[.]support | Joker-branded scam gambling domain using Google branding without an apparent affiliation. |
| DOMAIN | summer138[.]fit | Joker-branded scam gambling domain. |
| DOMAIN | vip311[.]cc | PeckBirdy casino decoy domain embedding a malware C2 domain. |
| DOMAIN | zenplay77-x[.]space | Domain listed by Infoblox as illegal Chinese-language casino infrastructure. |
| DOMAIN | zzyud[.]com | Domain listed by Infoblox as illegal Chinese-language casino infrastructure. |
| HOSTNAME | js[.]cache-mcp[.]com | Host serving a suspicious JavaScript payload to a PeckBirdy casino decoy site. |
| IPV4 | 146[.]103[.]91[.]133 | IP address hosting a copy of an illegal casino site after a redirect from 1862[.]cc for a Japanese visitor IP. |
| IPV4 | 157[.]185[.]143[.]150 | IP address hosting a copy of an illegal casino site after a redirect from 1862[.]cc for a Hong Kong visitor IP. |
MITRE ATT&CK
Threat Actors
FUNNULL CDNReport label for an active cluster associated with illegal Chinese-language casino domains and bulletproof CDN infrastructure.Sable SquirrelTracked actor described as operating gambling and streaming domains that also function as malware C2 infrastructure.Vault ViperTracked gambling network discussed in the cited UNODC case study and earlier Infoblox research.Vigorish ViperTracked network associated with a large population of illegal Chinese-language casino domains.
Vendors
AkamaiAkamai TechnologiesAmazonhosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host portions of the observed infrastructure associated with these casino operations.Cloudflarehosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host portions of the observed infrastructure associated with these casino operations.CTG Serverhosts, they are using a wide range of Asian hosting providers including the known bulletproof hosting ASN, CTG Server (myctgs[.]com).GoogleIf you search this domain “dragobet[.]net” on Google it quickly becomes clear that someone ran a blackhat SEO campaign spamming websites all over the internet with this domain earlier this year (Figure 10).Microsofthosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host portions of the observed infrastructure associated with these casino operations.
Tools
PeckBirdyThat last category is used by little-known China-aligned advanced persistent threat (APT) actors operating since 2023 using a C2 framework known as PeckBirdy to attack corporate and government targets across Asia.URLscanLive PeckBirdy casino domains can be found through this URLscan query for the cache-mcp[.]com C2 domain—open them only if you understand the risks.VirusTotalWe also documented a C2 domain being used by the PeckBirdy framework that had zero detections on VirusTotal at the time of this publication.
Countries
Chinathree major purposes hiding behind most illicit online casino sites: facilitating illegal gambling across China and Asia, and laundering money; stealing money from customers or preventing them from cashing outHong KongWhen trying to visit 1862[.]cc while using a Hong Kong IP address, the site redirected to a final destination IP address, 157[.]185[.]143[.]150, hosting the website.North KoreaIt supports the movement of money out of China and other Asian jurisdictions to avoid taxes and oversight, and North Korea uses it to launder proceeds from its online criminal operations.PhilippinesThe UNODC report also highlighted that the Philippines ordered more than 7,000 illegal gambling websites blocked in 2024, which had limited effect and was described as “practical futility.”SingaporeThe counts are small, and the mix leans toward Hong Kong, mainland China and Singapore (Starcloud Global) hosts alongside Cloudflare, Microsoft, Amazon and Akamai.United States
Industries
BankingThese Chinese-language online casinos are one leg of the Asian underground banking economy operating across over 1.7 million domains.EducationWhen we look at the industries that are targeted, education has been a top target, which aligns to previous Trend Micro reporting about a July 2024 attack on a Philippines education institution.Financial ServicesWe have also seen IT, banking, financial services, and government as top targets, but also broad potential targeting of other industries.GamblingMany security teams ignore online gambling and casino domains, especially Chinese-language websites.GovernmentThat last category is used by little-known China-aligned advanced persistent threat (APT) actors operating since 2023 using a C2 framework known as PeckBirdy to attack corporate and government targets across Asia.ITNo, it’s rigged/can’t cash out