Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some quietly connect visitors and compromised systems to attacker-controlled servers.

The pages are built to appear disposable and harmless, which can lower the chance that they receive security scrutiny. The activity centers on PeckBirdy, a JavaScript-based command-and-control framework used by China-aligned advanced persistent threat groups since 2023.

The campaigns have targeted corporate and government organizations across Asia, with education, IT, banking, financial services, and government among the sectors observed. Infoblox analysts identified the latest expansion while tracking a vast ecosystem of illegal casino domains.

Infoblox said in a report shared with Cyber Security News (CSN) that the same disguise now extends to Chinese-language adult sites, widening the places where the operators can hide.

Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source - Infoblox)
Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source – Infoblox)

It also underlines how criminal web ecosystems can give espionage operators a cover story, and not only that even the danger is not a casino page alone.

Attackers use pages that look unimportant to host or embed code, establish background web connections, and blend their traffic into a crowded and frequently ignored corner of the internet. That approach can leave defenders focused on the lure while the real espionage channel remains unseen.

Hackers Are Hiding Espionage Infrastructure

Researchers separate this activity from two broader casino-abuse models: illegal gambling and money laundering operations, and scam gambling sites that prevent victims from withdrawing funds.

PeckBirdy sites are different because the casino is set dressing, not a service intended to attract or retain real players. One observed page registered a JavaScript service worker and loaded a suspicious script resembling earlier PeckBirdy code.

Service workers can run in the background, making them useful for maintaining contact after a page visit. Similar abuse has appeared in service worker credential theft campaigns, where background browser code can intercept or persist beyond normal browsing.

The report highlighted a casino-themed decoy that embedded a command server behind familiar branding. Investigators then found that live WebSocket connections reached another domain, while related adult websites used the same pattern.

This layered design makes quick reputation checks less reliable, particularly when automated scanners do not fully capture browser-side behavior.

Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source - Infoblox)
Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source – Infoblox)

PeckBirdy can also lead victims to false browser-update prompts that deliver backdoors, a familiar social-engineering route that deserves closer review alongside reports of fake browser update malware.

The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access, raising the potential impact from a single web visit to a wider network intrusion.

Detection Gaps Demand Context

The researchers found that just over 3% of their enterprise customers resolved at least one PeckBirdy C2 domain. A lone lookup is not always proof of compromise because one historical domain resembles a possible typo.

But repeated resolution of three to ten distinct C2 domains is a meaningful warning sign that warrants investigation, rather than a single alert viewed in isolation.

Detection coverage varied sharply. A known PeckBirdy domain had 13 detections in VirusTotal, another had three, and the WebSocket-related domain had none at the time of publication.

That gap shows why defenders should not treat a clean reputation result as clearance, especially when investigating Chinese threat actor infrastructure that is designed to blend into common web services.

Security teams should review DNS, proxy, and browser telemetry for the indicators below, then correlate connections with endpoint events and unusual service-worker registrations.

They should prioritize hosts contacting several distinct domains, preserve relevant logs, and examine whether users were sent to fake updates or unfamiliar gambling and adult pages.

Blocking one domain at a time is unlikely to solve the problem because operators rotate domains and infrastructure quickly.

Organizations should instead combine domain monitoring with web filtering, timely browser and endpoint updates, least-privilege controls, and incident-response checks that look for related activity across the network.

That layered approach also helps uncover covert C2 communication methods that do not resemble conventional malware traffic.

Indicators of compromise (IoCs):-

Type Indicator Description
Decoy casino domain vip311.cc Casino-themed site identified as embedding PeckBirdy C2 infrastructure
Casino comparison domain zzyud.com Casino site shown in the researchers’ comparison of lookalike pages
Casino comparison domain zenplay77-x.space Casino site shown in the researchers’ comparison of lookalike pages
Casino domain 11170011.com Illegal Chinese-language casino site using impersonated branding
Investment scam domain puqxr.com Site impersonating an investment platform
Casino domains 80074.cc, 11168833.com Near-identical casino sites using different branding
Casino domains 312zym001.cc, am125.cc, 843470.cc Recently active casino-site examples
Redirecting casino domain 1862.cc Casino site that fingerprinted visitors and redirected them by location
IP address 157.185.143.150 Final destination observed when accessing 1862.cc from a Hong Kong IP address
IP address 146.103.91.133 Final destination observed when accessing 1862.cc from a Japanese IP address
Scam gambling domain dollycasino.com Scam gambling site associated with complaints about withdrawal problems
Scam gambling domain dragobet.net Scam gambling site promoted through injected comment spam
Redirect domain appcasino.online Domain reached through clicks on dragobet.net
Scam gambling domain summer138.t Joker-branded scam gambling site
Scam gambling domain storebet77.support Joker-branded scam gambling site using misleading branding
Scam gambling domain realz.com Scam gambling site advertising a deposit bonus
Casino decoy domain asg78.com Chinese-language casino domain observed loading a suspicious JavaScript payload
Malicious JavaScript URL js.cache-mcp.com/layer.js Suspicious payload loaded by asg78.com
C2 domain cache-mcp.com PeckBirdy command-and-control domain embedded in casino pages
C2 domain mcp-source.online WebSocket-related PeckBirdy domain used to collect connections
C2 domain cache-cdn.org Previously identified PeckBirdy domain with VirusTotal detections
Possible typosquat/C2-related domain githubassets.net Historical PeckBirdy domain that may also receive accidental typo-related queries

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites appeared first on Cyber Security News.