Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some quietly connect visitors and compromised systems to attacker-controlled servers.
The pages are built to appear disposable and harmless, which can lower the chance that they receive security scrutiny. The activity centers on PeckBirdy, a JavaScript-based command-and-control framework used by China-aligned advanced persistent threat groups since 2023.
The campaigns have targeted corporate and government organizations across Asia, with education, IT, banking, financial services, and government among the sectors observed. Infoblox analysts identified the latest expansion while tracking a vast ecosystem of illegal casino domains.
Infoblox said in a report shared with Cyber Security News (CSN) that the same disguise now extends to Chinese-language adult sites, widening the places where the operators can hide.
![Three casino sites from left to right, vip311[.]cc, zzyud[.]com, zenplay77-x[.]space; vip311[.]cc is associated with PeckBirdy (Source - Infoblox)](https://i0.wp.com/www.cryptika.com/wp-content/uploads/2026/09/Threecasinositesfromlefttorightvip311cczzyudcomzenplay77-xspacevip311ccisassociatedwithPeckBirdySource-Infoblox.jpg?w=1260&ssl=1)
It also underlines how criminal web ecosystems can give espionage operators a cover story, and not only that even the danger is not a casino page alone.
Attackers use pages that look unimportant to host or embed code, establish background web connections, and blend their traffic into a crowded and frequently ignored corner of the internet. That approach can leave defenders focused on the lure while the real espionage channel remains unseen.
Hackers Are Hiding Espionage Infrastructure
Researchers separate this activity from two broader casino-abuse models: illegal gambling and money laundering operations, and scam gambling sites that prevent victims from withdrawing funds.
PeckBirdy sites are different because the casino is set dressing, not a service intended to attract or retain real players. One observed page registered a JavaScript service worker and loaded a suspicious script resembling earlier PeckBirdy code.
Service workers can run in the background, making them useful for maintaining contact after a page visit. Similar abuse has appeared in service worker credential theft campaigns, where background browser code can intercept or persist beyond normal browsing.
The report highlighted a casino-themed decoy that embedded a command server behind familiar branding. Investigators then found that live WebSocket connections reached another domain, while related adult websites used the same pattern.
This layered design makes quick reputation checks less reliable, particularly when automated scanners do not fully capture browser-side behavior.
![Screenshot of a Chinese-language casino domain (vip311[.]cc) (Source - Infoblox)](https://i0.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAMZD1oYveHXSbXMV45cYXPhOXOt3igerI-jt9Wtlwud0fGqi4iCIoS6sQhR98bo4J-keujZ1KjjKqGajfwqjhc5BIaYJFHkGxFJguhHGg6Pf5fO30RhqRvVNP9ruN_vNX3r442yVwnW4I1iCXQ48M6NY4u-ILtmmk5wRfYauJXaxjLoNup6FgiB0rqMg/s1600/Screenshot%20of%20a%20Chinese-language%20casino%20domain%20%28vip311%5B.%5Dcc%29%20%28Source%20-%20Infoblox%29.webp?w=1260&ssl=1)
PeckBirdy can also lead victims to false browser-update prompts that deliver backdoors, a familiar social-engineering route that deserves closer review alongside reports of fake browser update malware.
The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access, raising the potential impact from a single web visit to a wider network intrusion.
Detection Gaps Demand Context
The researchers found that just over 3% of their enterprise customers resolved at least one PeckBirdy C2 domain. A lone lookup is not always proof of compromise because one historical domain resembles a possible typo.
But repeated resolution of three to ten distinct C2 domains is a meaningful warning sign that warrants investigation, rather than a single alert viewed in isolation.
Detection coverage varied sharply. A known PeckBirdy domain had 13 detections in VirusTotal, another had three, and the WebSocket-related domain had none at the time of publication.
That gap shows why defenders should not treat a clean reputation result as clearance, especially when investigating Chinese threat actor infrastructure that is designed to blend into common web services.
Security teams should review DNS, proxy, and browser telemetry for the indicators below, then correlate connections with endpoint events and unusual service-worker registrations.
They should prioritize hosts contacting several distinct domains, preserve relevant logs, and examine whether users were sent to fake updates or unfamiliar gambling and adult pages.
Blocking one domain at a time is unlikely to solve the problem because operators rotate domains and infrastructure quickly.
Organizations should instead combine domain monitoring with web filtering, timely browser and endpoint updates, least-privilege controls, and incident-response checks that look for related activity across the network.
That layered approach also helps uncover covert C2 communication methods that do not resemble conventional malware traffic.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Decoy casino domain | vip311.cc |
Casino-themed site identified as embedding PeckBirdy C2 infrastructure |
| Casino comparison domain | zzyud.com |
Casino site shown in the researchers’ comparison of lookalike pages |
| Casino comparison domain | zenplay77-x.space |
Casino site shown in the researchers’ comparison of lookalike pages |
| Casino domain | 11170011.com |
Illegal Chinese-language casino site using impersonated branding |
| Investment scam domain | puqxr.com |
Site impersonating an investment platform |
| Casino domains | 80074.cc, 11168833.com |
Near-identical casino sites using different branding |
| Casino domains | 312zym001.cc, am125.cc, 843470.cc |
Recently active casino-site examples |
| Redirecting casino domain | 1862.cc |
Casino site that fingerprinted visitors and redirected them by location |
| IP address | 157.185.143.150 |
Final destination observed when accessing 1862.cc from a Hong Kong IP address |
| IP address | 146.103.91.133 |
Final destination observed when accessing 1862.cc from a Japanese IP address |
| Scam gambling domain | dollycasino.com |
Scam gambling site associated with complaints about withdrawal problems |
| Scam gambling domain | dragobet.net |
Scam gambling site promoted through injected comment spam |
| Redirect domain | appcasino.online |
Domain reached through clicks on dragobet.net |
| Scam gambling domain | summer138.t |
Joker-branded scam gambling site |
| Scam gambling domain | storebet77.support |
Joker-branded scam gambling site using misleading branding |
| Scam gambling domain | realz.com |
Scam gambling site advertising a deposit bonus |
| Casino decoy domain | asg78.com |
Chinese-language casino domain observed loading a suspicious JavaScript payload |
| Malicious JavaScript URL | js.cache-mcp.com/layer.js |
Suspicious payload loaded by asg78.com |
| C2 domain | cache-mcp.com |
PeckBirdy command-and-control domain embedded in casino pages |
| C2 domain | mcp-source.online |
WebSocket-related PeckBirdy domain used to collect connections |
| C2 domain | cache-cdn.org |
Previously identified PeckBirdy domain with VirusTotal detections |
| Possible typosquat/C2-related domain | githubassets.net |
Historical PeckBirdy domain that may also receive accidental typo-related queries |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites appeared first on Cyber Security News.

