News

Casino Lookalikes Hide Gambling, Scams & Cybercrime: Infoblox Research

Published

on

New research from Infoblox Threat Intel shows that similar looking casino websites may mask very different risks – from illegal gambling and money laundering to consumer scams related to gambling or “scambling” and malware.

Defenders should not dismiss Chinese-language casino domains as low-priority noise: on a similar-looking page the difference between a working casino, a scam and a malware command-and-control endpoint may not be visible in a browser.

The largest population in the research, Chinese-language casinos for illegal gambling and money laundering, includes more than 1.7 million casino domains. Infoblox Threat Intel tracks 16 clusters, with the two largest (FUNNULL and Vigorish Viper) accounting for roughly 81 percent of the tracked population. These sites often operate as real casinos, with working customer support and withdrawals, helping them retain players and deposits.

A second group of sites, referred to as “scambling”, presents itself as online gambling but is set up to defraud customers. The sites may rig games or prevent withdrawals through delays, fees and other tactics. The research shows these sites primarily target English-speaking audiences, but operators have also built sites aimed at people in Europe, South America and Asia.

The smallest group embeds PeckBirdy command-and-control domains in low-quality Chinese-language casino websites. PeckBirdy is a framework used by China-aligned advanced persistent threat (APT) groups since 2023.

Just over 3 percent of enterprise customers in Infoblox telemetry resolved at least one related domain, and one domain had zero detections on VirusTotal as of August 31, 2026.

Together, these findings challenge a common assumption: that a casino domain is merely a low-value browsing or policy issue. The research shows that defenders need to assess what sits behind the page before closing an alert, because the visible content alone cannot reliably distinguish gambling from fraud or malware.

Zach Edwards, Staff Threat Researcher at Infoblox said: “The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review.”

The full research outlines practical actions defenders can take against those threats: https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/

Trending

Exit mobile version