VYPR
researchPublished Sep 15, 2026· 1 source

Low-Quality Casino Sites Used as Cover for Chinese APT C2 Infrastructure

Infoblox research reveals that numerous Chinese-language gambling and adult websites are being repurposed by threat actors, including China-aligned APT groups, as command-and-control infrastructure.

Security researchers and the broader cybersecurity community have historically overlooked a significant threat vector: low-quality Chinese-language casino and adult websites. These domains, often hosted on major US cloud providers, are increasingly being utilized by sophisticated threat actors, including China-aligned Advanced Persistent Threat (APT) groups, as covert command-and-control (C2) infrastructure. Infoblox's latest report highlights that these seemingly innocuous sites can be difficult to distinguish from legitimate ones, making them ideal hiding places for malicious activities.

These websites, numbering around 1.7 million according to Infoblox's tracking, facilitate illegal gambling and are implicated in activities such as North Korean money laundering and tax evasion. Their visual and functional similarities across many platforms make them a confusing landscape to navigate. While many operate as typical online casinos relying on house odds, a subset has been co-opted for more nefarious purposes. A significant concern is their reliance on major US cloud providers like Amazon, Microsoft, Cloudflare, and Google for their computing infrastructure. Infoblox suggests this is likely due to "infrastructure laundering," where compromised accounts or services from these providers are rented out to malicious actors.

The United Nations Office on Drugs and Crime (UNODC) has noted a trend where disparate crime syndicates increasingly share common infrastructure for cybercrime. Online scams alone resulted in estimated losses between $88.3 billion and $114.1 billion across East Asia, Southeast Asia, Australia, and New Zealand in 2025. Within this ecosystem, a subset of casino sites engage in "scambling," where users can bet but are unable to withdraw winnings. However, the most alarming development is the use of these sites by China-aligned threat groups.

Specifically, China-aligned APT groups have been observed deploying the PeckBirdy framework since 2023, embedding their C2 domains within these low-quality casino websites. PeckBirdy, a script-based framework, allows attackers to inject malicious scripts into compromised websites. In one documented campaign, attackers used these scripts on gambling sites to load PeckBirdy and then present fake software update pages, tricking unsuspecting visitors into downloading malware. The deceptive nature of these sites lies in their ability to appear as legitimate, albeit low-quality, entertainment portals.

Infoblox reports that just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain, indicating a non-trivial level of exposure. The critical takeaway for defenders is to cease dismissing alerts related to Chinese-language casino or adult domains as mere employee browsing violations. This dismissal is precisely what the operators of PeckBirdy are counting on; their "decoy" works because the assumption that these sites are solely for entertainment is often correct, masking the malicious activity hidden beneath.

Security analysts investigating suspicious network contacts are strongly advised to perform deeper analysis of these domains, specifically checking for malicious payloads before closing tickets. The complexity and deceptive nature of these platforms require a more thorough investigative approach than previously applied. By understanding this evolving tactic, organizations can better defend against sophisticated APT operations that leverage the anonymity and perceived harmlessness of online gambling and adult content sites.

The use of these platforms represents a significant challenge in threat detection and attribution. The constant evolution of these tactics, coupled with the sheer volume of such domains, necessitates advanced analytical tools and a shift in defensive strategies. Ignoring these seemingly low-risk sites could lead to significant security breaches, making vigilance and thorough investigation paramount.

Synthesized by Vypr AI