Infoblox finds PeckBirdy malware behind Chinese casino sites

Infoblox finds PeckBirdy malware behind Chinese casino sites

Security firm Infoblox has published a report arguing that the security industry pays too little attention to Chinese-language gambling and adult websites, because a subset of them double as command-and-control (C2) infrastructure for espionage and malware distribution. Infoblox says it tracks about 1.7 million Chinese-language casino websites that offer illegal gambling, and that these sites also support North Korean money laundering and tax avoidance, among other dubious activities. Zach Edwards, a staff threat researcher at Infoblox, suggests that security researchers and the media have largely ignored these sites because the story is complicated and confusing.

The report describes three types of casino sites that look alike from the outside but serve different purposes. Most operate like an ordinary illegal casino, profiting from house odds. A subset run what the report calls "scambling": visitors place bets but cannot withdraw their winnings. And a further subset is used by China-aligned APT groups, which, Infoblox says, have run a framework called PeckBirdy since 2023 to hide their malware C2 domains inside these low-quality casino sites. Trend Micro researchers first flagged PeckBirdy in January, describing it as a script-based framework that attackers load through compromised websites; in one campaign, attackers injected scripts into gambling sites that loaded PeckBirdy and served fake software-update pages meant to trick visitors into downloading malware.

Although the sites target visitors in China and elsewhere in Asia, some rely on US cloud infrastructure. "Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the Infoblox report states, adding that one likely explanation is account theft at those providers, a practice previously documented as "infrastructure laundering." The report points to hosting companies such as Funnull, which have reportedly rented IP addresses from Amazon Web Services and Microsoft and then made them available to clients running illegal operations. The article does not say whether Amazon, Microsoft, Cloudflare or Google were asked to comment, or took any action.

Infoblox says just over 3 percent of its enterprise customers have resolved at least one PeckBirdy C2 domain, the only concrete figure it gives for the framework's reach; no specific domains, organizations or victims are named. For broader context, a July 2026 report from the UN Office on Drugs and Crime found that criminal syndicates increasingly share infrastructure for cybercrime, and estimated that online scams caused losses of between $88.3 billion and $114.1 billion in 2025 across East Asia, Southeast Asia, Australia and New Zealand.

Infoblox's central recommendation is procedural rather than technical: stop treating a flagged casino or adult domain as an automatic browsing-policy violation. "The most important thing for defenders to do is stop ignoring casino domains," the report argues, adding that PeckBirdy's operators are counting on exactly that kind of dismissal, because it is usually the reasonable call since most of these domains really are what they appear to be. Analysts reviewing suspicious network contacts are advised to check whether a flagged domain carries a malicious payload before closing the review ticket.

Key facts

  • Infoblox tracks about 1.7 million Chinese-language casino websites that offer illegal gambling, which it says also support North Korean money laundering and tax avoidance.
  • China-aligned APT groups have run a malware framework called PeckBirdy since 2023, hiding its command-and-control domains inside low-quality Chinese-language casino sites.
  • Just over 3 percent of Infoblox's enterprise customers have resolved at least one PeckBirdy C2 domain, the report's only concrete figure for the framework's reach.
  • Major US hosts including Amazon, Microsoft, Cloudflare and Google still carry infrastructure tied to these domains, which Infoblox attributes to likely account theft at hosting companies such as Funnull, a pattern it calls "infrastructure laundering."
  • A July 2026 UN Office on Drugs and Crime report put 2025 global online-scam losses across East Asia, Southeast Asia, Australia and New Zealand at $88.3 billion to $114.1 billion.

Why it matters

Casino and adult-site domains are the kind of alert a security team closes without a second look, and Infoblox's point is that the same look and template covers an ordinary illegal casino, a scam-gambling ("scambling") operation, and, in a further subset, China-aligned espionage infrastructure. Since 2023, China-aligned APT groups have used exactly that resemblance to hide PeckBirdy C2 domains inside gambling sites that look, and mostly are, harmless in the routine sense. At a tracked base of roughly 1.7 million such sites, which Infoblox says also support North Korean money laundering and tax avoidance, the ecosystem is large enough that a blanket dismissal leaves a real gap.

Who it affects

Enterprise security teams are the direct audience: Infoblox says just over 3 percent of its own enterprise customers have resolved at least one PeckBirdy C2 domain, meaning the framework is already reaching real corporate networks, not a hypothetical. Employees who visit these sites from work devices are the entry point the report describes. It also names the hosting side: Amazon, Microsoft, Cloudflare and Google, whose infrastructure the report says still carries some of these domains through what it calls account theft and "infrastructure laundering" at companies such as Funnull. More broadly, the UNODC's July 2026 report ties the same shared-infrastructure pattern to a wider online-scam economy it says caused $88.3 billion to $114.1 billion in losses in 2025 across East Asia, Southeast Asia, Australia and New Zealand.

How to use it

Infoblox's advice is procedural. When a Chinese-language casino or adult domain triggers an alert, the report says not to close it as a routine employee browsing violation without a check. PeckBirdy is loaded through compromised sites as a script-based framework and has been used to serve fake software-update pages designed to get victims to download malware, so treating a repeat hit on these domains as routine noise is, per the report, precisely the outcome the operators are counting on. Analysts reviewing suspicious network contacts are advised to check whether a flagged domain carries a malicious payload before closing the ticket.

How solid is it

The claims come from a vendor threat report by Infoblox, the security firm that conducted the research, presented through staff researcher Zach Edwards and the report's own quoted text. The PeckBirdy framework itself was first identified independently by Trend Micro researchers, cited here only as "in January" with no year given. The account-theft explanation for why Amazon, Microsoft, Cloudflare and Google infrastructure still appears tied to these domains is offered as "one likely explanation," not a confirmed cause, and the article does not say whether those four companies were asked for comment or took any action. The only quantified measure of PeckBirdy's reach, just over 3 percent, comes from Infoblox's own customer base rather than an independently verified count across the wider internet, and no specific domain, C2 address or compromised organization is named.

Risks and caveats

The report ties the casino sites to "North Korean money laundering" and calls the APT groups "China-aligned," but no Chinese or North Korean government body is named or officially blamed; that is a characterization, not a state attribution. The $88.3 billion to $114.1 billion scam-loss figure comes from a separate UNODC report on the broader online-scam economy, not from PeckBirdy or from Infoblox's own data, and should not be read as the cost of this specific campaign. And because the underlying sites "change frequently," per the report, any defensive signature or domain list built from this research is likely to have a short shelf life.

“The most important thing for defenders to do is stop ignoring casino domains.”

— Infoblox