Infoblox Threat Intel has uncovered a staggering 1.7 million Chinese-language casino domains that are linked to various forms of cybercrime, including illegal gambling and fraud. This alarming finding highlights the potential risks associated with visually similar websites that may mask malicious activities, ranging from money laundering to malware command-and-control operations.
Scope of the Threat
The research indicates that the majority of these domains fall into the category of illegal gambling and money laundering, making it the largest group identified in the study. Infoblox has categorized these domains into 16 clusters, with the two largest—FUNNULL and Vigorish Viper—accounting for approximately 81% of the tracked domains. Many of these sites function as legitimate online casinos, offering customer support and facilitating withdrawals, which helps operators maintain player engagement and deposits.
Scambling: A New Form of Fraud
In addition to traditional illegal gambling, Infoblox has identified a second category termed ‘scambling.’ These websites present themselves as online gambling platforms but are designed to defraud users. Tactics employed by these sites include rigged games and various obstacles to withdrawing funds, such as delays and hidden fees. While these scams primarily target English-speaking audiences, Infoblox has also noted sites aimed at users across Europe, South America, and Asia.
Emerging Malware Threats
The research further identified a smaller subset of low-quality Chinese-language casino websites that host PeckBirdy command-and-control domains. This framework has reportedly been utilized by China-aligned advanced persistent threat groups since 2023. Notably, just over 3% of enterprise customers represented in Infoblox telemetry resolved at least one related domain, indicating a concerning level of exposure.
“The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review,” stated Zach Edwards, Staff Threat Researcher at Infoblox.
As the Middle East continues to embrace digital transformation, the implications of such findings are significant. Cybersecurity teams in the region must remain vigilant against these evolving threats, particularly as online gambling becomes more prevalent. The potential for financial loss and data breaches underscores the need for enhanced scrutiny of seemingly innocuous domains.
For more details, visit Intelligent CISO.
Follow Cyber Warriors Middle East for further regional cybersecurity developments.



