Home Business News Casino Lookalikes Hide Gambling, Scams and Cybercrime: Research from Infoblox Threat Intel

Casino Lookalikes Hide Gambling, Scams and Cybercrime: Research from Infoblox Threat Intel

The same casino-style page may support illegal gambling, defraud customers or conceal a command-and-control endpoint

DUBAI, UAE, September, 2026: New research from Infoblox Threat Intel shows that similar looking casino websites may mask very different risks – from illegal gambling and money laundering to consumer scams related to gambling or “scambling” and malware. Defenders should not dismiss Chinese-language casino domains as low-priority noise: on a similar-looking page the difference between a working casino, a scam and a malware command-and-control endpoint may not be visible in a browser.

The largest population in the research, Chinese-language casinos for illegal gambling and money laundering, includes more than 1.7 million casino domains. Infoblox Threat Intel tracks 16 clusters, with the two largest (FUNNULL and Vigorish Viper) accounting for roughly 81 percent of the tracked population. These sites often operate as real casinos, with working customer support and withdrawals, helping them retain players and deposits.

A second group of sites, referred to as “scambling”, presents itself as online gambling but is set up to defraud customers. The sites may rig games or prevent withdrawals through delays, fees and other tactics. The research shows these sites primarily target English-speaking audiences, but operators have also built sites aimed at people in Europe, South America and Asia.

The smallest group embeds PeckBirdy command-and-control domains in low-quality Chinese-language casino websites. PeckBirdy is a framework used by China-aligned advanced persistent threat (APT) groups since 2023. Just over 3 percent of enterprise customers in Infoblox telemetry resolved at least one related domain, and one domain had zero detections on VirusTotal as of August 31, 2026.

Together, these findings challenge a common assumption: that a casino domain is merely a low-value browsing or policy issue. The research shows that defenders need to assess what sits behind the page before closing an alert, because the visible content alone cannot reliably distinguish gambling from fraud or malware. Zach Edwards, Staff Threat Researcher at Infoblox said: “The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review.”

About Infoblox Threat Intel:

Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet’s inner workings allows us to track down threat actors that others can’t see. We’re proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox DNS Detection and Response solutions, so customers automatically get its benefits, along with ridiculously low false positive rates. 

About Infoblox:

Infoblox is a leading platform for preemptive security and hybrid, multi-cloud networking that delivers enterprise resilience and agility. Trusted by over 5,700 customers, including the majority of Fortune 100 companies as well as emerging innovators, we seamlessly integrate, secure and automate critical network services so businesses can move fast without compromise. 

Exit mobile version