Infoblox tracks about 1.7 million Chinese‑language casino websites, and many of them are more than just low‑quality entertainment: they can be cover for malware, espionage, and complex laundering networks that reach into major U.S. cloud providers.
Infoblox's core findings
In a new report, Infoblox warns that a vast ecosystem of Chinese‑language gambling and adult sites is being used for illegal gambling, money laundering and, in some cases, as command‑and‑control (C2) infrastructure for malware. The company says the sites are difficult to distinguish from one another because they "tend to use variations of common templates in terms of design and function," and often behave like legitimate casinos, relying on the advantage of house odds to profit.
Zach Edwards, staff threat researcher at Infoblox, told colleagues the security community and media have largely ignored the category because "the story is complicated and confusing." Infoblox also reported that "just over 3 percent of its enterprise customers resolved at least one PeckBirdy C2 domain."
Infoblox framed the operational risk bluntly: "The most important thing for defenders to do is stop ignoring casino domains." The company cautioned that closing an alert on a Chinese‑language casino or adult domain as merely an employee browsing violation plays directly into attackers' tactics.
PeckBirdy: a hidden script framework
Infoblox says China‑aligned APT groups "have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low‑quality Chinese‑language casino websites." Trend Micro researchers previously noted in January that PeckBirdy is a script‑based framework attackers can load through compromised websites.
Infoblox described an observed campaign in which attackers injected scripts into gambling sites that loaded PeckBirdy and presented fake software update pages designed to entice victims into downloading malware. Because the compromised domains often look like ordinary casino or adult sites, routine analyst reviews can dismiss them as harmless.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadMajor U.S. hosting companies and "infrastructure laundering"
Infoblox reports that many of these sites rely on U.S. cloud providers for computing infrastructure. "Major US hosting companies (Amazon, Microsoft, Cloudflare, and Google) continue to host infrastructure associated with these domains," the report says.
One explanation offered is account theft at those providers — a practice Infoblox describes using the established term "infrastructure laundering." The report cites hosting operators such as Funnull, which have reportedly rented IP addresses from Amazon Web Services and Microsoft and made those resources available to clients carrying out illegal activities.
Regional financial impact and scam gambling ("scambling")
The scale of the problem extends beyond malware. A July 2026 report from the UN Office on Drugs and Crime (UNODC) that Infoblox cites documents a trend toward disparate crime syndicates sharing infrastructure for cybercrime. The UNODC estimated online scams resulted in between $88.3 billion and $114.1 billion in losses in 2025 across East Asia, Southeast Asia, Australia, and New Zealand.
Infoblox also flags a category of scam gambling, known as "scambling," where visitors can place bets but cannot withdraw winnings — a direct consumer fraud that dovetails with the broader laundering and illegal gambling ecosystem.
What this means for security teams, enterprises, and policymakers
- Security teams and technologists: Treat alerts for Chinese‑language casino and adult domains as potential indicators of compromise. Infoblox advises analysts to check whether these domains include malicious payloads before closing review tickets as mere browsing violations.
- Enterprises and procurement leaders: Monitor outbound DNS and web traffic for connections to the types of domains Infoblox describes and consider whether vendor or cloud‑provider accounts have weak controls that could enable "infrastructure laundering."
- Policymakers and regulators: The Infoblox account‑theft explanation and examples of rented IP space highlight a policy intersection between hosting platforms and criminal misuse; those looking at platform abuse may need to consider the mechanisms behind account theft and the resale or rental of cloud resources.
The practical lesson is plain: an alert dismissed as "employee browsing" may be exactly the cover attackers count on. As Infoblox emphasizes, the decoy works because "these domains genuinely are, most of the time, exactly what they appear to be." That ambiguity — combined with large numbers of near‑identical domains, third‑party infrastructure links, and known frameworks like PeckBirdy — makes routine triage decisions consequential.




