Infoblox Threat Intel research has identified more than 1.7 million Chinese-language casino domains, warning that visually similar websites can conceal activities ranging from illegal gambling and fraud to malware command-and-control infrastructure.
Casino-style websites that appear similar to users and cybersecurity teams can conceal significantly different threats, including illegal gambling, money laundering, fraud and malware infrastructure, according to research from Infoblox Threat Intel.
The research identified more than 1.7 million Chinese-language casino domains associated with illegal gambling and money laundering, making this the largest category examined.
Infoblox Threat Intel tracks 16 clusters within this group, with the two largest, FUNNULL and Vigorish Viper, accounting for approximately 81% of the tracked domains.
According to the researchers, many of these sites operate as functioning online casinos, including providing customer support and allowing withdrawals, helping operators retain players and deposits.
A second category identified by the research involves what Infoblox calls ‘scambling’ – websites presented as online gambling operations but designed to defraud customers.
These sites can use tactics including rigged games or preventing customers from withdrawing funds through delays, additional fees and other measures. While they primarily target English-speaking audiences, Infoblox identified sites targeting users across Europe, South America and Asia.
Researchers also identified a smaller group of low-quality Chinese-language casino websites containing PeckBirdy command-and-control domains.
PeckBirdy is a framework that Infoblox said has been used by China-aligned advanced persistent threat groups since 2023. Just over 3% of enterprise customers represented in Infoblox telemetry resolved at least one related domain.
The company also found that one of the identified domains had no detections on VirusTotal as of August 31, 2026.
“The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review,” said Zach Edwards, Staff Threat Researcher at Infoblox.


