Casino Lookalikes Hide Gambling, Scams and Cybercrime
Summary
New research from Infoblox Threat Intel indicates that seemingly identical Chinese-language casino websites hide diverse threats. The largest group consists of over 1.7 million domains facilitating illegal gambling and money laundering, with two major clusters (FUNNULL and Vigorish Viper) dominating. A second category, termed 'scambling,' targets English-speaking and global audiences to defraud users through rigged games or withdrawal blocks. A smaller, critical group uses these casino sites to embed command-and-control domains for the PeckBirdy framework, linked to China-aligned APT groups since 2023. The findings challenge the assumption that casino domains are low-priority, emphasizing that visual inspection alone cannot distinguish between a legitimate operation, a scam, or malware infrastructure, requiring defenders to look beyond the surface.
(Source:iTWire)