Home » Emerging Technologies » Cyber Security » Casino Domains Mask Scams and Cyber Threats
News Desk -

Share

New research from Infoblox Threat Intel reveals that lookalike casino domains can hide very different risks. Furthermore, the same casino-style page may support illegal gambling, defraud customers, or conceal a command-and-control endpoint. As a result, defenders should not dismiss Chinese-language casino domains as low-priority noise. On a similar-looking page, the difference between a working casino, a scam, and a malware command-and-control endpoint may not be visible in a browser.

According to the research, the largest population of casino domains involves Chinese-language sites used for illegal gambling and money laundering. This group alone includes more than 1.7 million casino domains. Infoblox Threat Intel tracks 16 clusters in total. Notably, the two largest, FUNNULL and Vigorish Viper, account for roughly 81 percent of the tracked population. Interestingly, these sites often operate as functioning casinos, complete with working customer support and withdrawals. This helps them retain players and deposits over time.

Meanwhile, a second group of sites, referred to as “scambling,” presents itself as online gambling but is instead set up to defraud customers. In these cases, the sites may rig games or block withdrawals through delays, fees, and other tactics. The research shows these sites primarily target English-speaking audiences. However, operators have also built similar platforms aimed at people in Europe, South America, and Asia.

Additionally, the smallest group in the study embeds PeckBirdy command-and-control domains within low-quality Chinese-language casino websites. PeckBirdy is a framework that has been used by China-aligned advanced persistent threat (APT) groups since 2023. Just over 3 percent of enterprise customers in Infoblox telemetry resolved at least one related domain. Strikingly, one such domain had zero detections on VirusTotal as of August 31, 2026.

Taken together, these findings challenge a common assumption: that a casino domain is merely a low-value browsing or policy issue. Instead, the research shows that defenders need to assess what sits behind the page before closing an alert, since visible content alone cannot reliably distinguish gambling from fraud or malware.

“The visual similarity is the point,” said Zach Edwards, Staff Threat Researcher at Infoblox. “A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review.”

The full research outlines practical actions defenders can take against these threats. It is available here.

In summary, this research underscores that casino domains cannot be judged by appearance alone. Ultimately, distinguishing legitimate operations from scams and cyber threats requires deeper investigation, not just a glance at the page.