Chinese-Language Casino Sites Used To Hide PeckBirdy Malware

Security researchers at the threat-intelligence firm Infoblox say a large number of Chinese-language online casino sites are being used to conceal PeckBirdy, a malware framework linked to China-aligned hacking groups that target corporate and government networks across Asia.
Infoblox told CyberNews and other outlets it tracks roughly 1.7 million Chinese-language casino sites facilitating illegal gambling, a subset of which also function as command-and-control infrastructure for espionage campaigns.
How PeckBirdy Hides Behind Gambling Sites
PeckBirdy is a script-based framework built in JScript that can run across a wide range of execution environments once loaded via a compromised site.
Infoblox says China-aligned advanced persistent threat (APT) groups have run the framework since 2023, embedding its command-and-control domains inside low-quality Chinese-language gambling and, increasingly, adult websites.
In some campaigns, attackers have injected scripts into gambling sites that load PeckBirdy and display fake software-update pages designed to trick visitors into downloading malware.
Researchers identified three casino domains carrying the infrastructure directly tied to a PeckBirdy command-and-control node.
Real Money Moves Through Fake-Looking Sites
Infoblox notes the sites in question often operate much like legitimate online betting sites, complete with customer support, even though online gambling has been banned in mainland China for decades.
Some genuinely process real, if illegal, wagers; others exist purely as set dressing around the malware infrastructure.
The report also flags that some of this infrastructure runs on mainstream US cloud providers, including Amazon, Microsoft, Cloudflare, and Google, which researchers suggest may indicate that compromised accounts are being repurposed rather than direct sign-ups - a pattern previously documented as "infrastructure laundering."
While You Are Here, Why Not Check Out Our: Casino Games Hub & Free Slots?
A Blind Spot For Corporate Security Teams
Infoblox's central warning is aimed at enterprise security teams: an alert triggered by an employee visiting a Chinese-language casino or adult site is often dismissed as a browsing-policy violation rather than investigated further, which the researchers say is exactly the outcome PeckBirdy's operators are counting on.
The firm says just over 3% of its enterprise customer base has resolved at least one PeckBirdy command-and-control domain, underlining how the technique quietly threads through corporate networks that would otherwise flag more obviously malicious traffic.



