Infoblox research finds casino-style domains can span illegal gambling, consumer scams and malware infrastructure, making visual inspection an unreliable security indicator
Casino-themed websites are emerging as an overlooked cybersecurity risk, with apparently similar domains potentially serving very different purposes from illegal gambling and money laundering to online scams and malware command-and-control infrastructure, according to research from Infoblox Threat Intel.
The scale of the activity makes these domains difficult for security teams to dismiss as simple browsing or policy violations. Infoblox tracks more than 1.7 million Chinese-language casino domains associated with illegal gambling and money laundering across 16 clusters. The two largest clusters, FUNNULL and Vigorish Viper, account for approximately 81% of the tracked population.
What makes the infrastructure particularly challenging is that many of these sites function as legitimate-looking casinos, complete with customer support and withdrawal mechanisms. Their operational appearance can therefore make them difficult to distinguish from other casino-themed domains through conventional browser-based inspection.
A separate category identified by Infoblox, described as “scambling,” uses gambling-style websites to defraud customers. Operators may manipulate games or prevent withdrawals through delays, additional fees and other tactics. While these sites primarily target English-speaking audiences, the research identifies activity targeting users across Europe, South America and Asia.
“The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint.” — Zach Edwards, Staff Threat Researcher, Infoblox
The smallest category presents a potentially more serious enterprise security concern. Infoblox identified PeckBirdy command-and-control domains embedded within low-quality Chinese-language casino websites. PeckBirdy has been used by China-aligned advanced persistent threat groups since 2023.
Infoblox telemetry found that just over 3% of enterprise customers resolved at least one related domain. Significantly, one identified domain had no detections on VirusTotal as of August 31, 2026, highlighting the limitations of relying solely on conventional reputation-based detection.
For defenders, the implication is that a casino domain cannot automatically be classified as low-priority traffic. Security teams need to investigate the infrastructure and behaviour behind such domains, particularly when DNS activity originates from enterprise environments.
The research reinforces the value of DNS-level threat intelligence in identifying infrastructure that may otherwise remain obscured behind familiar-looking web content.
