Casino websites that look virtually identical can hide very different risks, from illegal gambling and money laundering to consumer scams and malware command-and-control infrastructure, according to Infoblox Threat Intel.
The largest group comprises more than 1.7 million Chinese-language casino domains linked to illegal gambling and money laundering. Infoblox tracks 16 clusters, with FUNNULL and Vigorish Viper accounting for about 81 per cent of the tracked population.
Many operate as genuine online casinos, complete with customer support and withdrawals, helping operators retain customers and deposits.
A second group, dubbed “scambling”, presents itself as gambling but is designed to defraud customers. Operators may rig games or block withdrawals using delays, fees, and other tactics. While primarily targeting English-speaking users, the sites also target audiences across Europe, South America, and Asia.
The smallest group embeds PeckBirdy command-and-control domains into low-quality Chinese-language casino sites. PeckBirdy has been used by China-aligned advanced persistent threat groups since 2023.
These scam casinos are also actively targeting Australian users.
“In 2026, in an average month, we’re seeing traffic from clients in Australia and New Zealand attempt to connect to about 10 unique scam gambling domains, which likely steal money, and over 100 illegal gambling websites, which also likely facilitate money laundering,” Zach Edwards, staff threat researcher at Infoblox, said in a statement
“We have seen very limited PeckBirdy activity in Australia and New Zealand so far this year, which is something we continue to closely monitor as this campaign scales up in 2026.”
Just over 3 per cent of Infoblox enterprise customers resolved at least one related domain, while one domain had zero detections on VirusTotal as of 31 August 2026.
“The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint,” Edwards said.
“That ambiguity is exactly why casino domains deserve closer review.”
Infoblox said the findings highlight the need for defenders to investigate the infrastructure behind casino domains rather than relying on visible website content to assess risk.
You can read the full research here.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.