This report explains how illicit casino websites are used for illegal gambling, money laundering, scam gambling, and as decoys for PeckBirdy command-and-control infrastructure. It shows that China-aligned APT groups hide malware endpoints inside Chinese-language casino and adult sites, with domains like vip311[.]cc, cache-mcp[.]com, and mcp-source[.]online slipping past detection. #PeckBirdy #vip311[.]cc #cache-mcp[.]com #mcp-source[.]online
Keypoints
- Three distinct categories of malicious casino websites are identified: illegal Chinese-language casinos, scambling sites, and PeckBirdy decoy sites.
- Illegal Chinese-language casino infrastructure is massive, with more than 1.7 million domains used for gambling, money laundering, and related criminal activity.
- Two large actor clusters, FUNNULL CDN and Vigorish Viper, account for the vast majority of tracked Chinese-language casino domains.
- Scambling sites are designed to trap victims with bonuses and fake winnings, then prevent withdrawals through delays, fees, or broken systems.
- PeckBirdy uses low-quality Chinese-language casino and adult websites to conceal C2 domains for China-aligned APT operations.
- Some PeckBirdy-related domains show very low or zero detection on VirusTotal, including mcp-source[.]online.
- The report warns defenders not to dismiss casino or adult domains automatically, because they may hide espionage infrastructure.
MITRE Techniques
- [T1071.001 ] Web Protocols: PeckBirdy uses web-based infrastructure and WebSocket connections to communicate with C2 domains hidden behind casino and adult sites (‘live WebSocket connections use an additional domain, mcp-source[.]online’ and ‘a JS connection that is blocked from some automated scanners’).
- [T1055 ] Process Injection: Not mentioned directly in the article.
- [T1090 ] Proxy: The malware infrastructure is concealed behind decoy websites and domain redirection, masking the true C2 endpoints (‘hiding their malware C2 domains inside low-quality Chinese-language casino websites’ and ‘redirected to a final destination IP address’).
- [T1583.001 ] Acquire Infrastructure: Domains and hosting are purchased or controlled at scale to support criminal and C2 operations (‘controlling more than 10,000 domains’ and ‘spending an estimated $7 million on expired domains’).
- [T1585.001 ] Establish Accounts: The scambling ecosystem uses accounts and profiles to advertise domains across platforms (‘a fake account promoting the scambling domain dragobet[.]net on Zillow’).
- [T1566 ] Phishing: Not directly described as phishing, but the article describes deceptive sites used to lure victims with bonuses and fake legitimacy (‘deposit bonus’ and ‘official partner’).
- [T1491.001 ] Defacement: Not mentioned directly in the article.
- [T1027 ] Obfuscated Files or Information: The payload is hidden in JavaScript and service worker behavior that scanners may miss (‘registered a JS service worker’ and ‘Most web scanners won’t capture this behavior’).
- [T1105 ] Ingress Tool Transfer: The article describes loading a suspicious JavaScript payload from a remote domain (‘was loading a suspicious JavaScript payload from js.cache-mcp[.]com/layer.js’).
Indicators of Compromise
- [Domains ] Illegal Chinese-language casino, scambling, and decoy infrastructure – vip311[.]cc, cache-mcp[.]com, mcp-source[.]online, and other domains such as dollycasino[.]com and dragobet[.]net
- [Domains ] Scam gambling and marketing domains – appcasino[.]online, summer138[.]fit, storebet77[.]support, realz[.]com
- [Domains ] Additional Chinese-language casino lookalikes – 11170011[.]com, 1862[.]cc, asg78[.]com, githubassets[.]net
- [IP Addresses ] Supporting or redirected hosting for illegal Chinese-language casinos – 157[.]185[.]143[.]150, 146[.]103[.]91[.]133
- [URL Path ] Suspicious JavaScript payload location associated with PeckBirdy – js.cache-mcp[.]com/layer.js
- [Brands / Fake branding ] Impersonated or misleading casino/investment branding used on the sites – Venetian Macao, Point 72, KY casino, Joker, Google logo