#vigorishviper — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vigorishviper, aggregated by home.social.
-
Our team is out today with a new piece of research about how money laundering, scams, and espionage are hiding among millions of low-quality casino websites. We found a huge portion of these are using U.S. infrastructure for their attacks.
Our research sorts the casino sludge into three crimes that look nearly indistinguishable in a browser.
First, the 1.7 million illegal Chinese-language casino domains. These sites actually work. They have real games, real payouts, and responsive support, because the operators need you to keep depositing. These operators facilitate illegal gambling in China and other countries and are the backbone for an underground banking economy facilitating billions of dollars in money laundering annually. The known threat actors FUNNULL and Vigorish Viper run about 81% of these casino websites.
The second casino grouping comes from “scambling” – or scam gambling websites. On these sites you’ll see impossibly high deposit bonus, rigged games, withdrawals that never arrive, and operators who fold and relaunch one website after another. Since Brian Krebs wrote about these scambling sites last year, some weeks of 2026 had twice as many new sites as we saw in the same weeks last year.
The third grouping of casino sludge is likely the most important for most defenders – a C2 framework called PeckBirdy, which China-aligned APT groups have been running since 2023 inside disposable casino websites, because an analyst who sees a Chinese casino domain in DNS logs may ignore it or mark it benign. That dismissal is reasonable, but it’s also exactly what these threat actors are counting on.
One of the newest C2 domains for PeckBirdy, mcp-source[.]online, has zero detections on VirusTotal. Zero. It's reached over WebSocket, which most automated scanners never observe.
PeckBirdy has now moved the same “hide amongst the noise” trick onto Chinese-language adult sites, and in 2026 targeting expanded beyond government and education into basically every sector. Over 3% of our enterprise customers resolved at least one PeckBirdy C2, and the targeting in 2026 seems to be dramatically scaling up.
We've said it before and we’ll say it again: Stop ignoring casino domains. There are significant crimes occurring on these, and now APT groups are taking advantage of visibility and monitoring holes. Continue to ignore them at the peril of folks who count on your detections!
#dns @threatintel #infoblox #VigorishViper #FUNNULL #PeckBirdy #moneylaundering #gambling #scambling #casinos #chinaRead our newest research @ https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/