Cybernews Chinese Casino Websites Conceal PeckBirdy Malware, Infoblox Reports
Article Content
- •Over 1.7 million Chinese-language casino sites linked to illegal activities identified.
- •PeckBirdy malware used against Asian corporate and government targets is concealed within these sites.
- •Security teams are urged to treat casino domains as potential threats, not just low-priority sites.
Infoblox has identified over 1.7 million Chinese-language casino websites linked to illegal gambling and malware distribution. These sites are used to conceal PeckBirdy malware, which targets corporate and government entities in Asia. Attackers employ tactics such as fake software update pages and compromised websites to trick victims into downloading malware. The malware infrastructure is supported by US cloud providers, raising cybersecurity concerns. Infoblox emphasizes that many security teams overlook these domains, treating them as low priority. The report highlights the need for increased scrutiny of casino and adult websites due to their potential as command-and-control (C2) infrastructure. PeckBirdy has been associated with China-aligned advanced persistent threat (APT) groups since 2023. The research also notes that some casino sites operate as legitimate online casinos, complicating the threat landscape.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track PeckBirdy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…