China-backed APT groups are using low-quality Chinese-language casino and adult websites to mask their command-and-control infrastructure, which is part of the PeckBirdy malware framework. This tactic helps attackers blend malicious network activity into a vast ecosystem of suspicious gambling sites that many security teams might overlook as unwanted browsing or low-priority web traffic. Researchers discovered that PeckBirdy operators have been using this approach since at least 2023 to target corporate and government organizations across Asia.

Previous reports linked the framework to campaigns using living-off-the-land binaries, but the latest analysis shows that its operators are expanding the use of casino-themed decoy sites and Chinese-language adult portals.

This visual similarity provides attackers with cover because analysts might classify the traffic as a policy violation rather than investigate it as a potential intrusion. The first category supports illegal gambling and money laundering, while scam sites typically entice victims with bonuses but prevent withdrawals. A screenshot of a recently active site 11170011[.

]com, featuring “Venetian Macao” branding in English, is a classic illegal Chinese-language casino website with both casino games and “video games for money” – simple games with gambling mechanics added (Source: infoblox). Researchers track over 1.7 million Chinese-language casino domains, generating substantial amounts of web traffic, hosting activity, and domain churn that can obscure a small number of malicious APT-controlled sites.