Full Report
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
Analysis Summary
# Threat Actor: PeckBirdy (Associated Framework/Campaign)
## Attribution & Identity
* **Actor Identification:** PeckBirdy is identified as a script-based framework utilized by China-aligned Advanced Persistent Threat (APT) groups.
* **Aliases/Associated Groups:** China-aligned APT groups (unnamed specific designations, but linked to broader Chinese state-sponsored activity).
* **Associated Entities:** Linked to "infrastructure laundering" services and criminal syndicates such as Funnull.
## Activity Summary
Infoblox reports that since 2023, PeckBirdy has been active within a massive ecosystem of approximately 1.7 million Chinese-language casino websites. While many of these sites are used for illegal gambling, money laundering (supporting North Korean interests), and tax avoidance, a specific subset is weaponized for cyber espionage. The PeckBirdy framework is injected into these low-quality sites to serve as a decoy for Command and Control (C2) operations and malware distribution, successfully compromising approximately 3% of Infoblox’s enterprise customers.
## Tactics, Techniques & Procedures
* **Infrastructure Laundering:** Rerouting traffic through reputable US cloud providers (AWS, Microsoft, Google, Cloudflare) via stolen accounts or third-party resellers to bypass reputation-based filters.
* **Web Injection:** Injecting script-based frameworks into compromised or purpose-built gambling/adult websites.
* **Social Engineering (Drive-by Downloads):** Displaying fake software update notifications to trick users into downloading malicious payloads.
* **Steganography/Decoy Traffic:** Hiding malicious C2 traffic within the high-volume noise of illegal gambling and adult content to exploit "alert fatigue" among security analysts.
* **MITRE ATT&CK Mapping (Inferred):**
* T1584.004 - Compromise Infrastructure: Server
* T1189 - Drive-by Compromise
* T1071.001 - Application Layer Protocol: Web Protocols
* T1036 - Masquerading
## Targeting
* **Sectors:** Enterprise organizations (broadly), including those with employees accessing prohibited entertainment content.
* **Geography:** Primarily targeting users in China, East Asia, Southeast Asia, Australia, and New Zealand.
* **Victims:** Over 3% of Infoblox enterprise customers were observed resolving PeckBirdy C2 domains.
## Tools & Infrastructure
* **Malware/Frameworks:** PeckBirdy (script-based framework).
* **Infrastructure Types:** Chinese-language gambling/casino templates, adult entertainment sites.
* **Domains (Defanged):**
* vip311[.]cc
* zzyud[.]com
* zenplay77-x[.]space
* **Hosting:** AWS, Microsoft, Cloudflare, and Google (via infrastructure laundering).
## Implications
The PeckBirdy campaign demonstrates a sophisticated convergence of traditional cybercrime (illegal gambling/money laundering) and state-aligned espionage. By utilizing "trash" domains that are often dismissed by SOC analysts as simple policy violations (HR/Acceptable Use Policy issues), the actors achieve high levels of persistence. This suggests a strategic shift toward using high-noise environments to mask high-value espionage operations.
## Mitigations
* **Advanced DNS Filtering:** Block or closely monitor resolutions of domains associated with illegal gambling and adult content, even if they appear to be non-malicious "noise."
* **SOC Process Adjustment:** Security analysts should not close alerts involving Chinese-language casino domains as simple "browsing violations" without checking for secondary malicious payloads or C2 traffic.
* **Endpoint Protection:** Implement robust browser security and EDR policies to detect and block fake software update prompts and unauthorized script executions.
* **Cloud Egress Monitoring:** Monitor for unexpected connections to major cloud provider IP ranges that correlate with high-risk domain categories.