SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Infoblox warns of scam gambling risks in ANZ traffic

Infoblox warns of scam gambling risks in ANZ traffic

Wed, 16th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Infoblox has published research on scam gambling websites and related cybercrime risks, including traffic from Australia and New Zealand.

The findings describe a broad ecosystem of casino-style websites that can serve different purposes behind similar-looking pages, including illegal gambling, customer fraud, money laundering and malware operations. A site's appearance often does not reveal which function sits underneath.

The research identified more than 1.7 million Chinese-language casino domains in what Infoblox described as the largest population in its study. It tracks 16 clusters in total, with the two biggest, FUNNULL and Vigorish Viper, accounting for roughly 81 per cent of the tracked population.

Many of the largest sites operate as functioning casinos rather than simple fake pages. Users may encounter working customer support and successful withdrawals, helping operators attract deposits while masking other suspected activity such as illegal gambling or money laundering.

A separate category, which Infoblox calls "scambling", is designed to imitate legitimate online gambling while defrauding users. These sites may rig games or block withdrawals through delays, fees or similar tactics. They appear to focus mainly on English-speaking audiences, while also extending into parts of Europe, South America and Asia.

The Australia and New Zealand element of the research points to a smaller but still notable stream of attempted connections. In a region where gambling losses are already high, the findings suggest scam sites may be adding a hidden layer of financial harm that is harder to measure than losses on regulated or recognised platforms.

Customer telemetry showed repeated attempts to reach both scam gambling domains and illegal gambling sites from Australia and New Zealand. Some visits likely begin with spam links or online promotions, while others may result from redirects that send users to a gambling page when they are trying to view unrelated content.

Those redirects are linked in the research to malicious advertising technology, also known as Traffic Distribution Systems. These systems can route web traffic from illicit sources and push users towards low-quality or harmful content, including scam gambling pages, using compromised websites, hijacked routers, parked domains and typo-squatting domains.

The study also examined a smaller, more overtly security-focused group of domains. In these cases, low-quality Chinese-language casino websites were used to embed PeckBirdy command-and-control domains, linking the gambling-themed pages to malware infrastructure rather than only financial crime.

PeckBirdy has been used by China-aligned advanced persistent threat groups since 2023, according to Infoblox. Just over 3 per cent of enterprise customers in its telemetry resolved at least one related domain, while one domain had no detections on VirusTotal at the time measured in the research.

Hidden risks

The overlap between fraud, illegal gambling and cyber operations is a central theme in the report. A site that looks like a routine gambling domain may actually be taking deposits illegally, preventing withdrawals or acting as a cover for malware communications, making it harder for security teams to judge the risk from a browser view alone.

That matters because some defenders may treat gambling domains as low-priority policy violations rather than indicators of broader criminal infrastructure. Infoblox argues this assumption can lead security teams to dismiss alerts too quickly when the same domain patterns may point to scams or command-and-control activity.

For Australia and New Zealand, the figures suggest the number of distinct scam gambling domains seen in an average month is lower than the number of illegal gambling websites, but both categories remain present in customer traffic. The research does not put a value on losses tied specifically to scam gambling in the region, but frames the activity as part of a wider online fraud market aimed at consumers.

The report also included a comment on the regional traffic observed.

"In 2026 in an average month, we're seeing traffic from clients in Australia and New Zealand attempt to connect to about 10 unique scam gambling domains which likely steal money and over 100 illegal gambling websites, which also likely facilitate money laundering. We have seen very limited PeckBirdy activity in Australia and New Zealand so far this year, which is something we continue to closely monitor as this campaign scales up in 2026," said Zach Edwards, Staff Threat Researcher, Infoblox.

Edwards also addressed the challenge for security teams assessing gambling-themed domains.

"The visual similarity is the point. A defender can see a casino domain and reasonably treat it as low priority, while the same-looking infrastructure may hide a scam or a malware command-and-control endpoint. That ambiguity is exactly why casino domains deserve closer review," said Edwards.