News / § Scam watch

1.7 million casino domains: Infoblox maps the impersonation economy where takedowns chase drop-catch infrastructure

Scam watch By Ihor Makushinsky

On 15 September 2026 Infoblox Threat Intel published the most complete census yet of the illegal casino web: more than 1.7 million illegal Chinese-language casino domains, tracked across sixteen actor clusters. Two of them — the FUNNULL bulletproof CDN network and Vigorish Viper — hold roughly 745,000 and 666,000 domains, about 81% of the population; the top four actors account for 99.5% of every domain in the census.

Three businesses wearing the same skin

The research separates the ecosystem into three types that look identical in a browser and behave nothing alike. Type 1 is the 1.7-million-domain machine itself: working casinos, real customer support, real withdrawals — because deposits are the pipeline that transnational money laundering runs through. UNODC’s 2026 Southeast Asia threat assessment, which cites Infoblox’s earlier research, puts global illegal betting revenue at up to $1.7 trillion annually and describes the sector’s convergence with cyber-fraud, underground banking and human trafficking.

Type 2 is “scambling” — thousands of polished fraud casinos where the games are rigged or winnings simply never cash out, a wave Krebs on Security first documented in 2025 and which Infoblox says has doubled in some weeks of 2026. Type 3 is the strangest: dozens of casino decoy sites operated by China-aligned APT groups as camouflage for espionage command-and-control infrastructure.

The brands are victims too

For the iGaming industry the key line sits in the middle of the report: across these networks, real casino brands — including brands with a physical presence in Macau — appear on sites that have no connection to them. Infoblox states it plainly: most major casino brands found on these sites are being impersonated, and are victims too. Fake celebrity endorsements (a fabricated Steph Curry campaign among the examples), device-fingerprinting redirects and per-visitor hosting complete the picture: your brand onboards the depositor, the syndicate keeps the pipeline.

Why takedowns feel like losing

The report’s most uncomfortable finding for enforcement teams comes from UNODC: these operators maintain thousands of active domains and rotate to a new one whenever the current one is blocked, making one-at-a-time domain blocking “largely ineffective as a standalone measure”. The Philippines ordered more than 7,000 illegal gambling sites blocked in 2024 — UNODC’s description of the result is “practical futility”. Domains here are consumables, often live for days or weeks, frequently drop-caught or bulk-registered — while the durable layer is elsewhere: a handful of backend platform providers, DNS infrastructure clusters and payment processors serving thousands of seemingly independent brands. And, as Infoblox notes, much of this infrastructure is registered and hosted with US and European companies, often for long periods.

What this means for you

If you run a legitimate casino brand, the practical readings are three. First, your brand is almost certainly in this dataset somewhere — impersonation at this scale is a statistical certainty, and every fake site converting your brand equity into deposits is also feeding regulators’ perception of gambling as a scam economy. Second, chasing individual domains against a 1.7-million-domain machine is a losing game by design; wins come from targeting what persists — the CDN accounts, registrar relationships, payment rails and hosting clusters that four actors reuse across hundreds of thousands of sites. Third, the infrastructure’s US/EU footprint is the good news: bulletproof is a marketing term, not a legal one, and the providers these networks depend on answer to Western abuse processes, courts and regulators.

Counsel’s note. Most brands facing casino impersonation buy a monitoring feed, file complaints domain by domain, and watch the count go up anyway. That is exactly the game the operators designed. The working method is to treat every takedown as reconnaissance: each fake site names a registrar, a CDN account, a payment channel and a hosting cluster, and after a few dozen removals the map of shared infrastructure is the real deliverable — one abuse case against a CDN account outweighs a hundred against domains. We broke the method down in our guide to taking down casino clone websites and finding the real host behind Cloudflare.

Ihor Makushinsky, senior counsel at Lawyerd
Ihor Makushinsky

Senior counsel · in IP and compliance practice since 2014. The counsel's note in every item is his own.

Full counsel profile →