The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Gambling/Casinos
Breach intelligence, attack campaigns, and threat reports targeting the Gambling/Casinos sector.
Explore Other Sectors
Gambling/Casinos Threat Reports
Google Play Early Access Exploited: How Thousands of Deceptive Apps Bypassed Security
In September 2026, cybersecurity researchers discovered threat actors systematically abusing Google Play's Early Access program to distribute thousands of deceptive Android applications. These malicious apps promised financial rewards, casino winnings, and premium content while exploiting the program's feature that prevents user reviews and ratings. Notable examples included fake casino games and a Grand Theft Auto imitator called "Vice Streets: Open World" with over 1 million downloads. The attackers promoted these apps through social media platforms using AI-generated celebrity deepfakes, ultimately generating revenue through excessive advertising while never delivering promised payouts to users. This incident highlights the growing sophistication of mobile malware campaigns that exploit legitimate platform features to bypass traditional security mechanisms. The abuse of Early Access programs represents an emerging trend where attackers leverage regulatory gaps and user trust mechanisms to distribute deceptive applications at scale.
2 weeks ago
Kill Chain
Chinese Cybercriminals Transform Brazilian Government Servers Into Gambling Phishing Infrastructure
For over a year, the Chinese-language cybercriminal group Gambling Goblin has compromised approximately 30 Brazilian government and education servers to create a reverse-proxy network that boosts gambling phishing sites' search engine rankings. The attackers deployed Apache modules and Linux toolkits including backdoors, credential stealers, and downloaders to co-opt legitimate government domains' high reputation. While currently focused on gambling site promotion, the established infrastructure could easily be repurposed for malware distribution or lateral movement into connected government networks. The campaign demonstrates how Chinese cybercrime syndicates are expanding globally, leveraging AI translation capabilities to overcome language barriers and target Latin American organizations previously considered protected by local market complexities.
2 weeks ago
Kill Chain
Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors
The Chinese-speaking Gambling Goblin cybercrime cluster has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect visitors to attacker-controlled gambling and sports betting pages. The campaign leverages compromised high-reputation .gov.br domains to manipulate search engine optimization at scale, with modules reverse-proxying traffic while stripping security headers to allow malicious content execution. Linked to the Earth Berberoka threat group, the operation deploys sophisticated tooling including custom downloaders, modular backdoors, and credential stealers to maintain persistent access to government infrastructure. This incident highlights the growing trend of SEO manipulation attacks targeting government domains for cybercriminal profit, particularly as Brazil's newly regulated online betting market creates lucrative opportunities for threat actors to exploit trusted infrastructure for financial gain.
3 weeks ago
Kill Chain
OpenAI Disrupts Sophisticated Cambodian Social Engineering Network Using ChatGPT
In December 2024, OpenAI disrupted a sophisticated social engineering operation based in Cambodia that leveraged ChatGPT to conduct multi-faceted scams targeting victims globally. The network simultaneously operated fake dating profiles, fraudulent investment schemes involving cryptocurrency and gold trading, and impersonated law enforcement agencies demanding fine payments. The attackers used AI-generated content to create convincing personas and forged documents including passports, legal notices, and financial confirmations, demonstrating the scalability and effectiveness of AI-enhanced social engineering attacks. This incident represents a significant escalation in AI-powered threat campaigns, highlighting how readily available large language models are being weaponized by criminal networks to enhance traditional romance scams and financial fraud at unprecedented scale and sophistication.
4 weeks ago
Kill Chain
Cybercriminals Invest Millions in Expired Domains for Malicious Activities
In the first half of 2026, cybercriminals have increasingly exploited expired domains, known as 'dropcatch' domains, to conduct large-scale scams and malware distribution. By re-registering these domains, threat actors inherit their previous reputation and traffic, enabling them to evade detection and effectively target victims. Notably, the group 'Sable Squirrel' invested over $7 million to acquire more than 10,000 such domains, which they utilized for illegal streaming, online gambling, and as command-and-control servers for various malware families, including Quasar RAT and AsyncRAT. This trend underscores a significant shift in cybercriminal tactics, leveraging the residual trust of expired domains to facilitate malicious activities. The prevalence of this method highlights the urgent need for organizations to monitor and manage their domain portfolios proactively, ensuring that expired domains are not left vulnerable to exploitation. Additionally, it emphasizes the importance of enhancing detection mechanisms to identify and mitigate threats originating from re-registered domains.
1 month ago
Kill Chain
Europol's Crackdown on 'The Com' Network: 4,340 URLs Flagged for Removal
Between June and July 2026, Europol coordinated 'Referral Action Days' involving investigators from nine countries to target 'The Com,' a decentralized network of nihilistic violent extremist groups. This operation led to the identification and referral of 4,340 URLs containing content that promotes self-harm, child sexual exploitation, and violent attacks. The initiative aimed to disrupt The Com's online ecosystem and limit the dissemination of extremist propaganda. This crackdown underscores the persistent threat posed by decentralized extremist networks exploiting online platforms to radicalize and victimize individuals, particularly minors. The operation highlights the necessity for continuous international collaboration to monitor and mitigate the spread of such harmful content.
2 months ago
Kill Chain
Trojanized Newtonsoft.Json Package Targets Digitain's FG-Crash Game
In July 2026, cybersecurity researchers uncovered a malicious NuGet package named "Newtonsoftt.Json.Net," a typosquatted version of the legitimate Newtonsoft.Json library. This trojanized package specifically targeted Digitain's FG-Crash betting game by manipulating game results and exfiltrating rigged outcomes to an attacker-controlled server. The package was designed to function normally for other users, activating its malicious payload only within Digitain's environment. Seven versions of this package were published between August and October 2025, accumulating approximately 1,200 downloads before detection. The attack highlights the growing sophistication of supply chain attacks, where adversaries exploit trusted software repositories to distribute targeted malware. This incident underscores the critical need for developers to exercise caution when integrating third-party packages and to implement robust security measures to detect and prevent such threats.
2 months ago
Kill Chain
GoldenEyeDog Subgroup's Infiltration of DigiCert: A Wake-Up Call for Digital Trust
In April 2026, DigiCert, a leading Certificate Authority, experienced a security breach attributed to the CylindricalCanine subgroup of the GoldenEyeDog cybercrime group. The attackers infiltrated DigiCert's internal support portal by compromising two support analyst workstations through a malicious screensaver file delivered via a customer chat channel. This access enabled them to issue 27 fraudulent Extended Validation (EV) Code Signing certificates, which were subsequently used to sign malware, notably the Zhong Stealer, facilitating its distribution and evasion of security measures. The incident underscores the critical vulnerabilities within trusted digital infrastructure and the potential for widespread impact when such systems are compromised. ([thehackernews.com](https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html?utm_source=openai)) This breach highlights a concerning trend of cybercriminals targeting Certificate Authorities to obtain legitimate certificates for malicious purposes. The use of social engineering tactics to exploit support channels emphasizes the need for enhanced security protocols and employee training to prevent similar incidents in the future.
2 months ago
Kill Chain
Malicious SDKs on npm and PyPI Compromise Paysafe and Skrill Integrations
In July 2026, a coordinated supply-chain attack targeted developers integrating payment services by distributing at least 17 malicious packages on the npm and PyPI repositories. These packages masqueraded as legitimate SDKs for Paysafe, Skrill, and Neteller, aiming to steal sensitive credentials such as API keys, AWS keys, and GitHub tokens. The attackers employed typosquatting techniques, publishing packages with names closely resembling authentic ones, leading to unauthorized access and potential data breaches. This incident underscores the escalating threat of supply-chain attacks within open-source ecosystems. The attackers' ability to infiltrate multiple package managers simultaneously highlights the need for enhanced vigilance and security measures among developers and organizations to safeguard against such sophisticated threats.
2 months ago
Kill Chain
Massive Crypto Scam Operation Exploits DCloud Uni-App Framework
In June 2026, cybersecurity firm Infoblox uncovered that over 236,000 websites were utilizing investment scam templates built with the DCloud Uni-App framework. These sites facilitated a range of fraudulent activities, including fake cryptocurrency exchanges, phishing schemes, and crypto wallet drainers. The malicious domains spanned multiple continents and languages, indicating a coordinated effort by various threat actors. Notably, the RainbowEx platform, implicated in a Ponzi scheme affecting thousands in Argentina in late 2024, was among the identified domains. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai)) The exploitation of legitimate development frameworks like DCloud Uni-App underscores the evolving tactics of cybercriminals. This incident highlights the critical need for organizations to implement robust security measures, including thorough vetting of third-party tools and continuous monitoring for suspicious activities. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai))
2 months ago
Kill Chain
DraftKings 2022 Credential Stuffing Attack: A Case Study
In November 2022, DraftKings, a prominent fantasy sports and betting platform, experienced a credential stuffing attack that compromised approximately 60,000 user accounts. The attackers, led by Nathan Austad, known online as "Snoopy," exploited reused login credentials to gain unauthorized access. In about 1,600 cases, they added new payment methods to the compromised accounts and withdrew funds, resulting in approximately $600,000 in losses. The remaining compromised accounts were sold on cybercriminal marketplaces. Austad was sentenced to 18 months in federal prison, ordered to serve three years of supervised release, pay over $1.3 million in restitution, and forfeit an additional $463,000. This incident underscores the persistent threat of credential stuffing attacks, particularly in the online betting industry, where user accounts often contain sensitive financial information. It highlights the critical need for robust password policies, multi-factor authentication, and user education to prevent unauthorized access and financial losses.
3 months ago
Kill Chain
DraftKings 2022 Credential Stuffing Attack: A Case Study
In November 2022, DraftKings, a prominent sports betting platform, experienced a credential stuffing attack that compromised approximately 68,000 user accounts. Attackers exploited reused or weak passwords to gain unauthorized access, leading to the theft of nearly $300,000 from customer accounts. The company promptly reimbursed affected users and emphasized the importance of unique passwords and two-factor authentication to enhance account security. This incident underscores the growing threat of credential stuffing attacks, where cybercriminals leverage stolen credentials from previous breaches to infiltrate accounts on other platforms. The DraftKings case highlights the critical need for robust password practices and multi-factor authentication to mitigate such risks.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports