The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Gambling/Casinos
Breach intelligence, attack campaigns, and threat reports targeting the Gambling/Casinos sector.
Explore Other Sectors
Gambling/Casinos Threat Reports
Aisuru/Kimwolf Botnet's Unprecedented 31.4 Tbps DDoS Attack in 2025
In December 2025, the Aisuru/Kimwolf botnet launched a record-breaking distributed denial-of-service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and 200 million requests per second. This unprecedented assault targeted multiple companies, primarily in the telecommunications sector, and Cloudflare's own infrastructure. The attack, part of a campaign dubbed "The Night Before Christmas," was successfully mitigated by Cloudflare's automated systems, preventing significant disruptions. ([techradar.com](https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it?utm_source=openai)) This incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the urgent need for robust cybersecurity measures. The rapid growth of botnets like Aisuru/Kimwolf, which exploit vulnerabilities in IoT devices, poses a significant threat to global internet infrastructure. ([tomshardware.com](https://www.tomshardware.com/service-providers/network-providers/botnet-smashes-ddos-traffic-record-at-31-4-tb-s-equivalent-to-streaming-2-2-million-netflix-4k-movies-at-once-attack-was-large-enough-to-take-entire-countries-offline?utm_source=openai))
7 months ago
Kill Chain
China-Backed PeckBirdy APT Orchestrates Cross-Platform Attacks in 2024
In early 2024, the China-linked threat group dubbed 'PeckBirdy' orchestrated sophisticated cross-platform cyberattacks against Asian government entities and gambling platforms. Utilizing the JScript C2 framework, the attackers deployed new backdoors to penetrate both Windows and Linux systems, enabling remote command execution and persistent access. The dual-campaign approach demonstrated PeckBirdy's flexibility, targeting sectors with rich data and financial value. The initial compromise was achieved via spear-phishing emails and exploit delivery, followed by lateral movement to critical systems. Exfiltration of sensitive data and ongoing espionage activities resulted in operational disruptions and an increased risk of regulatory exposure for targeted organizations. This incident underscores the evolving nature of state-sponsored APT operations, notably the growing crossover between espionage and financially-motivated attacks. PeckBirdy's toolset and cross-platform reach reflect a trend where threat actors innovate rapidly, blending custom malware with proven C2 tactics, raising the stakes for defenders in Asia and beyond.
7 months ago
Kill Chain
DraftKings 2025 Credential Stuffing Breach: Lessons in Password Security
In October 2025, DraftKings, a prominent sports betting company, disclosed that less than 30 customer accounts were compromised via credential stuffing attacks. Threat actors utilized previously stolen username and password combinations from breaches of unrelated services, leveraging automated tools to gain unauthorized access to DraftKings user accounts. While the attackers obtained personal data such as names, addresses, dates of birth, contact details, and the last four digits of payment cards, there was no evidence of access to sensitive government-issued IDs or full financial account numbers. DraftKings responded swiftly by notifying affected users, requiring password resets, and recommending the use of multifactor authentication to mitigate further risk. This incident highlights the persistent threat of credential stuffing—an attack vector that exploits widespread password reuse. With large troves of leaked credentials available and automated attack tools on the rise, organizations across industries face increasing regulatory pressure to implement layered authentication and robust account monitoring to defend against identity-driven threats.
8 months ago
Kill Chain
Teen Hacker, Scattered Spider, and the 2023 Vegas Casino Ransomware Crisis
In late summer and early fall 2023, Las Vegas casinos MGM Resorts and Caesars Entertainment suffered major cyberattacks conducted by the Scattered Spider threat group, including at least one 17-year-old suspect. Attackers gained network access via social engineering and lateral movement, ultimately deploying BlackCat/ALPHV ransomware. The incidents led to severe operational disruption, significant financial losses exceeding $100 million for MGM, a $15 million ransom paid by Caesars, and exposure of sensitive customer and employee data. Law enforcement identified and apprehended one teenage perpetrator, who was later released to parental custody pending trial. This high-profile case highlights the growing trend of sophisticated, identity-driven ransomware attacks launched by younger, tech-savvy threat actors and hacking collectives. It underscores the urgent need for organizations to close internal security gaps, improve zero trust posture, and address the challenges of compliance amid increasingly aggressive and disruptive ransomware campaigns.
8 months ago
Kill Chain
Boyd Gaming 2023 Data Breach Exposes Employee Information
In October 2023, Boyd Gaming Corporation, a major US gambling and casino operator, disclosed a data breach after threat actors infiltrated its network, stole sensitive data, and caused disruptions to company operations. The attackers gained unauthorized access to internal systems and exfiltrated data belonging to employees and a limited number of other individuals. While Boyd Gaming acted promptly to contain the incident and launched a forensic investigation, the breach led to operational disruptions and the exposure of personal information. The company notified regulators and affected individuals and engaged law enforcement in response efforts. This incident is significant due to the continued targeting of the gaming and hospitality sector by ransomware groups and other cybercriminals seeking valuable data. It also highlights the challenges organizations face in defending against complex threat tactics, and underscores the importance of robust security measures and employee data protection amid rising regulatory scrutiny.
8 months ago
Kill Chain
Teen Arrested in 2023 Las Vegas Casino Ransomware Attacks Linked to Scattered Spider
In late 2023, Las Vegas casinos suffered major cyberattacks attributed to the Scattered Spider threat group, resulting in widespread operational disruption. The attacks targeted MGM Resorts International and Caesars Entertainment, leveraging sophisticated social engineering and phishing tactics to gain network access, move laterally, and ultimately extort ransom payments. MGM reported losses exceeding $100 million, while Caesars reportedly paid $15 million to mitigate risks. In June 2024, a local teenage suspect was arrested in connection to these events, highlighting the involvement of young, native English-speaking cybercriminals and a broader international law enforcement response. This incident exemplifies the increasing prevalence of highly organized, technology-savvy ransomware and extortion campaigns that rely on social engineering and identity-centric attack vectors. Organizations across industries face rising risks as threat groups adopt coordinated, multifaceted tactics to exploit internal and hybrid cloud environments.
8 months ago
Kill Chain
Gambler Panel: The Rise of Affiliate-Driven Scam Gambling Operations in 2025
In July 2025, researchers uncovered a rapid proliferation of fraudulent online gambling platforms connected to a Russia-based affiliate operation called 'Gambler Panel.' This scheme enables thousands of affiliates to launch polished scam gambling sites using a turnkey fake casino engine and aggressive social media lures—often involving fraudulent endorsements and false claims of free credits. Victims are tricked into making cryptocurrency 'verification deposits' which are subsequently stolen, with attempts to cash out consistently denied. The operation is highly organized, offering detailed playbooks and infrastructure supporting over 1,200 domains run by a network of more than 20,000 affiliates. This incident highlights a new, scalable model for financial fraud: cybercriminals outsourcing risk and execution to large affiliate networks via sophisticated, multi-platform campaigns. The case underscores the dangers posed by accessible, turnkey scam infrastructure and the challenges organizations face in monitoring affiliate-driven threat activity targeting consumers globally.
8 months ago
Kill Chain
Rapper Bot: How a 2025 IoT DDoS-for-Hire Botnet Fueled Global Extortion
In August 2025, Ethan J. Foltz of Springfield, Oregon was arrested and charged with operating 'Rapper Bot,' a global botnet composed of approximately 65,000 compromised Internet of Things (IoT) devices. Foltz and an unidentified partner rented the botnet to extortionists, enabling massive distributed denial-of-service (DDoS) attacks—some surpassing six terabits per second—that disrupted services including Twitter/X and targeted various global networks, with victims concentrated in China, Japan, the United States, Ireland, and Hong Kong. The botnet, inspired by fBot/Satori and Mirai code, launched over 370,000 attacks against 18,000 unique victims between April and August 2025. Investigators traced the operation through hosting records, PayPal, and Telegram chats, ultimately apprehending Foltz and tying the extortion activities to the U.S. Department of Defense network attacks. This breach underscores the ongoing threat posed by commercially operated, IoT-based DDoS-for-hire services, which enable large-scale attacks while evading detection through careful operational security and botnet size management. As extortion tactics and DDoS capabilities evolve, organizations across industries face increasing pressure to implement resilient network defenses and real-time threat visibility.
8 months ago
Kill Chain
GhostRedirector: Chinese SEO Poisoning Attack Hits Global IIS Web Servers (2024)
In August 2024, a cybercrime group tracked as "GhostRedirector" conducted a widespread SEO poisoning campaign targeting Windows web servers across Brazil, Vietnam, Thailand, and several other regions. The attackers exploited unpatched SQL injection vulnerabilities to gain initial access and deployed custom malware, including Rungan (a C++ backdoor) and Gamshen (a malicious IIS server extension), to maintain persistence and manipulate web content. The campaign's main tactic was to covertly inject links into compromised legitimate websites, boosting the search engine rankings of gambling sites favored by the threat actors. Affected sites span diverse sectors without clear industry targeting, complicating defense strategies. The incident illustrates the persistent risk posed by native IIS module malware and the ongoing evolution of China-based threat actors using advanced web server exploitation and SEO manipulation tactics. Its relevance is heightened by increased attacker interest in manipulating search engine results to drive illicit business revenue and evade detection by blending with legitimate site infrastructure.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports