07.04.2025

Gambling iGaming

Chinese Hackers Compromised 150,000+ Websites to Serve Casino Ads


Chinese Hackers Compromised 150,000+ Websites to Serve Casino Ads

In late March, American cybersecurity company c/side published a report on a large-scale cyberattack in which over 150k websites were redirecting traffic to Chinese gambling resources. 

Attack Details

On February 20, c/side experts reported that 35,000 websites had been compromised by Chinese hackers using a malicious script. The affected pages offered users games at Chinese casinos. 

The attack targeted regions where Standard Chinese (Mandarin/Putonghua) is spoken, and on the final landing pages users were shown iGaming slots from the Kaiyun brand.

Notably, many sites on the list still display the placeholder left by the hackers. And the content substitution, apparently, is applied not only to users with Chinese IPs. 

On compromised sites, users mostly see targeted landing pages, but in some cases a message appears stating that access is blocked. Most likely, this is done to add credibility to the cloaking layers.

Kaiyun is not a licensed casino in China. Gambling is prohibited in the region, with the exception of special administrative regions such as Macau.

On March 26, c/side researchers recorded a new wave of attacks — the number of affected sites increased fivefold, surpassing the 150,000 mark. This time, the hackers added updated page variants but still use iframe injection to display a full-screen overlay in the browser. 

The hackers also created pages featuring design elements of well-known bookmakers such as Bet365. The iframe display doesn't raise suspicion among users, as there are no redirects. 


Most of the sites to which attackers are driving traffic from compromised resources have been flagged by Google and antivirus solutions as malicious. 

We tested several of the sites and found that most of them are indistinguishable from standard iGaming platforms. Registration went through without issues, and we were able to access personal accounts and game pages. 

Available deposit methods include Chinese Alipay and WeChat, as well as cryptocurrency. It's clear that the primary target GEO is China, but the attackers are also counting on deposits from other GEOs. 

A new address is generated for each deposit, making it impossible to trace transaction history on the blockchain. 

The gambling on the site mostly works without technical issues, though some slots are unavailable. It appears that the attackers are funneling traffic to a functioning "black" casino and earning a percentage of deposits. 

Traffic monetization schemes through iGaming offers can be quite unexpected. But there's another side to this story — even in GEOs as specific as China, gambling remains in demand.