Wednesday, May 7, 2025
HomecryptocurrencyThreat Actors Compromise 150,000 Websites to Promote Chinese Gambling Platforms

Threat Actors Compromise 150,000 Websites to Promote Chinese Gambling Platforms

Published on

SIEM as a Service

Follow Us on Google News

A large-scale cyberattack has compromised approximately 150,000 legitimate websites by injecting malicious JavaScript to redirect visitors to Chinese-language gambling platforms.

The campaign, first detected in February 2025 with 35,000 infected sites, has since expanded significantly, leveraging obfuscated scripts and iframe injections to hijack browsers.

Chinese Gambling Platforms
injected pages

Attackers use domains like zuizhongyj[.]com to host payloads, which display full-screen overlays mimicking legitimate betting sites such as Bet365.

- Advertisement - Google News

Technical Tactics

The threat actors employ HTML entity encoding and hexadecimal obfuscation to hide malicious scripts, such as injecting <script> tags disguised as benign code.

Decoded scripts reveal redirects to gambling domains like 551007t[.]cc and W88in[.]com, targeting Chinese-speaking users in China, Hong Kong, and the U.S.

The payloads enforce mobile-friendly viewports and use keyword detection (e.g., “bet365” or “太阳城”) to tailor redirects.

Chinese Gambling Platforms
redirect URLs

Broader Implications

According to the Report, this campaign mirrors other malicious operations, including GoDaddy’s disclosure of the DollyWay World Domination malware, which compromised 20,000 sites since 2016.

Experts warn of rising client-side attacks, urging website owners to audit scripts, monitor for unauthorized iframes, and implement strict Content Security Policies (CSPs).

Are you from SOC/DFIR Teams? – Analyse Malware, Phishing Incidents & get live Access with ANY.RUN -> Start Now for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

SpyCloud Analysis Reveals 94% of Fortune 50 Companies Have Employee Data Exposed in Phishing Attacks

SpyCloud, the leading identity threat protection company, today released an analysis of nearly 6...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...