HomeSecurityChinese cybercrime network: Gambling and human trafficking

Chinese cybercrime network: Gambling and human trafficking

A Chinese organized crime network linked to money laundering and human trafficking in Southeast Asia is using an advanced "technology suite" to manage its entire supply chain online.

Chinese network Ponymuah

Infoblox tracks the owner and operator, known as Vigorish Viper, noting that this gang was developed by the Yabo Group (also known as Yabo Sports), which has been linked to illegal gambling activities and pig butchering scams in the past. In late 2022, it was renamed Kaiyun Sports and has since been incorporated into a new entity called Ponymuah.

See also: New malicious packages revealed in NuGet Supply Chain Attack

The gang, known in China as “baowang” (“包网,” meaning complete package), includes various components such as domain name system (DNS) configurations, website hosting, payment mechanisms, advertising, and mobile applications.

This operation secures sponsorships from European football clubs, using front companies or white label brands as a “force multiplier” to promote illegal gambling websites, aiming to attract more players. In July 2023, it was reported that the logos of these betting companies appeared up to 3,500 times during a televised football match.

Yabo Group, Ponymuah and other related offshoots such as OB (aka OBGM), DB Gaming, Panda Sports, KM Gaming and Smart King Games (SKG) are part of Vigorish Viper’s extensive network. This highlights the confusing and murky ownership of gambling companies and the careful steps taken to circumvent scrutiny.

It is not just English football clubs that are involved in these sponsorships. The investigation revealed that cricket and kabaddi teams in India have also entered into similar sponsorship deals to promote Vigorish Viper brands.

The Vigorish Viper network manages over 170,000 active domain names, evading detection and law enforcement through sophisticated DNS CNAME traffic distribution systems, Infoblox researchers Maël Le Touz, Jacques Portal, Renée Burton, and Elena Puga report in a detailed report shared with The Hacker News.

“In addition to gambling, Vigorish Viper’s CNAME traffic distribution systems serve illegal streaming and pornography websites. Some of the domains used for streaming are long-term registered domains that Vigorish Viper seized after the original registration expired,” the researchers explain.

Renée Burton, vice president of threat intelligence at Infoblox, described the threat actor as “one of the most sophisticated and significant cybersecurity threats discovered to date.” According to Burton, “Vigorish Viper has created a complex infrastructure with multiple layers of traffic distribution systems (TDS) using DNS CNAME records and JavaScript, making it extremely difficult to detect. These systems are complemented by encrypted communications and custom applications, making their operations not only elusive but also extremely resilient.”

The technique used by Vigorish Viper involves redirecting traffic via DNS CNAME records, a method previously used by other DNS attackers such as Savvy Seahorse. In addition, the system can differentiate between residential, mobile, and business IP addresses in China.

Read more: China: Preparing a spacecraft to crash into an asteroid

In January, the Danish Institute for Sports Studies’ “Play the Game” initiative uncovered links between dozens of European football clubs and illegal gambling brands related to Yabo and targeting regions such as China, where gambling is banned and considered organized crime.

Cybercrimes are not limited to the digital realm. They also include human trafficking, where individuals are lured with the promise of high-paying jobs and forced to support sports betting schemes and promote scams such as “pig butchering” and other cryptocurrency scams, according to the Asian Horse Racing Federation (ARF).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Operating in teams of 8-10 people, some coordinate with commentators and broadcasters for live sporting events (often via pirate channels) to promote live streaming groups that advertise betting sites during matches, according to a report [PDF] published by the ARF in October 2023. Others act as relationship managers, encouraging customers to continue betting, while some act as customer recruitment agents.

Infoblox reported that its investigation into Vigorish Viper originated from a single suspicious domain, kb[.]com, a gambling website called KB Sports that uses Chinese name servers and also hosts yabo[.]com, which is the domain for Yabo Sports.

An interesting observation is that the website is geo-blocked for users in France and other European countries, while remaining accessible from China and the special administrative regions of Hong Kong and Macau. “When the user visits from one of these regions, they are redirected to another domain, such as kb830[.]com,” the researchers note. “The redirect domain changes periodically, and all right-click and text selection functions are disabled, preventing attempts to explore or copy the website.”

Users of the site see advertisements promoting financial incentives for regular betting, along with a variety of payment options, including WeChat Pay, EBpay, Alipay, JD Pay, KOIPay, AstroPay, YunShanFu, UniPay, Net Pay, Fast Pay and NetBank. Bets are placed through agents, who handle deposits and communicate with players via personalized, encrypted chat apps.

A thorough analysis of DNS logs revealed that Vigorish Viper’s activities extend beyond China’s borders, targeting users around the world. Some of the defense mechanisms built into these sites include regular checks for signs of automated activity and displaying CAPTCHA puzzles to visitors to prevent potential attempts to scan or contact customer support. This operation is performed by individuals who have been trafficked in Southeast Asia.

Chinese network

However, these efforts don't stop there. Users visiting Vigorish Viper branded domains are subjected to multiple fingerprint checks to confirm that their IP address is in China and legitimate, before they are allowed to bet on the sites.

See also: Chinese cyber espionage targets telecom operators in Asia from 2021

“Both the DNS and software link the entire Vigorish Viper business to Yabo Sports or Yabo Group,” the company said. “Their influence extends to dozens, if not hundreds, of brands and targets users beyond Southeast Asia.”.

"Despite the vast number of domain names, websites, and companion applications, and their obvious public presence, Vigorish Viper operates openly and inexplicably in the PRC without any significant consequences.".

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS