Vigorish Viper is a sophisticated Chinese organized-crime syndicate operating an integrated cybercrime supply chain for primarily Chinese-language illegal online gambling and associated financial flows. Identified publicly in 2024, the group has been linked to a large bulletproof content-delivery and hosting network, custom software, DNS configuration and domain-management services, mobile applications, encrypted communications, and payment systems. Its infrastructure supports illegal gambling, money laundering, and movement of funds from China and other Asian jurisdictions; it controlled roughly 666,000 active Chinese-language casino domains in a tracked ecosystem. Vigorish Viper is closely connected to Vault Viper and is assessed as part of the wider Suncity criminal enterprise. The syndicate is associated with Southeast Asia-based transnational organized crime and has links to cyber-enabled fraud ecosystems, although particular infrastructure overlaps with recruitment-fraud operations remain unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates one of the largest active Chinese-language casino-domain networks, using bulletproof CDN infrastructure to support illegal gambling and transnational money laundering.
Threat cluster previously associated with scam-center-linked cyber-enabled fraud activity; the report identifies infrastructure and behavioral overlaps between the Android banking trojan MaaS and activity attributed to this group, with links to the K99 Triumph City compound in Cambodia.
Vigorish Viper is a Chinese organized crime group specializing in illegal online gambling, cyber-enabled fraud, money laundering, and human trafficking. It operates a massive DNS and hosting infrastructure, leverages sports sponsorships for covert promotion, and is closely linked to other major criminal networks in Asia, including Vault Viper and Suncity Group.
Referenced as a previously uncovered named actor connected to illegal online activity in Southeast Asia, in the broader ecosystem surrounding gambling and cyber-enabled fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.