Vault Viper is a financially motivated cybercriminal operation associated with Baoying Group, also known as BBIN and Business Group 1, a major Asian iGaming technology provider. The network has operated from the Philippines’ Clark Freeport and Special Economic Zone and maintains business interests spanning gambling technology, hotels, casinos, property development, investment entities, and offshore corporate structures. It is linked to illegal Chinese-language online gambling, money laundering, cyber-enabled fraud, pig-butchering scams, and human trafficking within the Southeast Asian organized-crime ecosystem. Vault Viper is linked to Vigorish Viper and has reported connections to the wider Suncity criminal enterprise. The group distributes Universe Browser through gambling websites. The Windows variant routes users’ web traffic through infrastructure in China and exhibits malware-like functionality, including covert background components, keylogging, code injection, network-configuration changes, screenshot collection, and persistent access. It uses virtual-machine checks, restricts browser settings and developer tools, and disables security features to hinder analysis and evade detection. Vault Viper maintains a large and rapidly changing domain and proxy infrastructure to support resilient distribution and operations. Its tooling and infrastructure enable surveillance, credential theft, data collection, and monetization of victims, alongside its gambling and fraud operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously documented Chinese-language gambling network whose apparently independent brands rely on concentrated backend platforms, DNS infrastructure, and payment-processing systems.
Threat cluster linked in the report through infrastructure and behavioral overlaps with a multilingual scam and Android banking trojan MaaS operation targeting victims across multiple continents.
Vault Viper is a cybercrime group operating a global DNS infrastructure supporting illegal gambling, money laundering, fraud, and human trafficking, using the Universe Browser malware to control victim systems and facilitate organized crime.
Cyber-enabled gambling/fraud ecosystem tied to Baoying Group/BBIN distributing a custom 'Universe Browser' that routes traffic via China-based servers and includes RAT-like surveillance capabilities; linked to large-scale scam operations in Southeast Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.