Suncity Group is a Southeast Asia-linked transnational organized crime syndicate centered on illegal gambling, money laundering, underground banking, and cyber-enabled fraud. The organization has been described as a controlling entity behind other criminal operations including Baoying, also known as Vault Viper, and linked ecosystems such as Vigorish Viper. It has been associated with a broad criminal empire using legitimate-seeming fronts including casinos, hotels, and real-estate interests to conceal and support illicit activity. The group is closely associated with founder Alvin Chau, who was convicted on charges related to illegal gambling, organized crime, fraud, and money laundering. Suncity has been tied to large-scale illicit betting turnover in Macau and to proxy structures used to service criminal operators across East and Southeast Asia. Reporting links the organization to cyber scam-center activity, pig-butchering and romance fraud, phishing-enabled fraud, police impersonation scams, human trafficking, and laundering of criminal proceeds through underground financial networks. Suncity’s cyber-enabled ecosystem includes infrastructure and tooling attributed to subordinate or affiliated groups such as Vault Viper. Through these linked operations, the broader network has been associated with credential theft, keylogging, covert surveillance, persistent access on victim devices, code injection, proxying of victim traffic, and other malware-like behaviors delivered through custom software platforms. The organization and its affiliates have also been connected to DDoS activity against critics, rapid infrastructure rotation, encrypted communications, and other defense-evasion measures. Overall, Suncity is best understood as a sophisticated criminal enterprise whose dominant purpose is financial gain through gambling-related crime, fraud, laundering, and technology-enabled exploitation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suncity Group is a major Asian organized crime syndicate specializing in illegal gambling, money laundering, and cyber-enabled fraud. It has deep connections to other criminal groups (Vault Viper, Vigorish Viper), and has operated globally through a network of shell companies, online platforms, and proxies.
Suncity is a shadowy, Southeast Asia-based criminal organization that controls multiple cybercrime syndicates, including Vault Viper and Vigorish Viper. It is deeply involved in illegal gambling, organized crime, and large-scale cyber fraud operations globally.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.