Gaming & Gambling — Cyber Threat Activity
Gaming and gambling holds no recorded incidents in our log, and the sector's real history sits almost entirely in vendor research instead. 14 groups carry a researched association with it, including APT41, Winnti Group, Earth Berberoka, DiceyF, Stormous and LAPSUS$, with 39 malware families linked through those actors. The sector is unusual because it is where a state-sponsored group has most clearly moonlighted for personal profit. Mandiant's analysis of APT41 describes an operator conducting Chinese state espionage against healthcare, telecommunications and higher education while separately using the same non-public tooling against the video game industry for its own gain: manipulating and stealing in-game virtual currency, taking game source code, and stealing code-signing certificates that were then reused to sign malware in unrelated operations. That last step is why gaming compromises matter well beyond gaming, since a stolen legitimate certificate buys trust on every platform that checks signatures. Game studios are also a supply-chain vector in their own right, with attackers reaching production environments and injecting malicious code into legitimate game files distributed to players. Gambling operators face a different mix, holding payment instruments, identity verification documents and high-value account balances, and running customer support functions that social-engineering crews target directly. Player accounts themselves sustain a large credential-theft economy that never appears in organisational incident data. Read the zero here as a limit of our collection, and the actor associations as published research on each group rather than attributions measured in our own corpus.
- Recorded incidents: 154
- Incidents, trailing 180 days: 5
- Tracked threat actors: 19
- Malware families: 40
Threat actors targeting Gaming & Gambling
- Coinbase Cartel 1 incident
- Fog Ransomware 1 incident
- INC Ransom 1 incident
- N0n 1 incident
- RansomHub 1 incident
- APT41 researched targeting
- Winnti Group researched targeting
- Stormous researched targeting
- LAPSUS$ researched targeting
- DiceyF researched targeting
- Earth Berberoka researched targeting
- Fail0verflow researched targeting
- FIN10 researched targeting
- FIN5 researched targeting
- GambleForce researched targeting
- Operation DRBControl researched targeting
- PIZZO SPIDER researched targeting
- Team-Xecuter researched targeting
- TheWizards researched targeting
Malware used against Gaming & Gambling
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- China Chopper Malware
- Empire Tool
- gh0st RAT Malware
- njRAT Malware
- PowerSploit Tool
- pwdump Tool
- ShadowPad Malware
Where these victims are
Recent incidents
- Vietnamese betting operator (GC789 network / Boundless TE) 2026-09-18
- Doğanay Ürgüplüoğlu 2026-08-02
- Atlas Menu 2026-05-30
- Reborn Gaming 2026-04-30
- SongTrivia2 2026-04-02
- ATG - New samples added 2026-03-15
- Divine Skins 2026-03-13
- Station Casinos, LLC 2026-03-05
- Toy Battles 2026-02-06
- Dragonica Lunaris 2025-12-06
- Casino, LLC dba Larry Flynt s Lucky Lady Casino 2025-05-14
- Aeonsparx 2025-03-06
- tnlottery.com 2025-01-29
- 1win 2024-11-02
- SuperDraft 2024-10-27
- Earth 2 2024-10-16
- The Club Penguin Experience 2024-10-14
- Sanyo Bussan Co., Ltd. 2024-09-02
- WoTLabs 2024-03-03
- Mr. Green Gaming 2024-03-01
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.