Vault Viper is a cybercriminal threat actor and criminal infrastructure cluster associated with Baoying Group, also known as BBIN, a major Asia-focused iGaming provider with longstanding ties to illegal gambling and broader organized-crime activity in Southeast Asia. The group has been linked to a large ecosystem spanning online gambling platforms, scam operations, money laundering, human trafficking, and other cyber-enabled fraud. Reporting also connects Vault Viper to the wider Suncity criminal network and notes overlap with activity tracked as Vigorish Viper. Some reporting refers to it as Business Group 1. Vault Viper is best known for distributing Universe Browser, a custom browser promoted as a privacy or circumvention tool but exhibiting malware-like behavior. The Windows variant has been observed routing user traffic through infrastructure in China, covertly installing background components, performing anti-virtual-machine checks, disabling browser security features, modifying network behavior, and supporting capabilities consistent with keylogging, code injection, persistence, screenshot capture, and covert communications. The browser is primarily distributed through gambling-related websites tied to the actor and appears designed to help users bypass online gambling restrictions while exposing them to surveillance and exploitation. The actor maintains a large and resilient technical footprint, including thousands to tens of thousands of domains, dedicated network infrastructure, rapid domain rotation, DNS manipulation, encrypted communications, and cloud-hosted command-and-control resources. Its tooling and infrastructure have been described as professionalized and continuously evolving, with additional associated tools including authentication applications and custom mobile malware. Infrastructure and behavioral overlaps have also been noted between Vault Viper and a Chinese-speaking malware-as-a-service ecosystem servicing scam centers in the Mekong region. Vault Viper’s activity sits at the intersection of cybercrime and transnational organized crime rather than state espionage. The group has been associated with illegal gambling operations, pig-butchering and related fraud schemes, money laundering, and abuse of legitimate business fronts such as hotels, casinos, property development, and investment entities. It has been described as operating from the Philippines while enabling criminal operations across Southeast Asia, including scam compounds in Cambodia and Myanmar. The actor’s scale, financial resources, and integration with regional criminal supply chains make it a significant and durable threat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster linked in the report through infrastructure and behavioral overlaps with a multilingual scam and Android banking trojan MaaS operation targeting victims across multiple continents.
Vault Viper is a cybercrime group operating a global DNS infrastructure supporting illegal gambling, money laundering, fraud, and human trafficking, using the Universe Browser malware to control victim systems and facilitate organized crime.
Cyber-enabled gambling/fraud ecosystem tied to Baoying Group/BBIN distributing a custom 'Universe Browser' that routes traffic via China-based servers and includes RAT-like surveillance capabilities; linked to large-scale scam operations in Southeast Asia.
Vault Viper is a threat group operating in connection with BBIN, a major online gambling company. The group is responsible for distributing the Universe Browser, which covertly installs malware-like components, routes traffic through China, and is linked to Southeast Asia's cybercrime ecosystem, including money laundering, illegal gambling, human trafficking, and scam operations. Vault Viper's infrastructure includes tens of thousands of web domains and command-and-control servers, and the group is associated with sophisticated cyber-enabled fraud and scam operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.