TLDR
- NordVPN researchers found a criminal network using fake ads on Facebook and Instagram to impersonate Google, Disney+ and Duolingo.
- The ads send Android users to fake Play Store pages that install apps linking to unlicensed gambling sites.
- Over 7,200 gambling pages and 3,100 decoy pages were found, showing the scam was built to dodge ad review systems.
- Similar scams have used abandoned websites and fake betting brands during major sporting events.
- Meta is under growing legal pressure over gambling ads, with regulators in Thailand and the Netherlands taking action.
Android users are being targeted by a scam that hides illegal gambling apps behind the names of trusted brands. Cybersecurity researchers say the scheme is built to look convincing at every step.
NordVPN’s Threat Intelligence Team uncovered the operation. It runs through paid ads on Meta platforms, including Facebook and Instagram.
The ads copy the look of well known services like Google, Disney+ and Duolingo. At first glance, they seem harmless.
Clicking the ad does not lead to the real Google Play Store. Instead, users land on a fake copy of the page.
Criminals Hide Behind Familiar Brands
From there, victims are prompted to install what looks like a normal Android app. It is actually a Progressive Web App, a lightweight tool that runs like an app but is built with basic web code.
The fake app connects users to unlicensed gambling websites. It also turns on push notifications that keep sending gambling offers after installation.
The scam works because people trust familiar brand names. That trust makes them less likely to question what they are installing.
Once installed, some victims go on to deposit money on gambling sites they never meant to visit.
Researchers also found the group using cloaking technology. This lets them show a harmless page to ad reviewers while showing gambling content to real users.
NordVPN counted more than 7,200 cases where casino pages were shown to users. It also found over 3,100 decoy pages meant to fool automated review systems.
Familiar Pattern During Major Sporting Events
This is not an isolated case. Similar tactics have shown up around major sports events in the past.
During the FIFA World Cup, brand protection firm Corsearch reported a rise in phishing scams tied to betting brands. The firm recorded a 118% jump in betting related phishing activity during last year’s summer sporting events.
Separate research for the Betting and Gaming Council found scammers taking over abandoned websites. These included a tourist page for Bideford, a PlayStation news site, and a domain once tied to Nigel Farage’s Brexit Party.
Those recycled sites were used to promote unlicensed casinos. Some specifically targeted people who had already asked to be excluded from licensed UK gambling sites.
The new findings add to ongoing scrutiny of Meta’s ad systems. A Reuters investigation previously found that internal estimates linked about 10% of Meta’s 2024 ad revenue, roughly $16 billion, to scams and banned products, including illegal gambling.
Authorities in Thailand and the Netherlands have opened legal action against the company. Both argue its safeguards against illegal gambling ads fall short.
The UK’s Gambling Commission has also raised concerns. It has questioned why major tech platforms still struggle to remove illegal gambling ads despite having advanced tools available.
For now, researchers advise Android users to avoid installing apps through ad links and to stick to official app store searches instead.
