Research from cybersecurity software company NordVPN has exposed a social media scam that pushes victims into unlicensed gambling by impersonating over 400 well-known brands online.
The company's Threat Intelligence research unit has uncovered a large-scale criminal operation that hijacks the logos and names of over 400 trusted brands to redirect unsuspecting people toward unregulated online gambling, it said in a press release.
The network runs paid ads on social media platforms such as Facebook and Instagram, with adverts impersonating a number of household name brands including Google Authenticator, Kalshi, Disney+, Duolingo, Delta Air Lines and even national lotteries.
Internet users who tap the ad are shown a fake Google Play app store page, and when they press the “Install” button they are re-directed to an unlicensed casino and asked to make a deposit.
The criminal network includes a "PWA constructor for affiliates," around a thousand affiliate accounts across more than 250 teams who rent the kit and buy social media traffic to run campaigns, and the unlicensed casinos, who pay the affiliates a commission for every user who registers or deposits.
“What we're looking at is essentially trust laundering. Criminals take the credibility that legitimate companies have spent years building and redirect it toward their own ends,” says Marijus Briedis, chief technology officer at NordVPN, in a the press release.
“By the time a victim realises something is wrong, they've already deposited money into a casino they've never heard of,” he added.
Briedis offers advice for anyone hoping to avoid these fake apps and the sites they direct users to, reminding internet users that app installation should always open the official store, to check the address bar of any site they're directed to, and to review their push notification permissions.