NordVPN’s Threat Intelligence team has uncovered a large-scale cyber campaign that uses fake mobile app downloads and trusted global brands to redirect users to unlicensed online gambling sites.
The cyber security company reported that the campaign, named “pwa_betterlinks,” is impersonating over 400 famous brands in ads sponsored by Facebook and Instagram. The ads represent many well-known brands with names such as Kalshi and other country operators, asking people to install the apps.
Instead of directing the users to the official Google Play Store or Apple App Store, the ads link to fake app store sites that mimic the Google page closely. After that, users are told to install a Progressive Web App, which places an icon on their device and signs them up for browser push notifications offering illegal online casinos and betting.
According to NordVPN specialists, the operation uses advanced technology to circumvent the moderation system of social networks. Whereas automated reviewers see neutral sites, real people are redirected to the gambling ones. During the research, the company found over 7,200 records of sending users to the site compared to 3,100 fake pages that were used in the review of advertising.
Marijus Briedis, Chief Technology Officer at NordVPN, considered this action as a form of “trust laundering,” in which people try to use the fame of established brands to reassure customers and transfer them to other gambling websites.
