TLDR NordVPN researchers found a criminal network using fake ads on Facebook and Instagram to impersonate Google, Disney+ and Duolingo. The ads send Android users to fake Play Store pages that install apps linking to unlicensed gambling sites. Over 7,200 gambling pages and 3,100 decoy pages were found, showing the scam was built to dodge ad review systems. Similar scams have used abandoned websites and fake betting brands during major sporting events. Meta is under growing legal pressure over gambling ads, with regulators in Thailand and the Netherlands taking action.
Android users are being targeted by a scam that hides illegal gambling apps behind the names of trusted brands. Cybersecurity researchers say the scheme is built to look convincing at every step.
NordVPN’s Threat Intelligence Team uncovered the operation. It runs through paid ads on Meta platforms, including Facebook and Instagram.
The ads copy the look of well known services like Google, Disney+ and Duolingo. At first glance, they seem harmless.
Clicking the ad does not lead to the real Google Play Store. Instead, users land on a fake copy of the page.
Criminals Hide Behind Familiar Brands
From there, victims are prompted to install what looks like a normal Android app. It is actually a Progressive Web App, a lightweight tool that runs like an app but is built with basic web code.
The fake app connects users to unlicensed gambling websites. It also turns on push notifications that keep sending gambling offers after installation.
The scam works because people trust familiar brand names. That trust makes them less likely to question what they are installing.
Once installed, some victims go on to deposit money on gambling sites they never meant to visit.
Researchers also found the group using cloaking technology. This lets them show a