
NordVPN exposes Android scam that hijacks trusted brands to push illegal gambling
2026-07-29
Source: iGaming Expert
NordVPN has identified a criminal group using fake Google Play Store pages and hijacked brand identities to funnel Android users into unlicensed gambling sites, while Meta faces legal action over its role in hosting such ads.
The scam mechanism
Cybersecurity firm NordVPN has uncovered a sophisticated operation in which criminals abuse the reputations of well-known brands such as Google, Disney+ and Duolingo to lure Android users into downloading apps that secretly redirect them to black-market gambling sites. The company’s Threat Intelligence Team tracked a large-scale criminal network that exploits Meta’s Instagram and Facebook platforms to advertise legitimate-looking links. Victims are taken to a counterfeit version of the Google Play Store, but the app they install is a Progressive Web App that reroutes them to an unlicensed casino and enables push notifications for gambling offers.
According to NordVPN, the fraudsters employ cloaking technology to deceive moderation systems: while automated reviewers see harmless decoy pages, real users are delivered casino content. Researchers identified more than 7,200 instances where gambling pages reached users, alongside over 3,100 decoy pages shown to ad checkers. Marijus Briedis, Chief Technology Officer at NordVPN, described the scheme as “essentially trust laundering”, adding that criminals redirect credibility built by legitimate companies to their own ends, often causing victims to deposit money into unknown casinos before they realise they have been misled.
Wider industry warnings
This is not the first time the sector has flagged such tactics. During the 2022 FIFA World Cup, brand protection firm Corsearch reported that illegal betting platforms weaponise regulated brand identities through phishing and fake domains. It noted that betting-related phishing scams rose 118% month-on-month during last year’s sporting summer. Separately, research commissioned by the Betting and Gaming Council revealed that affiliates of unlicensed online casinos have hijacked dormant websites – including a tourist information page for the Devon town of Bideford, a PlayStation news site and even a domain once used by Nigel Farage’s Brexit Party – to advertise ‘not on GamStop’ casinos, targeting individuals who have already self-excluded from UK-licensed operators.
Meta in the spotlight
Meta has faced mounting pressure globally over its handling of illegal advertisements. A Reuters investigation suggested that the tech giant internally projected that approximately 10% of its 2024 annual revenue – roughly $16 billion – came from ads promoting scams and prohibited goods, including illegal gambling. Legal proceedings have been launched against Meta in Thailand and the Netherlands over what authorities describe as ‘structurally inadequate’ measures to curb such ads. The outgoing Executive Director of the UK Gambling Commission, Tim Miller, voiced frustration on the iGaming Daily podcast, arguing that the claim by tech billionaires that they cannot stop non-GamStop adverts from appearing on their platforms is “nonsensical”. He warned that their inaction “massively undermines” the efforts of other stakeholders to protect consumers.
These latest findings underscore the sophisticated lengths to which criminal networks will go to promote black-market gambling, and highlight the persistent challenge facing both technology companies and regulators in policing online advertising.
Related Articles
- UK Gambling Commission Pledges Autumn Release of FRA Evidence and Data
- Burnham’s Business Rate Reform Targets Adult Gaming Centres to Subsidise Hospitality
- Former Entain Executive Slams UK Gambling Commission Over Affordability Checks and Leadership Void
- BGC Welcomes New Ministerial Appointments and Sets Out Regulatory Agenda
- Spelinspektionen report highlights affiliates and social media as key black market gambling channels