Tag Archives: hack

How Fake Google Play Ads on Facebook Funnel People Into Unlicensed Casinos

Our friends at NordVPN’s Threat Intelligence team has just uncovered a criminal network running paid Facebook and Instagram ads that impersonate over 400 trusted brands — from Google Authenticator and Kalshi to national lotteries — to trick people into fake app installs that redirect them to unlicensed online casinos

The operation is not the work of a lone scammer.

It is a rented criminal platform, actively running today, used by roughly a thousand affiliates across more than 250 teams. This large-scale criminal operation hijacks the logos and names of over 400 trusted brands to redirect unsuspecting people toward unregulated online gambling. The network — which NordVPN tracks as pwa_betterlinks — runs paid adverts on Facebook and Instagram impersonating household names including Google Authenticator, Kalshi, Disney+, Duolingo, Delta Air Lines, and national lotteries. 

Victims who tap the ad are shown a fake Google Play Store page that is nearly impossible to distinguish from the real thing. One tap of “Install” later, they land on an unlicensed casino asking for a deposit. ImageWhat a real, targeted person sees: The full fake Google Play page — here spoofing Crown Melbourne

“What we’re looking at is essentially trust laundering. Criminals take the credibility that legitimate companies have spent years building and redirect it toward their own ends. By the time a victim realizes something is wrong, they’ve already deposited money into a casino they’ve never heard of.” Marijus Briedis, chief technology officer at NordVPN.

The fake app store hiding inside a social media ad 

Every victim’s journey starts with a paid ad on Facebook or Instagram. A real, purchased placement that carries the implicit legitimacy of a platform people use every day. Clicking it takes users to what appears to be a genuine Google Play Store listing, complete with the brand’s logo, a forged developer name, a 4.9-star rating, and thousands of fabricated reviews. The only visible tell is the web address in the browser bar — a random throwaway domain rather than play.google.com. ImageGoogle Authenticator spoofed on playrosario[.]site (Google LLC · Tools)

The impersonated brands span casinos and national lotteries (Crown Melbourne, Holland Casino, EuroMillions), mainstream apps (Google Translate, Google Authenticator, YouTube Kids, Adobe Acrobat, Shazam), financial services (Capital One, Credit Karma, Kalshi), streaming (HBO Max, Disney+, Peacock), and travel (Delta, United, Airbnb). 

The Install button that installs nothing

Tapping Install triggers a convincing fake progress bar. No app is downloaded. What actually happens is a shortcut — a Progressive Web App, or PWA — is silently added to the home screen under the impersonated brand’s name and icon. A PWA is not a real app. It is a website that looks like one, sitting on a phone’s home screen with zero app store vetting required. The criminal can spin up a new fake page as fast as they can register a domain. ImageOn the left PWA “Installation” on Android, on the right Official app installation. The process also silently signs the device up for push notifications, which fire gambling reminders directly to the lock screen and are deliberately difficult to disable. Even the back button is rigged. Instead of returning users to the previous page, it reroutes them to the casino offer. 

A commercial product designed to evade detection

Before any real page is shown, every click passes through a cloaking layer that checks whether the visitor is a human or an automated scanner — including Facebook’s own ad review bots. Checkers are served a blank decoy page. Real users are served the fake casino funnel. Across NordVPN’s captured dataset, the casino page was served 7,261 times; the decoy was served to checkers 3,153 times. The people doing the checking never see what the actual targets see. The network is structured as a commercial product, not a one-off scam. At the top sits betterlinks[.]pro, a platform that markets itself openly as a “PWA constructor for affiliates” with built-in cloaking and Facebook optimization. ImageUnlicensed casino registration with an offering of 150% up to €3,000/ $4,830 CAD + 150 FS dazard[.]com

 In the middle sit roughly a thousand affiliate accounts across more than 250 teams who rent the kit and buy social media traffic to run campaigns. At the bottom are the unlicensed casinos and CPA networks that pay the affiliates a commission for every user who registers or deposits — with captured records linking the operation to the Makeberry Affiliates network and casinos. 

How to stay safe?

 Marijus Briedis advises anyone using social media to keep three things in mind: A real app install always opens the official store. If tapping “Install” in an ad opens a web page rather than the Google Play Store or Apple App Store, stop immediately. Check the address bar. A genuine Google Play listing lives at play.google.com. Any other web address showing a store-style page — no matter how accurate the branding — is a fake. Review your push notification permissions. Go to your phone’s settings and check which websites have permission to send you alerts. Revoke anything you don’t recognize.

Methodology

The investigation began by identifying a shared template fingerprint across a cluster of fake app-store pages, which NordVPN used to recover live instances of the operation at scale. From there, analysts mapped the full funnel logic through network traffic analysis and JavaScript deobfuscation, revealing the infrastructure connecting individual affiliate accounts to their campaigns, destination casinos, and real Facebook Business ad pixels. Domain registration records, hosting provider data, and code-level signals — including language markers in the push notification code — were used to support operator attribution. All indicators of compromise are analyzed in machine-readable format (STIX 2.1, 880 indicators). Conclusions are based on verified data, with the perimeter of the identified systems delimited with the maximum possible accuracy.

For the Silo, Vilius Kardelis.

Top sites data breached last year include linkedin

Almost 6 billion accounts affected in data breaches in 2021 

The year 2021 was record-breaking in terms of the sheer size of data breaches. According to the data collected and analyzed by the Atlas VPN team, 5.9 billion accounts were affected by data breaches throughout 2021. 

Atlas VPN has retrieved and calculated the numbers of breached accounts based on multiple publicly available sources. The total count includes worldwide data breaches that took place from January 1st, 2021, to December 31st, 2021. 

Image

February saw the biggest data breach of all-time  COMB, or in other words, the Compilation of Many Breaches, which is responsible for the leak of a whopping 3.2 billion unique cleartext email and password combinations.

The breach was named this way because it is not a result of a single hack of a specific organization but rather combines leaked data from a number of different breaches spanning five years, including Netflix, LinkedIn, and others.

The breached data was first offered for sale on RaidForums, an underground database sharing and marketplace forum, for just $2 in February. Other breaches that made it to the top five biggest data leaks of 2021 include LinkedIn (700 million people), Facebook (533 million people), Brazil’s Ministry of Health (220 million people), and SocialArks (214 million people). 

Cybersecurity writer and researcher at Atlas VPN Ruta Cizinauskaite shares her thoughts on 2021 data breach trends: “Even with data breaches becoming a growing threat, it seems organizations are still not putting enough effort in protecting the personal information of their users. One of the first things every organization should do is evaluate the amount of sensitive user data it collects — the less sensitive data is stored, the lesser the risk of it being leaked.”

Minecraft is most malware infected game

228k Users Affected, Are You One Of Them?

As people are looking for ways to unwind at home, the gaming industry has been one of the primary places people set their eyes on. Not only is it a way to entertain yourself for hours on end, but it is also a place for people to connect, which is otherwise hard to do during the pandemic. 

According to data presented by the Atlas VPN team, 303,827 individuals’ devices were affected by gaming-related malware and unwanted software between July 1, 2020, and June 30, 2021. Mobile games are also a major threat for gamers.

As many as 50,644 users attempted to download 10,488 unique files disguised as the ten most-played mobile games, generating a total of 332,570 detections. Minecraft was by far the most popular game on both PC and mobile platforms for dangerous app distributors to hide behind. On PC, nearly 185 thousand users were affected with over 3 million malware and unwanted software detections.

On mobile, the number of victims exceeds 44 thousand for the period.

Unwanted software includes files like adware, spyware, and so on. There are various versions of Minecraft and a plethora of mods (modifications that may be placed on top of the basic game to diversify gameplay) may account for its enormous popularity. Because mods are unofficial and developed by users, they can be used to hide dangerous payloads or undesirable software. 

Security tips for gamers

  • Protect your accounts with two-factor authentication (2-FA) whenever possible. 
  • Use strong passwords for your accounts, with a different one for each. That way, even if one of your accounts is compromised, the remainder will remain unaffected.
  • Downloading games from official retailers such as Steam, Apple App Store, Google Play, or Amazon Appstore is safer. These marketplaces aren’t completely safe, but they are at least examined by store staff, and there is some sort of screening procedure in place: not every app is allowed into these stores.
  • If you want to buy a game that isn’t accessible in major stores, you should do it through the official website. Make sure to double-check the website’s URL to avoid impostor sites.
  • Be cautious of phishing campaigns and unfamiliar players. If you are unsure about the sender, do not open links you receive via email or in a gaming chat. Do not open files sent to you by strangers.

Another one of the most well-known game titles worldwide, The Sims 4, was the second most often used title to distribute unwanted files. Over 43 thousand users were impacted, with detections closing in on 1.3 million.  For the Silo, Valentina Perez.