Copied App Stores Give Illegal Casinos a Route through Meta

The campaign begins with paid advertisements on Facebook and Instagram. Some impersonate services such as Google, Disney+, and Duolingo, giving users little reason to expect a gambling offer behind the click.
A Fake Store Sits between the Ad and the Casino
The landing page copies Google Play. Instead of downloading the expected Android app, the visitor installs a Progressive Web App. It places a shortcut on the device and can continue reaching the user through gambling-related push notifications.
The route creates several layers of distance from the advert. The social post carries a trusted brand. The next page resembles an official app marketplace. The casino only appears after the user passes through both.
Cloaking Hides the Real Destination
NordVPN’s Threat Intelligence Team found that the network uses cloaking to separate real users from advertising review systems. Automated checks receive a harmless page. A person clicking the same campaign can be sent to casino content.
Researchers recorded over 7,200 cases in which users were served gambling pages. They also identified over 3,100 decoy pages shown to automated reviewers.
The problem is deeper than obvious casino banners slipping through. Review systems are seeing a different destination from the one presented to potential players. The campaign was built around that division.
Affiliate Tools Spread the Campaign
The infrastructure appears to operate as an affiliate service rather than a promotion for one casino. Technology linked to the Betterlinks platform was reportedly used by hundreds of affiliate accounts to direct traffic toward unlicensed operators.
That setup complicates enforcement. An advert, fake store page, affiliate account and casino domain may all sit under different names. Removing one link may leave the wider traffic system intact.
Pressure Returns to Meta’s Ad Controls
The findings add to concern over illegal gambling acquisition on major social networks. Previous research has shown the presence of phishing sites as well as replicas of betting services and abandoned websites repurposed for advertising black-market casinos. Some of them even focused on people who had excluded themselves from licensed gambling services.
A misleading download is only one danger among many. Users may end up depositing money on a site that they had not intended to, one that lacks the necessary licensing information or a reliable mechanism for lodging complaints.
The vulnerable spot is now the entire process of advertisement, not the final casino domain alone. It will hardly be effective to simply block known operator websites when the first visible product is a fake mainstream app. In such a case, platforms need to analyze redirects, installation prompts, and the pages served after automated checks have finished.