NordVPN’s Threat Intelligence team has uncovered a large-scale criminal operation that impersonates more than 400 well-known brands to lure users to unlicensed online gambling sites through paid social media advertising.
According to the cybersecurity company, the campaign, tracked as “pwa_betterlinks”, uses adverts on Facebook and Instagram featuring brands including Google Authenticator, Kalshi, Disney+, Duolingo, Delta Air Lines and several national lotteries. Users who click the adverts are taken to fake Google Play Store pages before being redirected to unlicensed online casinos.
Rather than downloading a genuine app, users are prompted to install a Progressive Web App (PWA), which places a shortcut on their device while subscribing them to push notifications promoting gambling offers.
NordVPN said the operation uses cloaking technology to evade automated moderation systems, serving legitimate-looking decoy pages to ad reviewers while directing real users to gambling sites. Its researchers identified more than 7,200 instances where casino pages were delivered to users, alongside more than 3,100 decoy pages shown to automated checkers.
The company said the infrastructure appears to operate as a commercial affiliate platform, with technology marketed through the Betterlinks platform and used by hundreds of affiliate accounts to drive traffic to unlicensed gambling operators.
Marijus Briedis, Chief Technology Officer at NordVPN, said: “What we’re looking at is essentially trust laundering. Criminals take the credibility that legitimate companies have spent years building and redirect it toward their own ends. By the time a victim realizes something is wrong, they’ve already deposited money into a casino they’ve never heard of.”
NordVPN advised users to verify that app installations always open the official Google Play Store or Apple App Store, check website addresses before downloading software and regularly review browser notification permissions to identify unauthorised alerts.


























