Confirm action

Are you sure you want to delete?

Link copied!
Gambling
Jul 31, 2026 · 3 min read

NordVPN finds 400+ brands impersonated to redirect users to illegal iGaming platforms

Affmarketingworld
Patric Mirgeschiss
Editor, Affmarketingworld
NordVPN finds 400+ brands impersonated to redirect users to illegal iGaming platforms

Cybersecurity researchers at NordVPN have uncovered a large-scale ad scheme that impersonated more than 400 global brands — including Google, YouTube, Disney+, HBO Max, and Airbnb — to funnel users toward unlicensed gambling platforms.

What was found

According to NordVPN, the operators behind the scheme ran ads on Facebook and Instagram disguised as well-known products and services, including Google Translate, Google Authenticator, YouTube Kids, Adobe Acrobat, HBO Max, Disney+, Airbnb, and Delta Air Lines.

The same infrastructure also impersonated gambling-industry brands directly, including Crown Melbourne, Holland Casino, and EuroMillions. NordVPN tracks the network internally under the name pwa_betterlinks.

How it works

Rather than prompting users to install an app, the ads generate a home-screen shortcut for a progressive web app (PWA) carrying the logo of the impersonated brand. Tapping that shortcut opens the unlicensed iGaming platform directly.

PWAs are a deliberate choice here: unlike a native app, a progressive web app installs straight from the browser with no app store review and no listing that could get flagged as malicious. That lets the operators skip the vetting layer that would normally catch an app impersonating Disney+ or HBO Max, while still giving users something that behaves like an installed app, complete with a home-screen icon.

The scheme relies on cloaking to evade ad-platform review: automated moderation systems checking the ad are shown a neutral, unrelated page, while real users who click through get redirected to the gambling site instead.

In the sample NordVPN collected, the gambling-platform pages were opened 7,600 times, while the decoy version shown to verification systems was served more than 3,100 times — meaning cloaking accounted for roughly a third of all page loads in the dataset. That ratio says something about the operators’ confidence: real users saw the gambling redirect more than twice as often as any reviewer or automated scanner saw the decoy page.

For the impersonated brands, the exposure is not just reputational. A user who lands on an unlicensed gambling site through what looks like a Google Authenticator or Delta Air Lines shortcut has no reason to suspect anything is wrong — which is exactly the trust the scheme exploits rather than any actual flaw in those companies’ own products.

The brand list here is the tell: nobody spoofs Google Translate and Delta Air Lines for a small operation. Running cloaking sophisticated enough to fool ad-platform reviewers two-to-one against real users points to a team that treats detection evasion as core infrastructure, not an afterthought — and that’s a harder problem for Meta and Google to solve than just banning individual ads as they get reported.

Patric Mirgeschiss
Reviewed by
Patric Mirgeschiss
Editor · AffMarketing World
Published Jul 31, 2026
X Profile →
Related tags