The house always wins at an unlicensed casino, so the safest move is not to sit down at the table. In this article, I’ll explain how BetterLinks PWA borrows trusted brand names, what happens after someone taps a fake ad, and how to spot the warning signs before the fake “install” begins. I’ll also share practical steps to take if you’ve opened one of these pages.
Disclaimer: NordVPN is not endorsed by, affiliated with, or sponsored by Google, Apple, Meta, or any other brand mentioned in this article. Brand names appear here solely to report the impersonation tactics observed in NordVPN’s research and to help readers recognize how scammers misuse trusted names to make fake app install pages look legitimate.
The scam starts with a brand you already trust
The operation borrows trust from names people already know. NordVPN’s investigation found fake install pages that copied brands across finance, travel, streaming, health, sports, children’s learning, security, gambling, and gaming.
Some fake pages impersonated Google products, including Google Authenticator, Google Translate, Gemini, and YouTube Kids. Others copied casino, lottery, and game brands, including local operators and popular slot-style games. A fake casino app may already raise suspicion, but a fake Google Authenticator page can feel more convincing because people associate that name with account security.
Once someone accepts the fake install flow, the criminal network can reuse the same playbook with a different logo, app name, or final destination. In the cases we observed, the flow sent people to unlicensed online casinos. The same setup could send people to fake banking pages, credential theft pages, or other malicious sites.
The fake install page looks like Google Play
The fake store page is one of the most convincing parts of the scam. It looks like a real Google Play listing, with a brand logo, developer name, screenshots, star ratings, download counts, reviews, and an install button.
The key difference is the address. A real listing opens on Google Play, and the install runs through the Google Play Store. These fake pages open on unrelated web domains that have no connection to the brand.
That detail can be easy to miss on a phone screen. Scammers count on people checking the logo, not the URL.
A fake install page may show:
- A familiar brand name or app logo.
- A polished design that mimics Google Play.
- A high star rating, often around 4.9.
- Large download numbers.
- Fake user reviews.
- Bonus offers or casino rewards.
- An “Install” or “Download” button that keeps you inside the browser.
- A web address that doesn’t match the real brand or app store.
The same ad shows different pages to different people
The scam uses a hidden check before it shows the fake install page. When someone taps the ad, the link first passes through a tracking system. The system looks at details such as where the click came from, the device type, and whether the visitor looks like a real person or an automated reviewer.
A real person may see the fake app install page. A security scanner, ad reviewer, or bot may see a blank page or a harmless website instead. That difference helps the ads avoid detection because the platform’s automated checks may not see the same page a real visitor sees.
For the person who taps the ad, none of the steps seem out of the ordinary:
- 1.The ad opens a page.
- 2.The page looks like an app store.
- 3.The page appears to install an app.
- 4.The “app” opens an online casino.
In those four steps, the platform checks the visitor, tracks the click, and records which affiliate gets paid if the person registers or deposits money.
The “app” is just a website
The scam uses progressive web apps, or PWAs. A PWA is a website that can behave like an app. It can add an icon to your home screen, open in a full-screen view, and send push notifications if you allow them.
PWAs are a legitimate technology. Many companies use them to make their websites faster and easier to access.
In the BetterLinks PWA scam, the fake page doesn’t download an app from Google Play. It adds a website shortcut to your home screen. The shortcut can look like a normal app icon, but it opens a website instead of a real mobile app.
Push notifications keep pulling people back
The fake install flow can ask for permission to send notifications. If you allow them, the website can send alerts to your phone without you visiting the page again. Those alerts may promote gambling offers, bonuses, or return visits to the casino.
Push notifications from a website look the same as notifications from a real app, which makes the scam harder to spot. You may think the alert comes from an app you installed. In reality, a website is sending it through your browser.
Some scam pages also interfere with the “Back” button. When you try to leave, the page may send you back to the offer instead of the previous page.
The chain ends at the unlicensed gambling site
After the fake install, you land on an online casino registration page. The casino may ask for:
- Your email address.
- A password.
- Your country of residence.
- Confirmation that you’re 18 or older.
- A first deposit.
Some pages display large welcome offers, such as €2,000-3,000 bonuses plus free spins. The casino may also claim to be “VPN friendly,” even while it blocks visitors from countries where it lacks permission to operate.
Unlicensed gambling sites often offer weaker consumer protections. People may face poor age checks, unclear deposit rules, unfair bonus terms, refused payouts, or aggressive marketing after they sign up.
The chain may have started with a fake Google Authenticator page, a fake lottery site, or a fake travel app. In the cases we observed, the goal was to move the person into an online casino and earn affiliate money from registrations or deposits.
Who’s behind the scam operation?
BetterLinks PWA appears to be a commercial platform that helps affiliates create and run fake app campaigns. Technical clues, including code comments in Ukrainian and domain registrations through a Ukrainian registrar, point to a Ukrainian-speaking operator. This operator hasn’t been publicly named before, and we haven’t identified the individuals running the platform.
The platform supplies the tools, the affiliates bring in the traffic, and the casinos pay for every person who registers or deposits money. Captured records show 88 affiliate accounts, and the platform’s account numbering suggests it has set up close to 1,000 accounts in total.
Important: The BetterLinks WordPress plugin is a legitimate product with no connection to the criminal platform described in this research.
How to spot a fake app install page
You don’t need technical skills to spot many PWA-based scams. Watch for these signs:
- 1.The install doesn’t open an official app store. A real Android app install opens Google Play. A real iPhone app install opens the App Store. If the “Install” button keeps you inside a browser page, treat the page as suspicious.
- 2.The URL doesn’t match the brand. A fake page may show the Google Authenticator logo while the address bar shows an unrelated domain. Check the domain before you trust the page.
- 3.The design copies Google Play or App Store. Scammers clone familiar app store layouts down to the star ratings.
- 4.The page offers a casino bonus after sending a non-casino ad. A fake bank app, travel app, or security app should never send you to a casino deposit page.
- 5.The page asks to send notifications during the install flow. A browser notification request should make you pause, especially if you accessed the page from a social media ad.
- 6.The ad pushes you to act fast. Paid ads can still be scams. Treat app install ads on Facebook and Instagram with the same care as email links.
What to do if you clicked the ad
A click alone doesn’t mean your phone has been infected. Your next steps depend on what happened after you clicked.
If you only opened the page:
- Close the browser tab.
- Don’t tap “Install.”
- Don’t allow notifications.
- Don’t enter your email, password, card details, or personal data.
- Report the ad to Facebook or Instagram.
If you added the shortcut to your home screen:
- Remove the shortcut from your home screen.
- Open your browser settings and find site permissions.
- Remove notification permission for the suspicious domain.
- Clear site data for that domain if your browser allows it.
- As a precaution, run a scan with trusted security software.
If you registered on the casino site:
- Don’t deposit more money.
- Contact your bank if you entered payment details.
- Freeze or replace your credit card if needed.
- Change any password you reused on the casino site.
- Save screenshots of the ad, website, casino page, messages, and payment records.
- Report the page and ad to the social media platform.
- Report financial loss to your bank or local consumer protection authority.
If you entered login details for a real account:
- Change that password immediately.
- Turn on two-factor authentication through the official app or website.
- Review your recent account activity.
- Sign out of all active sessions if the service allows it.
How to remove scam push notifications
Push notifications can take a few more steps to remove than the shortcut itself.
On Android Chrome:
- 1.Open Chrome.
- 2.Tap the three-dot menu.
- 3.Tap “Settings.”
- 4.Tap “Site settings.”
- 5.Tap “Notifications.”
- 6.Find the suspicious domain and tap it.
- 7.Turn off “Show notifications.”
On iPhone Safari:
- 1.Touch and hold the suspicious shortcut on your home screen.
- 2.Tap “Delete bookmark” or “Remove app,” depending on your iOS version.
- 3.Open “Settings.”
- 4.Tap “Notifications.”
- 5.Look for the suspicious website or web app and turn off “Allow notifications” if it appears.
- 6.Go back to “Settings.”
- 7.Find “Safari” in “Apps.”
- 8.Tap “Advanced.”
- 9.Tap “Website data.”
- 10.Remove data for the suspicious domain.
PRO TIP
If the website isn’t listed under “Notifications” (Step 4), removing the shortcut and clearing the website data should stop most alerts from that site.
Why the scam works
BetterLinks PWA works because it sends several trust signals at once:
- 1.The ad appears on a mainstream platform. Many people assume paid ads on Facebook and Instagram have been vetted before they run.
- 2.The page copies a trusted app store. A layout borrowed from Google Play or Apple App Store makes the fake page look familiar.
- 3.The scam borrows a brand you already know. You may recognize Google Authenticator, a bank, an airline, or a national lottery — and a familiar name is usually enough to lower your guard.
OUR EXPERT SAYS
What we’re looking at is essentially trust laundering. Criminals take the credibility that legitimate companies have spent years building and redirect it toward their own ends. By the time a victim realizes something is wrong, they’ve already deposited money into a casino they’ve never heard of.
Marijus Briedis, chief technology officer at NordVPN
One rule to stay safe
A real app install takes you to Google Play or the App Store. If tapping “Install” on a website only drops a shortcut onto your home screen, you’ve found a fake. Close the page and report the ad.
Open Google Play or the App Store yourself. Search for the app by name, check the developer, and read recent reviews. If the app isn’t listed, the ad was fraudulent.
How NordVPN can help
Scammers register new malicious domains every week, and many of the pages look polished enough to deceive even tech-savvy people.
NordVPN is an all-in-one1 digital security app that combines a VPN with scam and phishing protection. Scam and phishing protection blocks known malicious websites and scam domains before they load on your device, which helps when a risky link reaches you through a social media ad, a message, or search results.
If you want to check a suspicious URL first, use NordVPN’s Link Checker. Copy the link, paste it into the tool, and review the result. If the link looks unsafe, don’t open it — report the ad instead. No tool catches every new fake domain, so searching for the app yourself in the official store is still your best defense.
1 “All-in-one” refers to the VPN, scam protection, phishing protection, tracker and ad blocking, and other features available within the NordVPN app, depending on your device and the plan you choose.
Online security starts with a click.
Stay safe with the world’s leading VPN
Methodology
The investigation began by identifying a shared template fingerprint across a cluster of fake app-store pages, which NordVPN used to recover live instances of the operation at scale. From there, analysts mapped the full funnel logic through network traffic analysis and JavaScript deobfuscation, revealing the infrastructure connecting individual affiliate accounts to their campaigns, destination casinos, and real Facebook Business ad pixels.
Domain registration records, hosting provider data, and code-level signals — including language markers in the push notification code — were used to support operator attribution. All indicators of compromise are analyzed in machine-readable format (STIX 2.1, 880 indicators). Conclusions are based on verified data, with the perimeter of the identified systems delimited with the maximum possible accuracy.