Is your bank now offering gambling? Probably not, but someone wants you to think so.
A previously documented cluster (https://infosec.exchange/@Infob
Altro...
Is your bank now offering gambling? Probably not, but someone wants you to think so.
A previously documented cluster (https://infosec.exchange/@Infob
Altro...Is your bank now offering gambling? Probably not, but someone wants you to think so.
A previously documented cluster (https://infosec.exchange/@InfobloxThreatIntel/116001809925553061) has ramped up its activity across Latin America over the past few weeks, spoofing the brands of regional financial institutions to distribute algorithmically generated domains (RDGA) via Meta Ads, with per-user tracking capabilities throughout the entire activity flow.
The sites and apps this Latin American cluster are promoting appear to be classic scam gambling or "scambling" websites, a topic we recently covered @ "How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage" @ https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/
The sites behind these domains operate with multiple anti-analysis layers: through user-agent gating, they serve differentiated content based on device, browser, and region, actively blocking any client outside the target profile. The kit has a clear Russian development context, featuring Russian-language comments at the code level and integrated Yandex telemetry fields.
This isn't the first time that a scambling campaign has seen ties to Russia, with @briankrebs@infosec.exchange writing about this last Summer in his piece "Affiliates Flock to 'Soulless' Scam Gambling Machine" @ https://krebsonsecurity.com/2025/08/affiliates-flock-to-soulless-scam-gambling-machine/
When a victim accesses one of the sites in the current campaign from a target environment, it deploys a layout spoofing Google Play, financial brands, and other brands to distribute Progressive Web Apps (PWAs), Chrome-installable applications that bypass any official app store and require no malicious binaries.
Once installed, these PWAs act as a traffic-funneling mechanism toward illegal casinos operated from Russia or low-regulation jurisdictions such as Curaçao. Some of these casinos are conveniently tailored to the target the region, accepting payments through local financial institution gateways in addition to cryptocurrency. In other cases, there are signs of fraud based on the impersonation of state lotteries and betting markets on already-concluded events — indicators of potential crypto-based asset theft schemes.
The campaign has confirmed presence in Argentina, Chile, Brazil, Mexico, and Colombia.
If history is any indication, if you take the bait and deposit at one of these casinos they are promoting, which can seem like "free money" as they promote generous deposit bonuses, you will likely never see that money again. And even if you win on any games they are hosting, you'll likely face one cash out challenge after another until the organization attempts to disappear.
Scam, Run, Rinse and Repeat - a process which is becoming a criminal business model as scambling continues to scale in 2026. #scambling #malvertising #RDGA #FakeApp #Scam #Gambling