Scams & Phishing News Fake Google Play Store Pages Use Trusted Brand Names to Push Gambling PWAs

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,075
5,696
2,168
Germany
Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos.

The fraud begins with paid social creative on platforms including Facebook, Instagram, Threads and TikTok. Ads present either simple “Brand Slots” labels or increasingly sophisticated forgeries that borrow real logos, product interfaces and even AI-generated video footage showing apparent staff or branded locations.

These ads claim an “official” launch of slot or casino apps, sometimes pairing fabricated testimonials or fake app-store metadata to amplify credibility.

Clicking the ad leads to a scammer-controlled landing page that mimics a Google Play or App Store listing or a branded promotional page; the “Install” button does not download a vetted app from an official store but instead triggers a browser prompt to add a PWA to the device home screen.

Once installed, the PWA appears like a native app titled and iconised with the impersonated brand yet it is a thin wrapper that loads a third-party casino URL.
Read more:
 
Read more:
This is a realistic abuse pattern because PWAs can be “installed” directly from a website with no app-store vetting, yet still look like a normal app icon on the home screen.

Why this works (and what a PWA really is)
A Progressive Web App is essentially a website saved to your device with:
  • A home-screen icon and app-like window
  • Its own “app” entry in the browser’s site data (storage, permissions, notifications)
  • A URL it loads every time it’s opened

PWAs aren’t inherently malicious, but they’re very convenient for scammers because they can impersonate brands and change content server-side at any time, without going through Google Play / App Store review.

Common red flags in these campaigns
  • An “Install” button on a page that only looks like Google Play/App Store (but the address bar shows a normal website domain)
  • You see a browser prompt like “Add to Home screen” / “Install app” instead of being redirected into the actual Play Store
  • The domain doesn’t match the real brand, or uses lookalike spelling (extra words, hyphens, unusual TLDs)
  • Aggressive prompts to enable notifications (often used for ongoing scam/spam delivery)
  • “Too good to be true” claims, fake reviews, fake download counts, “official launch” language

What to do if someone already installed one
1) Remove the PWA icon
  • Android: long-press the icon on the home screen and remove it (wording varies by launcher)
  • iPhone/iPad: long-press the icon → Remove App (this removes the home-screen shortcut)

2) Clear the site’s data and revoke permissions (important)
Removing the icon alone may not remove site permissions/storage.
  • Chrome (Android): Settings → Site settings → All sites → find the suspicious site → Clear & reset, and set Notifications to Block
  • Safari (iOS): Settings → Safari → Advanced → Website Data → find and delete the suspicious domain; also check Settings → Notifications for anything you don’t recognize

3) Check for anything else installed
These scams sometimes chain into additional downloads or “security check” pages.
  • Review recently installed apps (Android: Settings → Apps → Sort by recently installed)
  • Run a scan with a reputable mobile security product if you suspect more than a PWA was installed

4) Protect accounts and payment info
If any credentials or card details were entered, treat it like a compromise:
  • Change passwords (starting with email/banking), enable MFA
  • Contact your bank/card issuer to monitor or freeze transactions if payment details were provided

Reporting helps reduce exposure
  • Report the ad in the social platform (Facebook/Instagram/TikTok/Threads) and report the impersonation
  • If the page is pretending to be Google Play, you can report it to Google Safe Browsing as a deceptive site: Report a Page to Google Safe Browsing
  • If this is being discussed on MalwareTips as an active campaign, using the forum’s report function can help staff review obvious scam/spam posts quickly

Key takeaway: an “app” that installs via a browser prompt from a lookalike store page is not the same as an app installed from the real Google Play/App Store, and it should be treated as untrusted until proven otherwise.
 
What's deceptive about these campaigns is that they exploit people's trust in well-known brands and the appearance of a legitimate app. In reality, you're not installing an app from the official Google Play Store, but a disguised shortcut that simply opens a gambling website. The key is to remember that if the install button doesn't take you to the real Google Play Store, it's safest to treat it as suspicious and avoid it. 📱⚠️