unphish
unphish unphish

Inside a Betting Brand Impersonation and Affiliate Redirect Campaign

Inside a Betting Brand Impersonation and Affiliate Redirect Campaign

Brand impersonation in the wagering industry does not always follow the same pattern as a typical phishing attack. A fake website may not be trying to steal credentials or payment information directly. In some cases, the impersonated brand is simply the first step in taking a user somewhere else.

During our monitoring, we identified a website using the branding of a major Australian wagering operator. The site used familiar branding and presented visitors with online casino games, bonus offers and prominent calls to register or start playing. At first glance, someone encountering the website could reasonably assume it was connected to the legitimate operator.

However, despite prominently displaying the brand, the website was hosted on an unrelated domain rather than the operator’s official website. We wanted to understand what happened when someone actually interacted with the site, so we followed the links.

Rather than keeping us within the website or taking us to an official service operated by the brand being impersonated, clicking through redirected us to entirely different gambling websites.

What initially looked like a straightforward case of brand impersonation was actually part of a much broader user journey.

A Familiar Brand on an Unfamiliar Domain

At first glance, the website has many of the elements someone might expect from an online wagering platform. It uses the logo and branding of a major Australian wagering operator alongside casino games, gambling imagery, bonus offers and prominent calls to Play Now, Register and Sign In.

Example of impersonating website using the branding of a major Australian wagering operator to promote casino games and bonus offers.

(Example of impersonating website using the branding of a major Australian wagering operator to promote casino games and bonus offers.)

But one of the clearest warning signs appears before you even interact with the website: the URL.

The legitimate operator uses its brand name followed by the official Australian domain extension .com.au. The impersonating website instead adds gambling-related terminology (“casino”), a hyphen and “au” before ending in .com.

This is an important distinction. Including a legitimate brand name in a domain doesn’t mean the website belongs to that brand. Likewise, simply having “au” somewhere in the URL doesn’t make it an Australian .au domain. For it to use the Australian country-code domain, .au must form part of the domain ending, such as .com.au or .au.

Attackers can register domains containing recognisable brand names alongside additional words, locations, hyphens or different domain extensions to make them appear connected to the organisation being impersonated.In this case, the website also promotes casino games and a first-deposit bonus while using the identity of the Australian wagering brand, giving visitors multiple reasons to click further into the site.

And that is where the investigation became more interesting. When we followed those links, we weren’t taken to another page on the impersonating website. We were sent somewhere else entirely.

Where does the redirects go?

Rather than keeping us on the original website, clicking through redirected us onto a separate online gambling platform.

We repeated the process and observed redirects to multiple different gambling websites. What made this even more interesting was that the original site was clearly designed to appear connected to an Australian wagering operator, while the destination sites displayed “Access Restricted” messages stating that the service was not available in our country for legal reasons.

One of the third-party gambling websites reached after clicking through the impersonating site, displaying an “Access Restricted” message for Australian visitors

(One of the third-party gambling websites reached after clicking through the impersonating site, displaying an “Access Restricted” message for Australian visitors.)

(A separate gambling website observed during testing, showing the impersonating site redirecting users to multiple third-party destinations.)

(A separate gambling website observed during testing, showing the impersonating site redirecting users to multiple third-party destinations.)

What was particularly noticeable was the structure of the destination URLs. Both directed us to a /registration page and contained a series of tracking parameters, including mid, fluid and clickid.

a /registration page and contained a series of tracking parameters, including mid, fluid and clickid.

These types of identifiers are commonly used in affiliate and performance marketing to track where traffic originates and attribute clicks, registrations or conversions. Combined with the fact that the impersonating website was directing users to registration pages across third-party gambling operators, the activity may be linked to affiliate marketing or affiliate fraud.

Affiliate marketing itself is a legitimate and widely used customer acquisition model. In the gambling industry, an affiliate may promote an operator and receive a commission when a referred user completes a particular action, such as creating an account, making a deposit or becoming an active player.

The problem arises when brand impersonation is used to generate those referrals. Instead of attracting users through legitimate advertising or content, a fraudulent affiliate can potentially use the name, logo and reputation of an established wagering brand to capture traffic that it otherwise may not have received.

The model can look something like this:

01 Recognised wagering brand
02 Impersonating website
03 User clicks “Play Now” or “Register”
04 Tracked redirect
05 Third-party gambling operator
06 User registers or deposits
07 Affiliate may receive commission

This helps explain why the impersonating website doesn’t necessarily need to process a payment or steal credentials itself. The traffic can be the thing being monetised. If the person behind the site can use a recognised brand to generate clicks and registrations for another gambling operator, there may be a financial incentive every time that journey results in a qualifying conversion.

Redirect chains can also make the relationship between the original impersonating website and the eventual destination harder to see. By the time the user reaches the registration page, they may have moved across different domains while tracking identifiers preserve information about where the referral originated.

In this type of campaign, the impersonated website isn’t necessarily the final destination. The brand itself becomes the lure used to generate and redirect traffic, while the affiliate model potentially provides the financial incentive behind it.

What This Means for Wagering Brands

This type of abuse shows that brand impersonation does not always end with a fake login page or cloned website. In some cases, a trusted brand can be used to attract users before directing them towards entirely different gambling services.

For wagering operators, that creates several risks. Customers may believe the redirect is part of the legitimate brand experience or associate unrelated gambling platforms with the operator. If something goes wrong further along that journey, the customer may still associate the experience with the brand they initially thought they were dealing with.

There is also the potential for traffic and customer acquisition to be diverted away from the legitimate operator. Instead of reaching the brand they intended to visit, users can be redirected towards competing or unrelated gambling services, potentially generating value for the parties responsible for the impersonation.

Ultimately, the legitimate brand has no control over where the customer is sent or what happens once they get there, but its name and reputation are being used to get them there.

Protecting Wagering Brands from Impersonation

Detecting the impersonating website is only the first step. Organisations also need visibility into where users are being redirected, whether other domains or digital assets are involved, and how those threats may be connected.

This means monitoring for unauthorised brand use across domains, websites, paid advertisements, social media and other digital channels, while investigating redirect paths and related infrastructure rather than treating every threat as an isolated incident.

unphish combines continuous threat monitoring, investigation and enforcement with Campaign Clustering & Intelligence to identify connections between related threats and help organisations uncover and disrupt the wider campaign.

For wagering brands, this means understanding not only where your brand is being impersonated, but where that impersonation is taking your customers.

If your brand is being impersonated online, contact the unphish team to learn how we can help detect, investigate and disrupt the wider threat.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account