You see a sponsored ad on Facebook. It’s from what looks like a well-known brand. The logo is right. The offer is compelling. You click, land on what appears to be a Google Play page, check the developer’s name, read a few glowing reviews, and hit install.
You just installed something on your device. And none of it was real.
This is one of the active phishing campaigns our team is currently monitoring and enforcing against. It’s sophisticated, it’s scaling fast, and most victims have no idea it’s happening.
How the Attack Chain Works
This isn’t a single phishing page sitting on a dodgy domain. It’s a coordinated multi-platform operation with several moving parts working together.
Step 1: Fake Facebook profile. Attackers create Facebook profiles impersonating a legitimate brand or creating casino-adjacent pages with enough credibility to run paid advertising.
Step 2: Meta Ads using real brand assets. The fake profiles run paid Meta advertisements using the real brand's logo, colours, and promotional language. Welcome bonuses, free spins, exclusive offers. These ads appear in Facebook and Instagram feeds just like legitimate sponsored content. They look real because the assets are real.
Step 3: Redirect to a fake app download domain. Clicking the ad doesn't take you to an official app store. It takes you to a domain hosted on the open web, built to look exactly like a Google Play Store page. The URL gives nothing away to an untrained eye. The page gives everything away if you know what to look for.
Step 4: Victim downloads an install file. The download button doesn't pull from Google's servers. It pulls from the fraudulent domain. What gets installed on your device is unknown until it runs.
This is a fully engineered trust chain. Every stage is designed to lower your guard before the next one.
Why Attackers Use Download Domains
Official app stores impose controls that make large-scale abuse more difficult. Applications submitted to Google Play and the Apple App Store are subject to review processes, developer requirements, and security controls that can delay or prevent malicious applications from being distributed.
By directing users to dedicated download domains, attackers operate outside those controls. They can host applications directly, change content without review, rotate infrastructure quickly, and launch new domains as older ones are suspended.
For threat actors running large-scale campaigns, these domains provide a level of flexibility and resilience that official app stores do not.
Why Victims Trust It
This is where it gets interesting. These pages aren’t just visually convincing. They’re psychologically engineered.
Fake developer credentials. The app is listed as being developed by the legitimate brand’s own development team. To a casual user checking the developer’s name before installing, this looks like confirmation the app is official.
Fabricated reviews and star ratings. Fake five-star reviews, thousands of fake download counts, detailed user comments praising the app. This mimics exactly what a legitimate, well-reviewed app looks like on Google Play. Victims do the right thing and check the reviews. The reviews are fake.
Cloned Google Play UI. Many of these domains replicate the Google Play Store interface almost perfectly using copied HTML and CSS. The layout, icons, install button, security data section. All of it is designed to make the page look indistinguishable from the real thing at a glance.
This isn’t accidental. It’s deliberate friction reduction at every decision point where a victim might pause and question what they’re looking at.
The techniques used in this campaign closely resemble those documented in PlayPraetor, a large-scale operation first reported by CTM360 in 2025.
What We're Currently Seeing
Across our monitoring and enforcement activities, we’ve observed a significant volume of domains using these techniques, highlighting both its scale and persistence.
The domains share consistent patterns. Many incorporate app store branding directly into the domain name itself (e.g., play-brand-au.store, brand-cashcloudcore.click). This is both a red flag for investigators and a deliberate credibility tactic for victims who glance at the URL and see familiar app store terminology.
The Meta ad campaigns are short-lived by design. Ads run for a matter of days before rotating to new creative and new domains. The speed of rotation suggests the operators anticipate enforcement and build replacement infrastructure ahead of time.
The ads themselves are running across Facebook with active status, using real brand logos in the ad image, fake star ratings, and calls to action directing users to “Play game” with the URL displaying play.google.com as the destination. It’s not going to play.google.com.
How to Spot a Fake App Download Domain
For brands and security teams monitoring for this type of abuse, here’s what to look for:
- The URL isn't an official app store. Legitimate Google Play links start with play.google.com. Any other domain hosting what looks like a Google Play page should be treated with caution and verified independently before downloading anything.
- App store branding in the domain name. Attackers frequently embed "play," "store," "google," or "apk" into the domain to appear legitimate at a glance.
- The developer’s name is too perfect. Fake pages list the real brand's developer credentials. If an app outside the official store claims to be developed by a major brand, verify directly on the official store.
- The ad destination doesn't match the landing page URL. Meta ads in this campaign display play.google.com as the destination while redirecting to a fraudulent domain.
- Unsolicited sponsored ads promoting app downloads. Legitimate brands rarely push app installs through Facebook ads to external download pages.
The Takedown Approach
When we identify domains tied to this campaign, enforcement runs on three tracks simultaneously.
Domain enforcement. DNS abuse reports to registrars with full evidence packages including screenshots of the fake app page, infrastructure details, and brand authorization. The goal is full domain suspension.
Facebook profile reporting. The fake profiles running the ads are reported directly to Meta for impersonation and fraudulent activity. Linking the ads as evidence is also recommended.
Meta ad reporting. Individual ads are reported through Meta’s ad reporting mechanism for misleading content and fraudulent destination URLs.
The domain enforcement tends to be the most effective lever. When the destination domain gets suspended, the ads become useless regardless of whether Meta acts quickly.
Key Takeaways
Fake app download domains are a growing enforcement challenge because they exploit trust at every level: trusted platforms, trusted brand assets, trusted UI patterns, and trusted social proof. By the time a victim reaches the download button, they’ve passed through multiple stages of manufactured legitimacy.
For brands, the challenge extends beyond identifying individual domains. Effective disruption requires visibility across the broader attack chain, including impersonating social media profiles, sponsored advertisements, malicious domains, and fraudulent application download pages. That’s why unphish monitors and disrupts threats across multiple digital channels, helping organisations identify related infrastructure and understand the wider campaign rather than treating each threat as an isolated incident. Focusing on a single component often leaves the underlying campaign intact.
If you’re a consumer, always download applications directly from the official Google Play Store or Apple App Store. If a link originates from a social media advertisement, navigate to the official app store yourself and search for the application independently.
The app store you just visited might not be the app store at all.
