FriendlyDealer mimics official app stores to push unvetted gambling apps

2026-03-23T20:51:51Z1d428df919e4fa15340faf2b8999bd742fdddfdd102d7b6fb0776a76b9d231f9
AV-evasionAndroid-accessibility-abuseAndroid-sideloadingCVE-2026-20643DarkSwordPureHVNCSEO-poisoningVidarWebKitZombie-ZIPcrypto-phishingfake-app-storesfake-shopsgambling-fraudiOS-exploitationmobile-malwarephishingprivacyscam-playbookweb-based-apps

What happened

Malwarebytes published a series of March 2026 reports covering widespread scam and malware activity: a network of 1,500+ fake app-store sites (FriendlyDealer) distributing unvetted/cloned web-based gambling apps; large networks of fake shops and crypto-phishing sites; PureHVNC and Vidar infections delivered via Google Forms and hacked WordPress “verify” pages; state-level iPhone attacks using the DarkSword vulnerability chain; an Apple WebKit fix (CVE-2026-20643); Android sideloading and accessibility abuse changes (Advanced Flow, Google crackdown); SEO-poisoning lures for VPN/corporate login盗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
1d428df919e4fa15340faf2b8999bd742fdddfdd102d7b6fb0776a76b9d231f9
Enrichment time
2026-03-23T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FriendlyDealer mimics official app stores to push unvetted gambling apps · Baitaphish