Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)
Turkish Banking & Government-Portal Fraud Ecosystem (TL-2026-1313), also tracked as Turkish e-Devlet Phishing Ecosystem, is a high-severity phishing campaign, first published 2026-07-14. It has no confirmed attribution, affects Turkish Banking Sector Online/mobile banking customer portals, maps to 31 MITRE ATT&CK techniques (T1027.002, T1102.002, T1111), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1313
- Threat ID
- TL-2026-1313
- Also known as
- Turkish e-Devlet Phishing Ecosystem, Turkish Banking Fraud Value Chain, e-Devlet Refund APK Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, government administration, public sector, consumer retail banking customers
- Target regions
- turkey, Europe, Middle East
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Turkish Banking & Government-Portal Fraud Ecosystem
Malware and tooling: Unnamed Android Remote Access Trojan (e-Devlet impersonation cluster), Turkish Bank Phishing Kit (~$250 underground commercial kit)
Group-IB's Digital Risk Protection platform and CERT-GIB uncovered a coordinated Turkish fraud ecosystem spanning five interconnected schemes: bank-impersonation phishing (8,400+ domains), e-Devlet government-portal impersonation (6,700+ domains), Meta-ad-driven credential theft (6,600+ scam ads/month, 80%+ via Facebook/Instagram), fake loan and investment offers, and money-mule-based cash-out through fragmented transfers and cryptocurrency conversion. A commercial phishing kit sold for roughly $250 supports most major Turkish banks and underpins at least four campaign clusters.
How Turkish Banking & Government-Portal Fraud Ecosystem works
Between November 2025 and April 2026, Group-IB researchers tracked a large-scale, financially motivated fraud ecosystem targeting Turkish banking customers and citizens using Turkey's e-Devlet (turkiye.gov.tr) government services portal. Rather than a single attributed actor, Group-IB characterizes the campaign as five interconnected criminal schemes operating as a coordinated value chain: victim acquisition via social media malvertising, credential theft via cloned banking/government interfaces, fraudulent loan and investment lures, government-portal impersonation for identity-document and payment-refund fraud, and money-mule-based laundering through cryptocurrency exchanges.
The core enabling technology is a commercial phishing-kit-as-a-service sold on underground channels for approximately $250, which ships templates and credential-collection panels supporting the majority of Turkish banks. At least four distinct campaign clusters were observed reusing this shared tooling, indicating a phishing-kit reseller model that lowers the technical barrier for new operators. Infrastructure is rotated roughly weekly (new domains, same templates/backend panels) specifically to outpace takedown and blocklisting.
Distribution is overwhelmingly (80%+) via Meta advertising on Facebook and Instagram. Ads are deliberately short-lived — replaced roughly every 30 minutes — defeating conventional ad-review and reporting workflows; by the time a malicious ad or landing page is reported, the operators have already rotated to new creative and infrastructure. Ad themes span fraudulent banking login pages, fake investment platforms, fake gambling sites, fraudulent consumer loan offers, and fake government-service pages.
A parallel and thematically linked vector documented by Cyble targets Turkish e-Devlet users with a phishing site (scanyalx[.]online) that harvests identity/TC kimlik credentials under a card-fee-refund pretext and then distributes an Android Remote Access Trojan (APK lures: edevletiadesistemi.apk, edevlet.apk, cimer.apk) with VNC-based remote control, keylogging, SMS interception/exfiltration, contact harvesting, and accessibility-service abuse for on-device fraud. The RAT retrieves C2 addresses indirectly via Telegram/ICQ channels rather than hardcoding them, and calls back to a2a2a2a[.]life. This RAT-based e-Devlet impersonation cluster shares the same lure theme, victim population, and government-portal-trust abuse pattern documented in the broader Group-IB ecosystem, though it is reported by a separate vendor and should be treated as an associated, thematically-linked cluster rather than confirmed common infrastructure.
Group-IB additionally documented a distinct smishing/vishing sub-scheme targeting Turkish pensioners: SMS messages impersonating e-Devlet and the Social Security Institution (SGK) promise retroactive pension supplements (e.g., a 3,000 TRY cost-of-living adjustment), driving victims to pixel-perfect cloned e-Devlet/SGK/bank login pages. Harvested TC kimlik numbers, e-Devlet passwords, and banking credentials feed automated account-takeover systems that sweep funds and submit instant consumer-loan applications in the victim's name; a second-stage vishing call impersonating police, prosecutors, or bank officials is then used to extract OTP/verification codes or coerce further transfers. Targeting is believed to be assisted by data from a prior (2023) e-Devlet-related breach. Turkey's cybercrime unit (SİBERAY) issued a public advisory on the smishing wave in June 2026.
Monetization follows a consistent money-mule model: recruitment ads offer Turkish citizens 30,000-50,000 TRY to rent out bank accounts/IBANs; stolen funds are then fragmented across 3-5 mule accounts before conversion via cryptocurrency exchanges to complicate tracing. Turkish courts have handed down sentences of up to 10 years for mule participants. Consumer complaint platform Şikayetvar recorded 23,000+ related complaints during the research window, with individual reported losses as high as $16,000.
MITRE ATT&CK techniques used in TL-2026-1313
Defense Evasion
Command and Control
T1102.002 Bidirectional Communication
Credential Access
T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Collection
T1119 Automated Collection; T1513 Screen Capture; T1636.003 Contact List; T1636.004 SMS Messages
Execution
T1204.001 Malicious Link; T1204.002 Malicious File; T1623.001 Unix Shell
collection
Discovery
command-and-control
Initial Access
T1566 Phishing; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
Impact
T1582 SMS Control; T1641 Data Manipulation; T1657 Financial Theft
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1586.003 Cloud Accounts; T1587.001 Malware; T1588.001 Malware
Reconnaissance
T1589 Gather Victim Identity Information
Persistence
defense-evasion
T1630.001 Uninstall Malicious Application; T1655 Masquerading
Exfiltration
T1646 Exfiltration Over C2 Channel
stealth
Affected products and versions in Turkish Banking & Government-Portal Fraud Ecosystem
- Turkish Banking Sector — Online/mobile banking customer portals (majority of Turkish banks)
Vulnerable versions: all customer-facing web/mobile banking login interfaces - Government of Turkey — e-Devlet Kapısı (turkiye.gov.tr) government services portal
Vulnerable versions: public-facing citizen login/identity-verification flow - Meta Platforms — Facebook and Instagram advertising platform (abused as distribution channel)
Vulnerable versions: Ad Library review/reporting workflow - Google — Android (sideloaded APK ecosystem, Accessibility Services API)
Vulnerable versions: Android devices permitting sideloaded APK installation
Remediation for Turkish Banking & Government-Portal Fraud Ecosystem
Immediate actions
- Block and monitor for known malicious domains and the confirmed Android RAT C2 (a2a2a2a[.]life) and phishing site (scanyalx[.]online) at email/web gateways
- Report and pre-emptively takedown-monitor Meta (Facebook/Instagram) ad accounts and pages impersonating bank brands, government services, loan, investment, and gambling offers
- Deploy brand/domain monitoring (Digital Risk Protection) tuned to weekly-rotating typosquat and e-Devlet/bank-lookalike domain registrations
- Issue customer-facing advisories: government institutions never send SMS with clickable password-entry links; verify domains before entering banking or e-Devlet credentials
- Flag and hold instant consumer-loan applications and outbound transfers immediately following a password-reset or new-device login event
Workarounds
- Educate customers to independently navigate to bank/e-Devlet URLs rather than clicking SMS or social-media ad links
- Enable step-up authentication (out-of-band, non-SMS) for new-device logins and high-value transfers to blunt automated account-takeover-and-sweep flows
- Disable or restrict installation of APKs from unknown sources on Android devices; treat any unsolicited government/bank 'refund' APK download prompt as malicious
Longer-term hardening
- Implement anomaly detection for money-mule account patterns: newly opened/rented accounts receiving fragmented inbound transfers followed by rapid cryptocurrency exchange cash-out
- Partner with Meta Ad Library monitoring and rapid-takedown workflows to counter sub-30-minute ad rotation
- Coordinate with CERT-GIB/Group-IB, Turkish SİBERAY, and national banking ISAC for shared blocklists of the ~$250 commercial phishing kit's templates/panel fingerprints
- Deploy mobile threat defense / Play Protect equivalent controls to block sideloaded APKs invoking Accessibility Services for input-injection and SMS interception
- Strengthen e-Devlet SMS/notification authenticity signals (e.g., verified sender IDs) to reduce trust-abuse smishing effectiveness
Weaknesses (CWE) in Turkish Banking & Government-Portal Fraud Ecosystem
CWE-451, CWE-601, CWE-346, CWE-287
Timeline of Turkish Banking & Government-Portal Fraud Ecosystem
- A prior e-Devlet-related data breach is assessed to have supplied identity data later leveraged to improve targeting precision in the 2026 smishing wave against pensioners.
- Group-IB traces the earliest activity linked to this phishing ecosystem back to August 2023, predating the formal research window.
- Group-IB's Digital Risk Protection platform and CERT-GIB begin the tracked research window, monitoring domain registrations, Meta ad activity, and mule-recruitment posts.
- Cyble documents a related e-Devlet-impersonation phishing site (scanyalx[.]online) distributing an Android RAT via APKs (edevletiadesistemi.apk, edevlet.apk, cimer.apk) with VNC, keylogging, and SMS-theft capability, C2 at a2a2a2a[.]life.
- Group-IB's active research/monitoring window closes, with 8,400+ bank phishing domains, 6,700+ e-Devlet lookalike domains, and 6,600+ monthly scam ads recorded.
- Turkey's cybercrime unit (SİBERAY) issues a formal public advisory warning citizens about the e-Devlet/SGK smishing wave.
- Eastern Herald reports a parallel smishing/vishing sub-scheme targeting Turkish pensioners with fake retroactive pension-supplement SMS lures driving credential theft and automated account takeover.
- Group-IB's findings are publicly reported by Cyber Security News, The420.in, and CyberPress, disclosing the full scale of the campaign: 8,400+ phishing domains, 6,700+ government-portal lookalikes, 6,600+ monthly scam ads, a ~$250 commercial phishing kit, and 23,000+ victim complaints via Şikayetvar.
Sources cited for Turkish Banking & Government-Portal Fraud Ecosystem
- Turkish Banks Targeted by 8,400 Phishing Domains
- 8,400 Phishing Domains Targeted Turkish Banks, Group-IB Reveals
- Scammers Use 8,400 Phishing Domains to Target Turkish Banking Customers
- The Turkish Government Masqueraded Site Distributing Android RAT
- Turkey's Retired Millions Are Targets: How Fake e-Devlet Links Are Draining Bank Accounts
- Group-IB Unites Partners to Strengthen Turkey's Cybersecurity Landscape
- Huge set of Turkish banks' cards on sale on dark net marketplace | Group-IB
- Deep water: exploring phishing kits | Group-IB Blog
- Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns | Group-IB Blog
Threats related to Turkish Banking & Government-Portal Fraud Ecosystem
Detection coverage for TL-2026-1313
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1313 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.