Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB) — Threadlinqs Intelligence
As of 2026-07-14, Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1313 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Group-IB's Digital Risk Protection platform and CERT-GIB uncovered a coordinated Turkish fraud ecosystem spanning five interconnected schemes: bank-impersonation phishing (8,400+ domains), e-Devlet
Between November 2025 and April 2026, Group-IB researchers tracked a large-scale, financially motivated fraud ecosystem targeting Turkish banking customers and citizens using Turkey's e-Devlet (turkiye.gov.tr) government services portal. Rather than a single attributed actor, Group-IB characterizes the campaign as five interconnected criminal schemes operating as a coordinated value chain: victim acquisition via social media malvertising, credential theft via cloned banking/government interfaces, fraudulent loan and investment lures, government-portal impersonation for identity-document and payment-refund fraud, and money-mule-based laundering through cryptocurrency exchanges.
The core enabling technology is a commercial phishing-kit-as-a-service sold on underground channels for approximately $250, which ships templates and credential-collection panels supporting the majority of Turkish banks. At least four distinct campaign clusters were observed reusing this shared tooling, indicating a phishing-kit reseller model that lowers the technical barrier for new operators. Infrastructure is rotated roughly weekly (new domains, same templates/backend panels) specifically to outpace takedown and blocklisting.
Distribution is overwhelmingly (80%+) via Meta advertising on Facebook and Instagram. Ads are deliberately short-lived — replaced roughly every 30 minutes — defeating conventional ad-review and reporting workflows; by the time a malicious ad or landing page is reported, the operators have already rotated to new creative and infrastructure. Ad themes span fraudulent banking login pages, fake investment platforms, fake gambling sites, fraudulent consumer loan offers, and fake government-service pages.
A parallel and thematically linked vector documented by Cyble targets Turkish e-Devlet users with a phishing site (scanyalx[.]online) that harvests identity/TC kimlik credentials under a card-fee-refund pretext and then distributes an Android Remote Access Trojan (APK lures: edevletiadesistemi.apk, edevlet.apk, cimer.apk) with VNC-based remote control, keylogging, SMS interception/exfiltration, contact harvesting, and accessibility-service abuse for on-device fraud. The RAT retrieves C2 addresses indirectly via Telegram/ICQ channels rather than hardcoding them, and calls back to a2a2a2a[.]life. This RAT-based e-Devlet impersonation cluster shares the same lure theme, victim population, and government-portal-trust abuse pattern documented in the broader Group-IB ecosystem, though it is reported by a separate vendor and should be treated as an associated, thematically-linked cluster rather than confirmed common infrastructure.
Group-IB additionally documented a distinct smishing/vishing sub-scheme targeting Turkish pensioners: SMS messages impersonating e-Devlet and the Social Security Institution (SGK) promise retroactive pension supplements (e.g., a 3,000 TRY cost-of-living adjustment), driving victims to pixel-perfect cloned e-Devlet/SGK/bank login pages. Harvested TC kimlik numbers, e-Devlet passwords, and banking credentials feed automated account-takeover systems that sweep funds and submit instant consumer-loan applications in the victim's name; a second-stage vishing call impersonating police, prosecutors, or bank officials is then used to extract OTP/verification codes or coerce further transfers. Targeting is believed to be assisted by data from a prior (2023) e-Devlet-related breach. Turkey's cybercrime unit (SİBERAY) issued a public advisory on the smishing wave in June 2026.
Monetization follows a consistent money-mule model: recruitment ads offer Turkish citizens 30,000-50,000 TRY to rent out bank accounts/IBANs; stolen funds are then fragmented across 3-5 mule accounts before conversion via cryptocurrency exchanges to complicate tracing. Turkish courts have handed down sentences of up to 10 years for mule participants. Consumer complaint platform Şikayetvar recorded 23,000+ related complaints during the research win
Weaknesses (CWE)
CWE-451, CWE-601, CWE-346, CWE-287
Target sectors: financial services, banking, government administration, public sector, consumer retail banking customers
Target regions: turkey, Europe, Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1585.001, T1588.001, T1587.001, T1586.003, T1566, T1566.003, T1566.002, T1204.001