Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)

Turkish Banking & Government-Portal Fraud Ecosystem (TL-2026-1313), also tracked as Turkish e-Devlet Phishing Ecosystem, is a high-severity phishing campaign, first published 2026-07-14. It has no confirmed attribution, affects Turkish Banking Sector Online/mobile banking customer portals, maps to 31 MITRE ATT&CK techniques (T1027.002, T1102.002, T1111), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1313

Threat ID
TL-2026-1313
Also known as
Turkish e-Devlet Phishing Ecosystem, Turkish Banking Fraud Value Chain, e-Devlet Refund APK Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-14
Last reviewed
2026-07-14
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, banking, government administration, public sector, consumer retail banking customers
Target regions
turkey, Europe, Middle East
Detection rules
9
Indicators of compromise
20

Malware and tooling in Turkish Banking & Government-Portal Fraud Ecosystem

Malware and tooling: Unnamed Android Remote Access Trojan (e-Devlet impersonation cluster), Turkish Bank Phishing Kit (~$250 underground commercial kit)

Group-IB's Digital Risk Protection platform and CERT-GIB uncovered a coordinated Turkish fraud ecosystem spanning five interconnected schemes: bank-impersonation phishing (8,400+ domains), e-Devlet government-portal impersonation (6,700+ domains), Meta-ad-driven credential theft (6,600+ scam ads/month, 80%+ via Facebook/Instagram), fake loan and investment offers, and money-mule-based cash-out through fragmented transfers and cryptocurrency conversion. A commercial phishing kit sold for roughly $250 supports most major Turkish banks and underpins at least four campaign clusters.

How Turkish Banking & Government-Portal Fraud Ecosystem works

Between November 2025 and April 2026, Group-IB researchers tracked a large-scale, financially motivated fraud ecosystem targeting Turkish banking customers and citizens using Turkey's e-Devlet (turkiye.gov.tr) government services portal. Rather than a single attributed actor, Group-IB characterizes the campaign as five interconnected criminal schemes operating as a coordinated value chain: victim acquisition via social media malvertising, credential theft via cloned banking/government interfaces, fraudulent loan and investment lures, government-portal impersonation for identity-document and payment-refund fraud, and money-mule-based laundering through cryptocurrency exchanges.

The core enabling technology is a commercial phishing-kit-as-a-service sold on underground channels for approximately $250, which ships templates and credential-collection panels supporting the majority of Turkish banks. At least four distinct campaign clusters were observed reusing this shared tooling, indicating a phishing-kit reseller model that lowers the technical barrier for new operators. Infrastructure is rotated roughly weekly (new domains, same templates/backend panels) specifically to outpace takedown and blocklisting.

Distribution is overwhelmingly (80%+) via Meta advertising on Facebook and Instagram. Ads are deliberately short-lived — replaced roughly every 30 minutes — defeating conventional ad-review and reporting workflows; by the time a malicious ad or landing page is reported, the operators have already rotated to new creative and infrastructure. Ad themes span fraudulent banking login pages, fake investment platforms, fake gambling sites, fraudulent consumer loan offers, and fake government-service pages.

A parallel and thematically linked vector documented by Cyble targets Turkish e-Devlet users with a phishing site (scanyalx[.]online) that harvests identity/TC kimlik credentials under a card-fee-refund pretext and then distributes an Android Remote Access Trojan (APK lures: edevletiadesistemi.apk, edevlet.apk, cimer.apk) with VNC-based remote control, keylogging, SMS interception/exfiltration, contact harvesting, and accessibility-service abuse for on-device fraud. The RAT retrieves C2 addresses indirectly via Telegram/ICQ channels rather than hardcoding them, and calls back to a2a2a2a[.]life. This RAT-based e-Devlet impersonation cluster shares the same lure theme, victim population, and government-portal-trust abuse pattern documented in the broader Group-IB ecosystem, though it is reported by a separate vendor and should be treated as an associated, thematically-linked cluster rather than confirmed common infrastructure.

Group-IB additionally documented a distinct smishing/vishing sub-scheme targeting Turkish pensioners: SMS messages impersonating e-Devlet and the Social Security Institution (SGK) promise retroactive pension supplements (e.g., a 3,000 TRY cost-of-living adjustment), driving victims to pixel-perfect cloned e-Devlet/SGK/bank login pages. Harvested TC kimlik numbers, e-Devlet passwords, and banking credentials feed automated account-takeover systems that sweep funds and submit instant consumer-loan applications in the victim's name; a second-stage vishing call impersonating police, prosecutors, or bank officials is then used to extract OTP/verification codes or coerce further transfers. Targeting is believed to be assisted by data from a prior (2023) e-Devlet-related breach. Turkey's cybercrime unit (SİBERAY) issued a public advisory on the smishing wave in June 2026.

Monetization follows a consistent money-mule model: recruitment ads offer Turkish citizens 30,000-50,000 TRY to rent out bank accounts/IBANs; stolen funds are then fragmented across 3-5 mule accounts before conversion via cryptocurrency exchanges to complicate tracing. Turkish courts have handed down sentences of up to 10 years for mule participants. Consumer complaint platform Şikayetvar recorded 23,000+ related complaints during the research window, with individual reported losses as high as $16,000.

MITRE ATT&CK techniques used in TL-2026-1313

Defense Evasion

T1027.002 Software Packing

Command and Control

T1102.002 Bidirectional Communication

Credential Access

T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Collection

T1119 Automated Collection; T1513 Screen Capture; T1636.003 Contact List; T1636.004 SMS Messages

Execution

T1204.001 Malicious Link; T1204.002 Malicious File; T1623.001 Unix Shell

collection

T1417.001 Keylogging

Discovery

T1418 Software Discovery

command-and-control

T1437.001 Web Protocols

Initial Access

T1566 Phishing; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

Impact

T1582 SMS Control; T1641 Data Manipulation; T1657 Financial Theft

Resource Development

T1583.001 Domains; T1585.001 Social Media Accounts; T1586.003 Cloud Accounts; T1587.001 Malware; T1588.001 Malware

Reconnaissance

T1589 Gather Victim Identity Information

Persistence

T1624.001 Broadcast Receivers

defense-evasion

T1630.001 Uninstall Malicious Application; T1655 Masquerading

Exfiltration

T1646 Exfiltration Over C2 Channel

stealth

T1684.001 Impersonation

Affected products and versions in Turkish Banking & Government-Portal Fraud Ecosystem

  • Turkish Banking Sector — Online/mobile banking customer portals (majority of Turkish banks)
    Vulnerable versions: all customer-facing web/mobile banking login interfaces
  • Government of Turkey — e-Devlet Kapısı (turkiye.gov.tr) government services portal
    Vulnerable versions: public-facing citizen login/identity-verification flow
  • Meta Platforms — Facebook and Instagram advertising platform (abused as distribution channel)
    Vulnerable versions: Ad Library review/reporting workflow
  • Google — Android (sideloaded APK ecosystem, Accessibility Services API)
    Vulnerable versions: Android devices permitting sideloaded APK installation

Remediation for Turkish Banking & Government-Portal Fraud Ecosystem

Immediate actions

  • Block and monitor for known malicious domains and the confirmed Android RAT C2 (a2a2a2a[.]life) and phishing site (scanyalx[.]online) at email/web gateways
  • Report and pre-emptively takedown-monitor Meta (Facebook/Instagram) ad accounts and pages impersonating bank brands, government services, loan, investment, and gambling offers
  • Deploy brand/domain monitoring (Digital Risk Protection) tuned to weekly-rotating typosquat and e-Devlet/bank-lookalike domain registrations
  • Issue customer-facing advisories: government institutions never send SMS with clickable password-entry links; verify domains before entering banking or e-Devlet credentials
  • Flag and hold instant consumer-loan applications and outbound transfers immediately following a password-reset or new-device login event

Workarounds

  • Educate customers to independently navigate to bank/e-Devlet URLs rather than clicking SMS or social-media ad links
  • Enable step-up authentication (out-of-band, non-SMS) for new-device logins and high-value transfers to blunt automated account-takeover-and-sweep flows
  • Disable or restrict installation of APKs from unknown sources on Android devices; treat any unsolicited government/bank 'refund' APK download prompt as malicious

Longer-term hardening

  • Implement anomaly detection for money-mule account patterns: newly opened/rented accounts receiving fragmented inbound transfers followed by rapid cryptocurrency exchange cash-out
  • Partner with Meta Ad Library monitoring and rapid-takedown workflows to counter sub-30-minute ad rotation
  • Coordinate with CERT-GIB/Group-IB, Turkish SİBERAY, and national banking ISAC for shared blocklists of the ~$250 commercial phishing kit's templates/panel fingerprints
  • Deploy mobile threat defense / Play Protect equivalent controls to block sideloaded APKs invoking Accessibility Services for input-injection and SMS interception
  • Strengthen e-Devlet SMS/notification authenticity signals (e.g., verified sender IDs) to reduce trust-abuse smishing effectiveness

Weaknesses (CWE) in Turkish Banking & Government-Portal Fraud Ecosystem

CWE-451, CWE-601, CWE-346, CWE-287

Timeline of Turkish Banking & Government-Portal Fraud Ecosystem

  • A prior e-Devlet-related data breach is assessed to have supplied identity data later leveraged to improve targeting precision in the 2026 smishing wave against pensioners.
  • Group-IB traces the earliest activity linked to this phishing ecosystem back to August 2023, predating the formal research window.
  • Group-IB's Digital Risk Protection platform and CERT-GIB begin the tracked research window, monitoring domain registrations, Meta ad activity, and mule-recruitment posts.
  • Cyble documents a related e-Devlet-impersonation phishing site (scanyalx[.]online) distributing an Android RAT via APKs (edevletiadesistemi.apk, edevlet.apk, cimer.apk) with VNC, keylogging, and SMS-theft capability, C2 at a2a2a2a[.]life.
  • Group-IB's active research/monitoring window closes, with 8,400+ bank phishing domains, 6,700+ e-Devlet lookalike domains, and 6,600+ monthly scam ads recorded.
  • Turkey's cybercrime unit (SİBERAY) issues a formal public advisory warning citizens about the e-Devlet/SGK smishing wave.
  • Eastern Herald reports a parallel smishing/vishing sub-scheme targeting Turkish pensioners with fake retroactive pension-supplement SMS lures driving credential theft and automated account takeover.
  • Group-IB's findings are publicly reported by Cyber Security News, The420.in, and CyberPress, disclosing the full scale of the campaign: 8,400+ phishing domains, 6,700+ government-portal lookalikes, 6,600+ monthly scam ads, a ~$250 commercial phishing kit, and 23,000+ victim complaints via Şikayetvar.

Sources cited for Turkish Banking & Government-Portal Fraud Ecosystem

Threats related to Turkish Banking & Government-Portal Fraud Ecosystem

Detection coverage for TL-2026-1313

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1313 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats