Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report) — Threadlinqs Intelligence
As of 2026-08-23, Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report) is a high-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 14 indicators of compromise.
Threat ID: TL-2026-2126 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
CloudSEK documented a seasonal illegal-betting fraud ecosystem active during IPL 2026, spanning 1,200+ domains and a single backend managing 25+ betting sites, that used purchased clone scripts, AI
On May 20, 2026, CloudSEK published "Hit Wicket: Inside The Expansive Web of Scams Targeting Millions of IPL Fans This Season," authored by researcher Sourajeet Majumder, documenting what the firm characterizes as "not a collection of opportunistic scams" but "a structured, seasonal criminal industry" built around India's IPL cricket tournament.
The fraud chain begins with discovery and recruitment: self-styled "tipper" accounts on Telegram, Instagram, and YouTube Shorts promote betting/prediction platforms via affiliate referral links, earning commissions per referred depositor. AI-generated deepfake videos cloning the faces and voices of Indian public figures — CloudSEK specifically names YouTuber/content creator Ranveer Allahbadia and cricketer Smriti Mandhana — are used without consent to manufacture false endorsements of these platforms. Reach is amplified through bulk SMS campaigns using spoofed sender IDs, and through Meta Ads and Google Ads purchased to target cricket fans; the underlying phone-number lists used for SMS targeting are themselves harvested and sold by dedicated lead-generation services.
On the platform side, clone betting scripts are sold openly on Telegram and underground forums, letting operators stand up new betting sites rapidly and cheaply. CloudSEK obtained visibility into the admin panel of one such operation and found a single backend simultaneously managing 25+ distinct betting websites, offering live odds, in-play betting, deposit bonuses, and referral programs across all of them. The admin panel provides real-time user-activity tracking and an agent-based, territory-assigned operator structure with centralized, manual control over withdrawal approval/denial. Early wins are engineered to build user confidence and encourage larger deposits; once deposits grow, withdrawal requests are deliberately — not technically — denied by platform agents. CloudSEK's access to this single admin panel showed more than 9,300 withdrawal requests rejected between May 2025 and May 2026, worth an estimated ₹4.65 crore, with individual denied withdrawals documented up to ₹5 lakh.
Victims who chase lost deposits or seek recovery funds are steered toward fake loan apps that request excessive Android permissions to harvest contacts, call logs, and photos from the device; this data is then used to blackmail and coerce victims, a secondary extortion layer on top of the direct financial loss from blocked withdrawals.
A distinct pillar of the ecosystem is black-hat SEO abuse of Indian government (.gov.in) websites: CloudSEK reports use of "Hacklink Market," an open marketplace where cybercriminals can purchase access to thousands of already-compromised websites and receive dedicated control panels for injecting keyword-rich anchor-text backlinks. Attackers used this to inject betting-platform backlinks directly into .gov.in sites, exploiting the high domain authority and inherited institutional trust of government domains to elevate betting destinations in organic search rankings. A press query CloudSEK/reporting outlets sent to India's Ministry of Electronics and IT (MeitY) about the compromised government websites went unanswered as of publication.
Fund movement is handled through money-mule networks recruited via Telegram and WhatsApp; mules receive deposited funds into business-registered bank accounts, which mask the operators' identity and lend a veneer of legitimacy to the transactions. Follow-on reporting additionally describes cryptocurrency laundering routes and traditional hawala transfers used to move proceeds out of the formal banking system.
CloudSEK frames the operation as recurring and seasonal: infrastructure (domains, scripts, deepfake content, ad campaigns) is developed and refreshed year-round and escalates sharply during each IPL tournament window, with rapid platform-renewal cycles (spinning up new domains as old ones are reported/blocked) deliberately outpacing enforcement and takedown efforts.
Target sectors: government administration, consumer, financial-services, sports-entertainment
Target regions: india
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 14 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1583.008, T1584.004, T1585.001, T1588.007, T1608.006, T1650, T1684.001, T1204.001