"A soulless project that is made for profit"
Fake Casino SaaS — gambler-partners.is — URLScan: hash fingerprint | page title fingerprint
GAMBLER is a Russian-language Scam-as-a-Service (SaaS) fake casino platform. Active since August 2024, it provides turnkey fraudulent casino websites to 6,000+ affiliates. Admins admitted to $50 million+ in deposits in one year from the "blue" design alone, with "all deposits going one way" (victims never get money back). Their stated goal is $2 billion in deposits.
Instagram/TikTok/Discord ads: "Exclusive celebrity partnership. Get $2,500 free credit with promo code!"
Victim plays rigged slots. Engine shows fake wins via "automatic spin-up." Balance grows. Wants to withdraw.
"Deposit ~$100 to verify identity." Fake ToS with %sum_verif% variables. Withdrawal reminder popup every 3 hours.
GAMBLER AI "closes objections" 24/7. 80% repeat deposit rate. Victim keeps depositing for weeks/months.
Final: "Connect wallet to withdraw." WalletConnect drains all crypto. Record: $90K single drain.
@gamblerworkmain
@lord_gamb
Key messages from GAMBLER Telegram channels. Click to expand. Full dumps: GAMBLER NEWS | Tech News
Domains detected via URLScan fingerprinting. Click to expand. Search by content hash or page title for latest results.
Channel ID: 2073492571 — Full chat dump — 61 photos, 7 videos

















Channel ID: 2260103997 — Full chat dump — 25 photos














































GAMBLER's 5,515+ domains are auto-detected by PhishDestroy Keitaro Hunter. Same Keitaro TDS fingerprints, identical panel structure, reused templates. They know it — that's why they distribute anti-PhishDestroy counter-phishing templates to partners, specifically naming @PhishDestroy_bot as a threat to counter.
After GAMBLER published a post in their channel about mass reports and distributed anti-PhishDestroy templates, we understood that the scammers had lost their fear. In response, PhishDestroy targeted their oldest and most established domains — those active for 6 months or more — and took down over 3,000 domains within a few weeks.
Previously, our automated system was sending only one report per domain as a standard approach, since the operation has thousands of sites. After their anti-PhishDestroy campaign, we configured dedicated parsers to automatically detect and report GAMBLER infrastructure using URLScan fingerprints (hash + page title). Their domains are now automatically detected and reported at scale.
15 endpoints: promo codes, victim wallet extraction, domain management, AI toggle, rigged game coefficients. Click to view full API docs.
Intelligence collected by PhishDestroy | GitHub
This data is provided for law enforcement, security research, and anti-fraud purposes.