Cybersecurity Reach Foundation
Scam Alert

Direct Deposit of $13,963.99 - Affiliate Phishing Scam

A phishing email claims you’ve received a direct deposit of $13,963.99, tempting you to click a hidden link. Instead of delivering money, the scam funnels you through a series of deceptive redirects to an offshore gambling site, earning the scammers referral profits.

Direct Deposit of $13,963.99 - Affiliate Phishing Scam

The Scenario

The scam begins when the victim receives an HTML-based phishing email with the subject and body highlighting a large “Direct Deposit of $13,963.99” to their account. The amount is presented as an image to bypass spam filters, alongside odd formatting like “(No_Deposit_Required)” and false Google branding to create trust. A hidden hyperlink, concealed with display:none styling, sends the user through a Google Cloud Storage link - a technique to evade detection - and onward to a malicious landing page (http://imd2.usualtimateur.in.net/dororo.html). This page displays a fake “Prove you’re not a robot” reCAPTCHA and carries the misleading browser tab title “Unsubscribe.” Completing the fake reCAPTCHA triggers a final redirect to DuckyLuck.ag, an unregulated online casino with a history of scam complaints, delayed payments, and deceptive promotions. The attacker’s goal is affiliate fraud - generating commission payments by sending unsuspecting visitors to the gambling site, not stealing sensitive information directly.

Red Flags to Watch For

💸 Temptation Bait: Promises a large financial reward to trigger hasty clicks.

🔍 Misleading Branding: Pretends to be from Google but redirects to gambling sites.

🚫 Insecure Connection: Uses HTTP instead of HTTPS for sensitive interactions

How to Protect Yourself

Check the link and verify site legitimacy – Ensure the URL is correct and the site is trustworthy before interacting.

Avoid entering sensitive information on suspicious platforms – Only provide personal or financial details on trusted, verified sites.

Verify all bank transactions directly with your bank – Never confirm them through outside webpages or links.

Investigated By

Tenzin Phuntsok

Tenzin Phuntsok

Threat Researcher