Google Play Early Access Abused for Deceptive Android Apps
Threat actors are exploiting Google Play's Early Access program to distribute thousands of deceptive apps, including fake casino games and reward apps, by

Bad actors are misusing Google Play's Early Access program to push thousands of deceptive Android applications. These apps falsely promise cash rewards, casino jackpots, and premium content, according to a report from cybersecurity firm Bitdefender shared with The Hacker News.
Google's Early Access program is designed for developers to gather user feedback on unreleased apps. A key feature is that users cannot leave public reviews or star ratings for these applications. Bitdefender warns this has created a new avenue for abuse, stripping users of a critical early warning system. "The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted," the company stated.
The Deceptive App Ecosystem
These deceptive Early Access apps are promoted through TikTok, Facebook, and other social media platforms. The ads often use bogus videos featuring celebrity deepfakes generated with artificial intelligence. A recurring pattern involves apps promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, or free casino spins.
Many applications rely on a similar engagement loop. A user installs the app after seeing an ad. They may receive generous virtual rewards initially, but progression slows dramatically once they reach a withdrawal threshold. The promised payout never arrives. The primary goal is to generate illicit revenue by serving a continuous stream of advertisements.
Evading Regulations and Trust Signals
Early Access provides a significant advantage for casino-oriented apps. It allows them to sidestep many regulatory requirements that legitimate gambling applications must follow, such as licensing, geofencing, and age verification. To bypass these restrictions, the apps masquerade as casual slot and puzzle games.
Aggressive social media advertising leads unsuspecting users to these Early Access apps on the Google Play Store or directly to various gambling websites. Without the ability for users to leave critical reviews or poor ratings, the traditional trust signals on the platform no longer apply, enabling such apps to gain traction.
Scope of the Threat
Analysis indicates the lures extend beyond casino games and fake reward apps. The deceptive applications also include PDF readers, QR scanners, phone trackers, utility apps, and games that infringe on third-party trademarks. One identified app was a Grand Theft Auto imitator named "Vice Streets: Open World."
This game had an APK package named com.gamblechaos.withfriends.game and recorded over 1 million downloads. It featured no reviews or ratings. It is currently no longer available on the Google Play Store, though it is unclear if Google or the uploader removed it.
Bitdefender noted that while the Early Access program remains a valuable tool for legitimate developers, the removal of comments and ratings also removes one of the community's strongest defenses. "Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software," the report said.
The disclosure of this abuse coincides with reports of other Android malware campaigns. These include the Hagaseca remote access trojan, the Mantax Otax spyware and ransomware hybrid, and the StreamRat malware that abuses accessibility services. A separate campaign uses the Gigabud banking trojan to install a companion app called Vwork, which clones banking apps inside a work profile to conduct financial fraud. Group-IB said operators use a cloned environment to evade fraud protection controls while carrying out transactions.





