Threat Actors Exploit Google Play Early Access for Deceptive Apps and Ad Fraud
Cybersecurity researchers have uncovered a widespread abuse of **Google Play**'s Early Access program, with threat actors deploying thousands of deceptive applications. These apps, ranging from fake casino games to reward schemes, exploit the program's lack of public reviews to ensnare users and generate illicit advertising revenue, often promoted via AI-generated celebrity deepfakes on social media.
Bad actors are actively misusing **Google Play**'s Early Access program to distribute deceptive applications promising money, rewards, casino winnings, and premium content.

Early Access apps are unreleased applications available on the Android marketplace, designed for developers to gather user feedback before an official launch.
A critical vulnerability in this system is that users cannot leave public reviews or star ratings for Early Access apps. This loophole is being exploited by threat actors to push thousands of deceptive applications, including fraudulent casino games, reward apps, misleading utilities, and titles infringing on third-party trademarks.
One notable example identified is a **Grand Theft Auto** imitator titled "Vice Streets: Open World" (APK package: com.gamblechaos.withfriends.game), which garnered over 1 million downloads without any reviews or ratings. The app has since been removed from the **Google Play Store**, though the reason for its removal remains unclear.
**Bitdefender** highlighted this issue, stating, "The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted." The absence of traditional trust signals, such as critical reviews, allows these malicious apps to gain significant traction.
These deceptive apps are aggressively promoted across platforms like **TikTok**, **Facebook**, and other social media, often using bogus advertisements featuring celebrity deepfakes generated by artificial intelligence (AI).
"A recurring pattern among suspicious Early Access apps involves promising cash rewards, **PayPal** payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot," **Bitdefender** reported. "Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive."
The primary objective of these campaigns is to generate illicit revenue through relentless ad serving. Additionally, the Early Access program allows casino-oriented apps to circumvent the stringent regulatory requirements typically imposed on legitimate gambling applications, including licensing, geofencing, and age verification.
To bypass these restrictions, these casino-style apps masquerade as casual slot and puzzle games, leveraging social media ads to direct unsuspecting users to Early Access apps on the **Google Play Store** or directly to various gambling websites.
Further analysis reveals that the lures extend beyond casino games and reward apps to include seemingly innocuous utilities like PDF readers, QR scanners, phone trackers, and trademark-themed games.

"Google's Early Access program remains a valuable tool for developers testing new ideas," **Bitdefender** concluded. "Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software."
**The Hacker News** has reached out to **Google** for comment and will update this story upon receiving a response.
This disclosure coincides with the emergence of several notable Android malware families:
* **Hagaseca**: A remote access trojan (RAT) distributed via the **THost9** loader, featuring a worm component that scans exposed Android Debug Bridge (**ADB**) services. It installs malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules.
* **Mantax Otax**: A hybrid mobile malware combining spyware and ransomware functionalities. It steals sensitive data, encrypts it on older Android versions (9 or earlier), and demands a ransom by locking the device screen. Its primary target appears to be Indonesian users.
* **StreamRat**: This trojan abuses Android's accessibility services and the **MediaProjection API** to control infected devices, serve overlays, and harvest sensitive data. It targets Spanish-speaking users through **Meta** and **TikTok** ads, directing them to counterfeit sites disguised as a free TV-streaming service called StreamTV Esp.
Furthermore, **GoldFactory** has been observed using the **Gigabud** banking trojan to install **Vwork**, a weaponized fork of **Shelter**, to clone target apps within a work profile for financial fraud. **Group-IB** noted, "With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim's phone while a black screen hides what is happening. A cloned environment is used to evade fraud protection controls."