Play Early Access Apps Hide a Deception Problem
Bitdefender says Google Play's Early Access program is being used to push fake casino and reward apps that offer no public reviews to warn users.
Apps that promise cash, jackpots, and free rewards are turning up inside Google Play's Early Access program — and the feature meant to protect developers testing unfinished work is giving those apps a place to hide. Users cannot post public reviews or star ratings on Early Access titles, so the usual warning signs never appear on the listing. According to research from Bitdefender, that gap is now being used at scale.
The Romanian security company says threat actors are pushing thousands of Early Access applications filled with deceptive content: fake casino games, reward apps, misleading utilities, and titles that may infringe on third-party trademarks.
What Early Access Actually Is
Google Play's Early Access apps are titles that have not been released on the official Android marketplace. The program exists so developers can gather feedback on new applications or features before a full launch.
The trade-off is deliberate. Users cannot leave public reviews or star ratings for apps offered through Early Access. That protects legitimate developers from review bombing, but it also strips away one of the earliest signals a shopper has that an app cannot be trusted.
Bitdefender summarized the tension plainly:
The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted.
— Bitdefender, in a statement
Without critical reviews or poor ratings, the traditional trust signals no longer apply, and deceptive apps can gain traction with nothing on the page to contradict them.
Fake Casinos and Vanishing Payouts
The apps Bitdefender examined are not subtle. Many promise cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins, or casino jackpots.
The mechanics follow a repeating loop. A user sees an ad on TikTok or Facebook and installs the app. Generous virtual rewards may arrive almost immediately, which reinforces the idea that the payout is real. Then, as the user approaches a withdrawal threshold, progress slows dramatically — and the promised payout never arrives.
Bitdefender described the pattern in its report shared with The Hacker News:
A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot.
— Bitdefender
The company added that many of these applications rely on the same engagement loop, with the user reaching a withdrawal threshold only to find progression grinding to a halt.
The end goal is to generate illicit revenue by serving ad after ad. In the case of casino-style apps, there is a second benefit: they sidestep many of the regulatory requirements that legitimate gambling applications must meet.
Dodging Gambling Rules
Legitimate gambling apps face licensing, geofencing, and age verification obligations. Bitdefender says the Early Access casino apps get around those restrictions by masquerading as casual slot and puzzle games.
They are then promoted aggressively through social media ads that lead users either to Early Access listings in the Google Play Store or directly to gambling websites. Because the apps present themselves as ordinary games, they can reach audiences that regulated gambling products could not legally target.
The lures do not stop at slot machines. Bitdefender's analysis found that the same playbook extends to fake reward apps, PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games.
A Million Downloads, Zero Reviews
One of the identified apps is a Grand Theft Auto imitator called "Vice Streets: Open World", carrying the package name com.gamblechaos.withfriends.game. It accumulated more than 1 million downloads.
The listing had no reviews or ratings. It is currently no longer available on the Google Play Store, though it is not clear whether Google or the uploader removed it.
The case illustrates the core problem: a title with a seven-figure install count would normally carry enough user feedback for a careful shopper to make a judgment. Here there was none to read.
Deepfake Ads on Social Media
Traffic to these apps is driven through TikTok, Facebook, and other social platforms using bogus advertisements. Bitdefender says the ads include videos featuring celebrity deepfakes generated with artificial intelligence.
The combination is difficult to counter with conventional advice. A deepfake video lends the promotion a familiar face, the ad platform supplies distribution, and the Early Access listing supplies a legitimate-looking install path through Google Play itself.
For users, the strongest available signal — a wall of critical reviews — is the one thing the program removes.
Why Review Removal Cuts Deep
Bitdefender framed the trade-off as a structural weakness rather than a one-off failure:
Google's Early Access program remains a valuable tool for developers testing new ideas.
— Bitdefender
The company followed that with a caveat: removing comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software.
That framing matters because it does not call for scrapping Early Access. It points to a design tension between protecting developers from coordinated negative reviews and protecting users from apps that no one can flag publicly.
The Broader Android Malware Wave
The Bitdefender disclosure lands alongside a run of other Android malware activity.
- Hagaseca, a remote access trojan spread through the THost9 loader, includes a worm component that scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control via shell execution, file transfers, tunneling, and downloadable modules.
- Mantax Otax is a hybrid mobile malware family that combines spyware with ransomware. It steals sensitive data, encrypts it on older Android versions (Android 9 or earlier), and demands a ransom by locking the device screen. Language indicators and files from victims suggest the activity is primarily focused on Indonesian targets.
- StreamRat abuses Android's accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. It targets Spanish-speaking users through Meta and TikTok ads that direct them to counterfeit sites masquerading as a free TV-streaming service called StreamTV Esp.
Separately, GoldFactory's use of the Gigabud banking trojan involves installing a companion Android app called Vwork — a weaponized fork of Shelter — to clone a target app inside a work profile for financial fraud.
Group-IB described the resulting fraud in a statement:
With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim's phone while a black screen hides what is happening.
— Group-IB
The firm added that the cloned environment is used to evade fraud protection controls.
What Google Has Said
The Hacker News contacted Google for comment and said it would update the story if the company responds. As of the report, no statement from Google was included.
That leaves the central claims — the scale of the Early Access abuse, the ad-driven funnel, and the deepfake promotions — resting on Bitdefender's research alone. The removal of "Vice Streets: Open World" is documented, but the reason for its removal is not.
What This Means for Users and Platforms
The practical takeaway for anyone installing Android apps is that an Early Access listing carries less information than a standard one. A missing review section is not reassurance that an app is new and untested — under this abuse pattern, it can mean the opposite.
For Google, the awkward part is that the fix cannot be as simple as restoring public reviews. Bitdefender itself notes that comments and ratings were removed to shield developers from unfair criticism, so any change would have to separate genuine user feedback from coordinated attacks.
For the advertising platforms named in the research, the deepfake videos and payout promises sit upstream of the install, which suggests the deceptive funnel begins before a user ever reaches the Play Store.
The broader Android malware activity described alongside the report points in the same direction. Attackers are combining legitimate distribution channels, social media advertising, and remote-control tooling rather than relying on any single weak point. Early Access abuse stands out because it requires no exploit at all — only a program feature that was designed with good intentions.
Sources
- The Hacker News Original source
- Early Access apps Also reporting
- said Also reporting
- Hagaseca Also reporting
- Mantax Otax Also reporting
- StreamRat Also reporting
- GoldFactory's use Also reporting
Continue Reading
Patch-Gap Zero-Days Fueled BlueMoon Kit
A new exploit kit chains four Chrome and Windows flaws, revealing how quickly attackers weaponize the delay between open-source fixes and stable browser patches.
Rootkit hides web shells in F5 BIG-IP memory
Sophos says a tailored Linux rootkit lets attackers run web shells inside F5 BIG-IP APM without leaving malicious PHP on disk.
IDScan Breach Exposes License Data
IDScan confirmed hackers accessed customer data in its cloud platform after reports linked it to 153 million stolen driver's license scans.