{"id":2790,"date":"2026-09-10T15:11:17","date_gmt":"2026-09-10T15:11:17","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2790"},"modified":"2026-09-10T15:11:17","modified_gmt":"2026-09-10T15:11:17","slug":"google-play-early-access-abused-to-push-thousands-of-deceptive-android-apps","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2790","title":{"rendered":"Google Play Early Access Abused to Push Thousands of Deceptive Android Apps"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 10, 2026<\/span><\/span><span class=\"p-tags\">Mobile Security \/ Artificial Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh4vbRDTWaQnxiILexae9P_rAk0hzx-re0czK2tM_WNQcoVDPlKblD4M5qOy8FZ9hHJBDLGjHHAyYutmaiacI54o5q1SH5qSbsptviRF16T2r6i8Iywvzk4GJprCm60p12qrK7t3R8h_ZR7CUoG47YfdeOb0iKY0WRapDeObI8_poWklMtKXrmr421Scjzi\/s1700-nu-rw-lo-l85-e365\/play.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Bad actors are misusing Google Play&#8217;s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.<\/p>\n<p><a href=\"https:\/\/support.google.com\/googleplay\/answer\/7003180?hl=en\" target=\"_blank\">Early Access apps<\/a> are apps that haven&#8217;t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release.<\/p>\n<p>One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on third-party trademarks.<\/p>\n<p>Among the identified apps is a Grand Theft Auto imitator named \u00abVice Streets: Open World\u00bb (APK package:com.gamblechaos.withfriends.game), which has more than 1 million downloads. The game has no reviews or ratings. It&#8217;s currently no longer available on the Google Play Store, although it&#8217;s not clear if it was taken down by Google or by the uploader themselves.<\/p>\n<p>\u00abThe same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,\u00bb Bitdefender said in a statement.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI).<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abA recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot,\u00bb the Romanian cybersecurity company <a href=\"https:\/\/www.bitdefender.com\/en-au\/blog\/hotforsecurity\/google-play-early-access-exploit-deceptive-apps\" target=\"_blank\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>\u00abMany of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive.\u00bb<\/p>\n<p>The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with.<\/p>\n<p>To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites.<\/p>\n<p>Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizOMCBEAYyMJ527QtdiWQWCnkp1fCDKIdZCeRpxejS-TmO-y1MO-XtjxJ99PHOipDU0aFaeVU3IJuceUdWCayDVdBPo12iQE26qWQSuWoFzGkP4d_naFxLDfgydSQNEi7PsGhvm5j6sDt0eBYOgfoLN9QHQxGD0ilHM0hX_pFpnu9I_tQ7OBdPt8eBHu_8\/s1700-nu-rw-lo-l85-e365\/apps.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizOMCBEAYyMJ527QtdiWQWCnkp1fCDKIdZCeRpxejS-TmO-y1MO-XtjxJ99PHOipDU0aFaeVU3IJuceUdWCayDVdBPo12iQE26qWQSuWoFzGkP4d_naFxLDfgydSQNEi7PsGhvm5j6sDt0eBYOgfoLN9QHQxGD0ilHM0hX_pFpnu9I_tQ7OBdPt8eBHu_8\/s1700-nu-rw-lo-l85-e365\/apps.png\" alt=\"\" border=\"0\" data-original-height=\"0\" data-original-width=\"0\"\/><\/a><\/div>\n<p>\u00abGoogle&#8217;s Early Access program remains a valuable tool for developers testing new ideas,\u00bb Bitdefender said. \u00abRemoving the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community&#8217;s strongest defenses against deceptive software.\u00bb<\/p>\n<p>The Hacker News has contacted Google for comment, and we will update the story if we hear back.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The disclosure coincides with the emergence of multiple malware families targeting Android &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/darkatlas.io\/blog\/hagaseca-inside-a-packed-android-rat-loader\" target=\"_blank\">Hagaseca<\/a><\/strong>, a remote access trojan spread via the THost9 loader that contains a worm component, which scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules.<\/li>\n<li><strong><a href=\"https:\/\/zimperium.com\/blog\/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration\" target=\"_blank\">Mantax Otax<\/a><\/strong>, a hybrid mobile malware that brings together comprehensive spyware capabilities and ransomware functionality, allowing the operator to steal sensitive data, encrypt it on targeted older Android versions (Android 9 or earlier), and demand a ransom payment by locking the device screen. Language indicators and files from the victims suggest the activity is primarily focused on Indonesian targets.<\/li>\n<li><strong>StreamRat<\/strong>, which abuses Android&#8217;s accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. The malware targets Spanish-speaking users through Meta and TikTok ads to direct users to counterfeit sites by masquerading as a free TV-streaming service named StreamTV Esp.<\/li>\n<\/ul>\n<p>The development also coincides with GoldFactory&#8217;s use of the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of <a href=\"https:\/\/f-droid.org\/en\/packages\/net.typeblog.shelter\/\" target=\"_blank\">Shelter<\/a>, to clone a target app inside a work profile with the goal of conducting financial fraud. Similar vi<\/p>\n<p>\u00abWith full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim&#8217;s phone while a black screen hides what is happening,\u00bb Group-IB said. \u00abA cloned environment is used to evade fraud protection controls.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 10, 2026Mobile Security \/ Artificial Intelligence Bad actors are misusing Google Play&#8217;s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2791,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1233,130,281,616,3374,1811,2,1583,908,327],"class_list":["post-2790","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abused","tag-access","tag-android","tag-apps","tag-deceptive","tag-early","tag-google","tag-play","tag-push","tag-thousands"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2790","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2790"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2790\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2791"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2790"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2790"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2790"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}