Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Deceptive Android apps are exploiting Google Play's Early Access program to bypass reviews.
Summary
Dishonest developers are abusing Google Play's Early Access program to distribute deceptive Android apps. These apps, advertised on social media with promises of rewards, instead bombard users with ads. They often mimic popular games or casino apps, sometimes using AI-generated images and trademarked names to trick users into downloading them, thereby generating ad revenue without providing the promised functionality.
Full text
Google Play’s Early Access program for Android apps allows developers to gather useful feedback from early adopters for app improvement before final release. It lets users try unreleased, in-development apps or games before their official public launch. The conversation is from user to developer, not between users. The program consequently includes no facility for inter-user recommendations, ratings or warnings. Dubious actors are exploiting this lack of public ratings and reviews by adding deceptive apps to the program, and then driving users through external advertising to download apps directly from the Early Access program. A typical process, outlined by Bitdefender, is for an app to be ‘advertised’ through TikTok or Facebook with promised cash rewards (PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots). But after installation, the promised payout never arrives. “Instead,” warns Bitdefender, “the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.” An example type of deceptive app is described as a ‘ghost casino’. While legitimate gambling acts are subject to strict regulation, many early access casino-style apps avoid the regulations by resembling casual slot games or puzzle products. Potential users are directed toward them by the fake social media ads. “Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free,” adds Bitdefender, noting that there are also ‘random user’ adverts.Advertisement. Scroll to continue reading. Social media has become adept at recognizing and removing these misleading adverts, but the process is easily repeatable and common enough for innocent users to be caught. Two of the most common sham titles used in this scheme are Chicken Road (a risk-and-reward mini-game where players guide a cartoon chicken across a hazardous path) and Ice Fishing (a fast-paced live dealer casino game), or variants on those names. Trademark abuse is also common, and Grand Theft Auto (GTA) is an example. The deceptive app is uploaded but named, for example, ‘Grand Theft Auto V (Early Access)’. After it has been indexed by Google Search, it is renamed – but any user searching for information on the product in question would be directed to the deceptive app. “Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.” Bitdefender’s research suggests this is a widespread problem, with some developers appearing multiple times, and some listings showing thousands of installs. The process is not using Coogle’s Early Access to deliver malware. Nor are the deceptive app developers being accused of anything clearly illegal (although fraud comes to mind). But it is nevertheless a clear misuse of a beneficial Google service, designed to benefit genuine app developers, being abused by deceitful developers. They benefit from the sale of advertisements, and they trick people into providing the hardware, possibly on a massive scale, to do so. Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps Related: Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Related: 300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads Related: North Korean Hackers Distributed Android Spyware via Google Play Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserThe Hidden Instructions That Can Hijack AI AgentsOpenAI Agents Hijack Another Victim WebsiteOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersCatch Raises $5 Million for AI Executive Assistant With GuardrailsCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents Latest News Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint RemediationCritical NetScaler Vulnerability Exploited in AttacksWidened Scan Turns Up Fourth Rogue Claude Cyber Incident4.1 Million Impacted by AdaptHealth Data BreachOrganizations Warned of Cisco Secure FMC ExploitationNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and Security Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveAmazon has elected Kevin Mandia to its Board of Directors.Gigamon has named Grant Yacomeni as Chief Information Security Officer.SSH Communications Security has appointed Lars Bell as Chief Executive Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Chicken Road
- malware — Ice Fishing