Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Deceptive Android apps are abusing Google Play's Early Access program to push fake rewards and games.
Summary
Threat actors are exploiting Google Play's Early Access program, which lacks user reviews and ratings, to distribute thousands of deceptive Android apps. These apps, often promoted with AI-generated deepfakes on social media, promise rewards or premium content but ultimately serve ads or lead to gambling sites, bypassing regulations. The abuse highlights how features intended to protect legitimate developers can also shield malicious actors.
Full text
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps Ravie LakshmananSep 10, 2026Mobile Security / Artificial Intelligence Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release. One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on third-party trademarks. Among the identified apps is a Grand Theft Auto imitator named "Vice Streets: Open World" (APK package:com.gamblechaos.withfriends.game), which has more than 1 million downloads. The game has no reviews or ratings. It's currently no longer available on the Google Play Store, although it's not clear if it was taken down by Google or by the uploader themselves. "The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted," Bitdefender said in a statement. Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI). "A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot," the Romanian cybersecurity company said in a report shared with The Hacker News. "Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive." The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with. To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites. Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games. "Google's Early Access program remains a valuable tool for developers testing new ideas," Bitdefender said. "Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community's strongest defenses against deceptive software." The Hacker News has contacted Google for comment, and we will update the story if we hear back. The disclosure coincides with the emergence of multiple malware families targeting Android - Hagaseca, a remote access trojan spread via the THost9 loader that contains a worm component, which scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules. Mantax Otax, a hybrid mobile malware that brings together comprehensive spyware capabilities and ransomware functionality, allowing the operator to steal sensitive data, encrypt it on targeted older Android versions (Android 9 or earlier), and demand a ransom payment by locking the device screen. Language indicators and files from the victims suggest the activity is primarily focused on Indonesian targets. StreamRat, which abuses Android's accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. The malware targets Spanish-speaking users through Meta and TikTok ads to direct users to counterfeit sites by masquerading as a free TV-streaming service named StreamTV Esp. The development also coincides with GoldFactory's use of the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app inside a work profile with the goal of conducting financial fraud. Similar vi "With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim's phone while a black screen hides what is happening," Group-IB said. "A cloned environment is used to evade fraud protection controls." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Android, artificial intelligence, mobile security ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro
Indicators of Compromise
- malware — Hagaseca
- malware — THost9