Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Fraud & Identity Theft

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Deceptive apps in Early Access are being used by dishonest developers for their own benefit.

Google Play’s Early Access program for Android apps allows developers to gather useful feedback from early adopters for app improvement before final release. It lets users try unreleased, in-development apps or games before their official public launch. The conversation is from user to developer, not between users. The program consequently includes no facility for inter-user recommendations, ratings or warnings.

Dubious actors are exploiting this lack of public ratings and reviews by adding deceptive apps to the program, and then driving users through external advertising to download apps directly from the Early Access program.

A typical process, outlined by Bitdefender, is for an app to be ‘advertised’ through TikTok or Facebook with promised cash rewards (PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots). But after installation, the promised payout never arrives.

“Instead,” warns Bitdefender, “the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.”

An example type of deceptive app is described as a ‘ghost casino’. While legitimate gambling acts are subject to strict regulation, many early access casino-style apps avoid the regulations by resembling casual slot games or puzzle products. Potential users are directed toward them by the fake social media ads.

“Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free,” adds Bitdefender, noting that there are also ‘random user’ adverts.

Advertisement. Scroll to continue reading.

Social media has become adept at recognizing and removing these misleading adverts, but the process is easily repeatable and common enough for innocent users to be caught.

Two of the most common sham titles used in this scheme are Chicken Road (a risk-and-reward mini-game where players guide a cartoon chicken across a hazardous path) and Ice Fishing (a fast-paced live dealer casino game), or variants on those names.

Trademark abuse is also common, and Grand Theft Auto (GTA) is an example. The deceptive app is uploaded but named, for example, ‘Grand Theft Auto V (Early Access)’. After it has been indexed by Google Search, it is renamed – but any user searching for information on the product in question would be directed to the deceptive app.

“Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.”

Bitdefender’s research suggests this is a widespread problem, with some developers appearing multiple times, and some listings showing thousands of installs.

The process is not using Coogle’s Early Access to deliver malware. Nor are the deceptive app developers being accused of anything clearly illegal (although fraud comes to mind). But it is nevertheless a clear misuse of a beneficial Google service, designed to benefit genuine app developers, being abused by deceitful developers. They benefit from the sale of advertisements, and they trick people into providing the hardware, possibly on a massive scale, to do so.

Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

Related: Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play

Related: 300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads

Related: North Korean Hackers Distributed Android Spyware via Google Play

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Amazon has elected Kevin Mandia to its Board of Directors.

Gigamon has named Grant Yacomeni as Chief Information Security Officer.

SSH Communications Security has appointed Lars Bell as Chief Executive Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.