Fraud & Identity Theft

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Deceptive apps in Early Access are being used by dishonest developers for their own benefit.

Deceptive apps in Early Access are being used by dishonest developers for their own benefit.

Google Play’s Early Access program for Android apps allows developers to gather useful feedback from early adopters for app improvement before final release. It lets users try unreleased, in-development apps or games before their official public launch. The conversation is from user to developer, not between users. The program consequently includes no facility for inter-user recommendations, ratings or warnings.

Dubious actors are exploiting this lack of public ratings and reviews by adding deceptive apps to the program, and then driving users through external advertising to download apps directly from the Early Access program.

A typical process, outlined by Bitdefender, is for an app to be ‘advertised’ through TikTok or Facebook with promised cash rewards (PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots). But after installation, the promised payout never arrives.

“Instead,” warns Bitdefender, “the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.”

An example type of deceptive app is described as a ‘ghost casino’. While legitimate gambling acts are subject to strict regulation, many early access casino-style apps avoid the regulations by resembling casual slot games or puzzle products. Potential users are directed toward them by the fake social media ads.

“Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free,” adds Bitdefender, noting that there are also ‘random user’ adverts.

Advertisement. Scroll to continue reading.

Social media has become adept at recognizing and removing these misleading adverts, but the process is easily repeatable and common enough for innocent users to be caught.

Two of the most common sham titles used in this scheme are Chicken Road (a risk-and-reward mini-game where players guide a cartoon chicken across a hazardous path) and Ice Fishing (a fast-paced live dealer casino game), or variants on those names.

Trademark abuse is also common, and Grand Theft Auto (GTA) is an example. The deceptive app is uploaded but named, for example, ‘Grand Theft Auto V (Early Access)’. After it has been indexed by Google Search, it is renamed – but any user searching for information on the product in question would be directed to the deceptive app.

“Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.”

Bitdefender’s research suggests this is a widespread problem, with some developers appearing multiple times, and some listings showing thousands of installs.

The process is not using Coogle’s Early Access to deliver malware. Nor are the deceptive app developers being accused of anything clearly illegal (although fraud comes to mind). But it is nevertheless a clear misuse of a beneficial Google service, designed to benefit genuine app developers, being abused by deceitful developers. They benefit from the sale of advertisements, and they trick people into providing the hardware, possibly on a massive scale, to do so.

Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

Related: Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play

Related: 300 Malicious ‘Vapor’ Apps Hosted on Google Play Had 60 Million Downloads

Related: North Korean Hackers Distributed Android Spyware via Google Play

Related Content

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Mobile & Wireless

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Mobile & Wireless

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks.

Malware & Threats

Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.

Mobile & Wireless

CVE-2026-0073 affects Android’s System component and it can be exploited without any user interaction. 

Artificial Intelligence

The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million.

Mobile & Wireless

Offered as a MaaS to a small number of affiliates, mainly Russian speakers, the RAT can turn devices into residential proxy nodes.

Mobile & Wireless

The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version