Close Menu
NCIJ Network NCIJ Network
    What's Hot

    FactChecking Trump’s Midterm Convention Speech

    September 10, 2026

    Spain’s Parliament backs citizenship for Western Saharans born before 1977 | Migration News

    September 10, 2026

    Kazakhstan can’t sing its way into Eurovision in 2027 – POLITICO

    September 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • FactChecking Trump’s Midterm Convention Speech
    • Spain’s Parliament backs citizenship for Western Saharans born before 1977 | Migration News
    • Kazakhstan can’t sing its way into Eurovision in 2027 – POLITICO
    • Slack can now vibe-code interactive charts and reports inside chats
    • NVIDIA Details BioNeMo Inference Runtime (BioIR): 2.90x Higher Boltz-2 Folding Throughput and 58.5K Residues per GPU-Hour on 8xH100
    • Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
    • Senate Republicans Release Revised Clarity Act Ahead of September 15 Vote
    • NASA Answers President’s Call to Establish United States Space Academy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 10, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 10, 2026Mobile Security / Artificial Intelligence

    Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.

    Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their release.

    One aspect worth highlighting is that users cannot leave public reviews or star ratings for apps that are available in Early Access. This has opened the door to a new kind of abuse where threat actors are pushing thousands of Early Access applications with deceptive content, including fake casino games and reward apps, as well as misleading utilities and titles that may infringe on third-party trademarks.

    Among the identified apps is a Grand Theft Auto imitator named “Vice Streets: Open World” (APK package:com.gamblechaos.withfriends.game), which has more than 1 million downloads. The game has no reviews or ratings. It’s currently no longer available on the Google Play Store, although it’s not clear if it was taken down by Google or by the uploader themselves.

    “The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,” Bitdefender said in a statement.

    Cybersecurity

    Because users cannot leave critical reviews or poor ratings, the traditional trust signals no longer apply, allowing such apps to gain traction. These apps are said to be promoted through TikTok, Facebook, and other social media platforms using bogus ads that include videos featuring celebrity deepfakes generated using artificial intelligence (AI).

    “A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpot,” the Romanian cybersecurity company said in a report shared with The Hacker News.

    “Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive.”

    The end goal is to generate illicit revenue by serving ad after ad. Another advantage that these Early Access casino-oriented apps have is that they allow them to sidestep many of the regulatory requirements legitimate gambling applications are required to comply with.

    To get around the licensing, geofencing, and age verification restrictions, the casino-style apps masquerade as casual slot and puzzle games and are aggressively promoted via ads on social media platforms that lead unsuspecting users to Early Access apps in the Google Play Store or directly to various gambling websites.

    Further analysis indicates that the lures used for these apps go beyond casino games, slot machines, and fake reward apps to include PDF readers, QR scanners, phone trackers, utility apps, and trademark-themed games.

    “Google’s Early Access program remains a valuable tool for developers testing new ideas,” Bitdefender said. “Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community’s strongest defenses against deceptive software.”

    The Hacker News has contacted Google for comment, and we will update the story if we hear back.

    Cybersecurity

    The disclosure coincides with the emergence of multiple malware families targeting Android –

    • Hagaseca, a remote access trojan spread via the THost9 loader that contains a worm component, which scans exposed Android Debug Bridge (ADB) services and installs the malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules.
    • Mantax Otax, a hybrid mobile malware that brings together comprehensive spyware capabilities and ransomware functionality, allowing the operator to steal sensitive data, encrypt it on targeted older Android versions (Android 9 or earlier), and demand a ransom payment by locking the device screen. Language indicators and files from the victims suggest the activity is primarily focused on Indonesian targets.
    • StreamRat, which abuses Android’s accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest sensitive data. The malware targets Spanish-speaking users through Meta and TikTok ads to direct users to counterfeit sites by masquerading as a free TV-streaming service named StreamTV Esp.

    The development also coincides with GoldFactory’s use of the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app inside a work profile with the goal of conducting financial fraud. Similar vi

    “With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim’s phone while a black screen hides what is happening,” Group-IB said. “A cloned environment is used to evade fraud protection controls.”

    abused access Android apps Deceptive early Google play Push Thousands
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Mandiant Founder Kevin Mandia Joins Amazon Board

    ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    AI-powered attack exploited PaperCut flaws to hack 395 organizations

    Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

    Expanding AI access and cyber defense for federal, state, local, and tribal governments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    FactChecking Trump’s Midterm Convention Speech

    September 10, 2026

    Spain’s Parliament backs citizenship for Western Saharans born before 1977 | Migration News

    September 10, 2026

    Kazakhstan can’t sing its way into Eurovision in 2027 – POLITICO

    September 10, 2026

    Slack can now vibe-code interactive charts and reports inside chats

    September 10, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    FactChecking Trump’s Midterm Convention Speech

    September 10, 2026

    Spain’s Parliament backs citizenship for Western Saharans born before 1977 | Migration News

    September 10, 2026

    Kazakhstan can’t sing its way into Eurovision in 2027 – POLITICO

    September 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.