Google Play's Early Access Loophole Is a Playground for Scammers
Google Play has an Early Access programme designed to let developers gather feedback on apps before they go live. Noble enough in theory. In practice, it's being systematically exploited to push thousands of fake casino apps, reward scams, and trademark-infringing knockoffs onto Android devices.
The critical design flaw here is simple: Early Access apps cannot receive public reviews or star ratings. That one quirk, intended to protect developers from coordinated review bombing, also happens to neutralise the most reliable signal ordinary users have for spotting dodgy software. Scammers noticed.
Bitdefender, the Romanian security firm that uncovered this, found a recurring pattern across the suspicious apps. Users see an ad on TikTok or Facebook, often featuring a celebrity deepfake, promising cash rewards, PayPal payouts, or casino jackpots. They install the app. Virtual rewards flow in almost immediately. Then, right as they approach a withdrawal threshold, everything grinds to a halt. The promised payout never arrives. The app just keeps serving ads.
That's the business model. Serve enough ads to enough people, and the maths works out fine, regardless of whether any user ever sees a penny.
One flagged example was "Vice Streets: Open World", a Grand Theft Auto imitation with over a million downloads and zero reviews. It has since disappeared from the Play Store, though whether Google pulled it or the developers quietly removed it themselves is unclear.
Beyond the reward scam angle, the casino-style apps have another useful feature from a fraudster's perspective: Early Access status helps them dodge the regulatory requirements that legitimate gambling apps must comply with. Age verification, licensing, geofencing restrictions, all of it can be quietly sidestepped by dressing up a slot machine as a casual puzzle game and routing installs through social media ads straight to an Early Access listing.
The scope of lures extends well beyond gambling. Bitdefender also identified fake PDF readers, QR scanners, phone trackers, and assorted utility apps running the same playbook.
Bitdefender's conclusion is measured but clear: the Early Access programme has genuine value for developers, but stripping community oversight as a side effect has created a gap that bad actors are filling enthusiastically. Google has not yet commented.
Separately, this week has seen several new Android malware families surface, none of them particularly reassuring.
Hagaseca is a remote access trojan distributed via a loader called THost9. It includes a worm component that scans for exposed Android Debug Bridge services and installs itself for persistence, with capabilities covering shell execution, file transfers, tunneling, and modular downloads.
Mantax Otax is a hybrid that combines spyware with ransomware. It can steal sensitive data, encrypt it on older Android versions (Android 9 and below), lock the device screen, and demand payment. Evidence from victims points to Indonesia as the primary target.
StreamRat abuses Android's accessibility services and the MediaProjection API to take control of infected devices, serve overlays, and harvest data. It spreads through ads on Meta and TikTok, masquerading as a free streaming service called StreamTV Esp and directing Spanish-speaking users to counterfeit sites.
Finally, the GoldFactory group has been using the Gigabud banking trojan to install an app called Vwork, a modified version of the legitimate Shelter tool, to clone banking apps inside Android work profiles. Once in place, operators conduct fraudulent transactions directly on the victim's device while a black screen keeps the activity hidden. Group-IB noted that the cloned environment is specifically designed to slip past fraud detection controls.