thehackernews.com 10 Sept 2026, 14:36 UTC

Google Play Early Access Exploited to Push Deceptive Apps Without Reviews

SECURITY researchers have flagged abuse of Google Play’s Early Access programme, where rogue developers have pushed thousands of deceptive Android apps that promise cash rewards, casino winnings, or premium content. The campaign relies on Early Access apps which are not yet officially released and, crucially, do not allow public reviews or star ratings. This removal of early trust signals helps threat actors gain traction before any community scepticism can form.

Bitdefender, which provided the analysis to The Hacker News, warns that the same feature designed to shield legitimate developers from review-bombing also deprives users of an early warning that an app may be untrustworthy.

Among the highlighted cases is a Grand Theft Auto-inspired game titled “Vice Streets: Open World” (APK: com.gamblechaos.withfriends[.]game) reportedly downloaded more than 1 million times and currently without reviews or ratings; it has since vanished from the Play Store. The report notes these apps are promoted via bogus ads on TikTok and Facebook, sometimes using AI-generated celebrity deepfakes in their promotions.

The typical lure sequence involves installing the app after viewing an ad, receiving immediate rewards, then stalling at withdrawal thresholds. The objective appears to be illicit ad revenue and circumvention of gambling regulations, with other compromised app types ranging from PDF readers to utility tools and trademark-themed games. Google’s comment was sought but not yet provided at the time of publication.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline