Cybersecurity firm Bitdefender has unearthed a large-scale exploit of Google Play’s Early Access program, where attackers are distributing thousands of deceptive Android apps that promise rewards, casino winnings, and premium content—but deliver relentless ads and data harvesting instead. By exploiting a key limitation of Early Access—disabled public ratings and reviews—malicious developers can avoid community warnings and scrutiny while aggressively promoting their apps through social media.
Modus operandi
Google designed Early Access to help developers gather feedback on unfinished apps before full release, intentionally disabling public star ratings and user reviews to protect beta testers’ input from skewing an app’s reputation. However, Bitdefender’s investigation shows that bad actors are weaponizing this blind spot: without visible reviews, users cannot see red flags such as non-paying “reward” apps, fake casino games, or utilities requesting excessive permissions. The result is an ecosystem where deceptive apps can accumulate significant downloads before any public accountability kicks in.
Researchers analysis of apps installed by its users identified thousands of suspicious Early Access listings across multiple categories, including fake casino and slot games, “earn money” and reward apps, PDF readers, QR scanners, phone trackers, and utility tools. Many of these apps are promoted via TikTok, Facebook, and other platforms using misleading ads, some featuring AI-generated deepfakes of celebrities to lend false credibility.
After installation, users typically never receive promised payouts; instead, the apps serve persistent ad after ad, turning victims into a revenue stream for the operators through fraudulent ad impressions. Some apps also request unusual permissions or exhibit behavior that could pose serious security risks on corporate or personal devices.
Beyond ad fraud, the researchers found Early Access listings that appear to infringe third-party trademarks, including imitation titles capitalizing on popular games and brands. The Early Access status also lets operators sidestep stricter rules that apply to real-money gambling apps, such as licensing requirements, geofencing, and age verification, by presenting themselves as unfinished or non-gambling products. This combination of weak oversight, hidden reviews, and external promotion creates a high-reward, low-risk channel for deceptive developers.
Safety recommendations
For users, the safest approach is to treat Early Access apps with extra caution, especially those promising cash, crypto, gift cards, or jackpots, and to avoid installing apps pushed via sensational social media ads. Organizations should consider blocking or flagging Early Access apps on managed Android devices, given the elevated risk of ad fraud, data harvesting, and permission abuse. On the platform side, Bitdefender’s findings highlight the need for Google to introduce stronger signals—such as limited or moderated user feedback, clearer labeling, and tighter review of high-risk categories—even within Early Access, to prevent the program from becoming a safe haven for deceptive apps.