Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, google-play, android, deceptive-apps, ad-fraud, deepfakes, mobile] ยท confidence: medium ยท severity: medium ยท affected_sectors: [retail, technology] ยท au_impact: false

Bitdefender has documented systematic abuse of Google Play's Early Access programme, which lets developers publish unreleased apps for feedback and, critically, prevents users from leaving public reviews or star ratings. Threat actors are using that review blind spot to distribute thousands of deceptive apps promising money, rewards, casino winnings and premium content, promoted through TikTok and Facebook adverts featuring AI-generated celebrity deepfakes.

Attribute Detail
Platform Google Play Early Access programme
Scale Thousands of deceptive apps
Lures Cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, casino jackpots; PDF readers, QR scanners, phone trackers, trademark-themed games
Mechanism Immediate virtual rewards, then progression stalls at the withdrawal threshold so no payout is ever made
Example "Vice Streets: Open World" (com.gamblechaos.withfriends.game) โ€” 1M+ downloads, no ratings or reviews
Reported 2026-09-10

The casino-oriented apps sidestep licensing, geofencing and age-verification requirements by masquerading as casual slot and puzzle games, and are aggressively promoted through social media adverts that lead to either Early Access listings or third-party gambling sites. Bitdefender framed the root problem plainly: the feature that shields legitimate developers from unfair review bombing also removes one of the community's strongest defences against deceptive software. The disclosure coincides with a cluster of new Android malware families โ€” Hagaseca (spread via the THost9 loader and scanning exposed ADB services), Mantax Otax (hybrid spyware/ransomware aimed at Indonesian targets) and StreamRat (accessibility and MediaProjection abuse delivered through Meta and TikTok adverts to Spanish-speaking users). See gigabud-banking-trojan-builds-android-work-profiles-to-evade-fraud-checks.md.