Google Play's Early Access program, designed to allow Android developers to test apps and games still in development, is becoming a channel exploited to distribute deceptive products without facing public user scrutiny. According to research by Bitdefender, several developers are publishing apps under the program that promise cash rewards, casino payouts, cryptocurrencies, gift cards, or premium content, subsequently driving installs through social media advertising campaigns.

What makes the mechanism particularly effective is a structural feature of Early Access: users who download an app can submit feedback to the developer, but cannot post reviews visible to other users or assign star ratings. This design choice was intended to prevent incomplete products from being penalized by premature ratings or hostile review campaigns. In the hands of bad actors, however, that same protection eliminates one of the most immediate indicators that normally help identify a problematic app on the Play Store.

Social ads and promises that never materialize

The identified scheme often begins with ads circulating on TikTok and Facebook. Depending on the campaign, the ads promise PayPal payouts, cryptocurrency earnings, gift cards, free spins, or jackpots. Bitdefender also notes the use of deepfake videos featuring celebrities, including athletes and actors, as well as purported testimonials from everyday users. The objective is to drive the victim to the Early Access app page on Google Play, or in some instances toward external gambling websites.

Following installation, users may quickly receive virtual rewards, creating the impression that their balance is growing with ease. That changes as the payout threshold approaches: progress slows dramatically, the requirements become virtually unattainable, and the promised funds are never disbursed. Meanwhile, the app serves a barrage of ads, turning the user's time and attention into the publisher's true revenue stream.

This type of conduct does not necessarily coincide with the distribution of malware. The research does not describe an operation aimed at installing malicious code on smartphones, nor does it attribute specific violations already established by authorities to the analyzed apps. However, the harm can be concrete: consuming time and data traffic, subjecting people to aggressive advertising pressure, inducing them to share information, or convincing them to chase prizes that will never arrive. The absence of public reviews also makes it harder to understand, prior to downloading, whether others have already experienced the same behavior.

The “ghost” casinos behind seemingly harmless games

A significant portion of the phenomenon involves apps styled after casinos, slot machines, and prize games. Legitimate gambling activities are normally subject to obligations that can include licensing, age verification, and geographical restrictions. The apps identified by researchers attempt to circumvent these constraints by presenting themselves as simple pastimes: puzzles, mini-games, or casual titles featuring slot mechanics.

Here too, external promotion serves to establish a direct link between the advertisement and the installation, without users pausing long enough to reflect on the nature of the product. Recurring names cited in the research include Chicken Road and Ice Fishing, or variants that evoke these titles. The former is associated with a game where a chicken must cross a dangerous path based on a risk-reward dynamic; the latter evokes a live casino format. These are formulas familiar to those who frequent the online gaming scene and are therefore capable of intercepting users who are already inclined to believe promotional offers.

The issue does not solely concern compliance with gambling regulations. An app that presents itself as a casual game but is advertised as an opportunity to win can deliberately blur the lines between entertainment and real-money gambling. For minors and vulnerable users, the combination of persuasive ads, virtual rewards, and prompts to continue playing can be particularly insidious, even when the app does not directly provide a regulated betting platform.

Imitated brands and listings that change identity

Bitdefender also detected the opportunistic use of well-known brands and names. One technique involves uploading a listing with a title that references a popular product to intercept web and search engine queries. Once indexing and visibility are achieved, the app's name can be changed. Users arriving from a search result tied to the original brand therefore risk landing on a different product, with descriptions and images that do not reflect the actual experience.

The most prominent case involves Grand Theft Auto. Researchers point to an app named Vice Streets: Open World, with the package name com.gamblechaos.withfriends.game, which surpassed one million downloads without any visible reviews or ratings. The app is no longer available on Google Play, but based on the collected information, it is not possible to determine whether it was removed by Google or pulled by the uploader.

According to the analysis, some ads explicitly leveraged the appeal of Grand Theft Auto, including wording that suggested early access to an installment in the franchise. Later, the title and screenshots could be modified; promotional images, in some cases generated with artificial intelligence tools, did not match the game actually accessible. The result is a product designed primarily to display ads, while the promised gaming experience remains marginal or entirely different from what was shown.

A flaw in trust signals, not in technical control

The case highlights a weakness in the marketplace's trust model rather than a technical flaw in Android or Google Play Protect. Reviews are not an absolute guarantee: they can be manipulated, purchased, or coordinated. However, they remain a useful tool for quickly detecting recurring patterns, such as missing payouts, excessive ads, suspicious requests, or features that differ from what was advertised.

In Early Access, that level of collective oversight is missing by definition. Feedback remains a private matter between app testers and developers, meaning any potential warning is not visible to those who come later. For a legitimate experimental project, the system can be reasonable. For those aiming to maximize downloads through misleading ads, however, it provides a convenient window to accumulate installs before the product’s public reputation can take shape.

The research also suggests that these are not isolated anomalies: some developers appear in multiple ads, and several apps boast install counts in the thousands, if not higher. The fact that Early Access is designed for software that has not yet been officially released also makes it less intuitive for many users to distinguish between a genuine test and an app using the label as a reputational shield.

How to reduce risk before installation

For users, the first sign of caution should be the source of the invitation. A social media ad promising easy money, guaranteed winnings, or very large rewards warrants independent verification, especially if it relies on a familiar face or an artificial-looking video. A presence on the Play Store alone is not enough to confirm that a financial offer is genuine or that an app meets the expectations set by advertising.

  • Check whether the app is listed as Early Access and remember that it will not feature public reviews.
  • Be wary of rewards tied to vague withdrawal thresholds, repetitive tasks, or continuous ad viewing.
  • Verify the developer’s name, the requested permissions, and the consistency between the title, screenshots, and stated functionality.
  • Do not trust deepfakes or testimonials featured in social media ads, even when they mention well-known payment platforms.

For Google, the case raises a question of balance: preserving a useful testing ground without allowing the absence of reviews to become a systematic advantage for deceptive apps. Potential interventions could include tighter controls on campaigns directing users to Early Access titles, checks on frequent changes to names and promotional materials, or additional indicators explaining to users why stars and comments are missing. At present, the most immediate takeaway is that the early access label must not be interpreted as a stamp of reliability: it merely indicates that the app is not in its final release.

Sources