news.mlab.sh
Back to the feed
threat-intel

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

High
Summary

Bad actors are exploiting Google Play's Early Access program to distribute thousands of deceptive apps – including fake casino games, reward apps, and utility apps – through social media ads and TikTok. These apps lack user reviews and ratings, allowing them to bypass security measures and generate illicit revenue by serving endless ads and promising unrealistic rewards that never materialize. The program’s design, intended to protect developers from negative feedback, has inadvertently created a vulnerability for malicious actors.

Google Play's Early Access program, designed for developers to solicit user feedback on new applications, is being abused by threat actors to push deceptive apps onto users. These apps, such as a Grand Theft Auto imitator named "Vice Streets: Open World" (APK package:com.gamblechaos.withfriends.game), are presented as casino games, reward apps, and utility tools, but lack user reviews and ratings. The program's design, which prevents users from leaving critical feedback, has created a significant vulnerability.

These apps are aggressively promoted through TikTok, Facebook, and other social media platforms using bogus ads featuring AI-generated celebrity deepfakes. A common tactic involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, and free casino spins, but these rewards are rarely delivered. Once a user reaches a withdrawal threshold, progression slows dramatically, and the promised payout never arrives – a deliberate strategy to keep users engaged and serving ads.

Many of these apps bypass regulatory requirements for legitimate gambling applications, masquerading as casual slot and puzzle games. The apps are designed to steal user data and generate revenue through endless advertising.

Alongside these deceptive apps, Android is experiencing a surge in malware activity. Specifically, the Hagaseca remote access trojan, spread via the THost9 loader, contains a worm component that scans exposed Android Debug Bridge (ADB) services and installs malware for remote control. Mantax Otax, a hybrid mobile malware, combines spyware capabilities with ransomware functionality, encrypting older Android versions (Android 9 or earlier) and demanding ransom payments. StreamRat abuses Android's accessibility services and the MediaProjection API to control infected devices and harvest sensitive data, targeting Spanish-speaking users through Meta and TikTok ads.

Furthermore, GoldFactory utilizes the Gigabud banking trojan to install a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app inside a work profile for financial fraud. These cloned environments allow operators to carry out transactions directly on the victim's phone while a black screen hides the activity, bypassing fraud protection controls.

Google has contacted The Hacker News for comment, and we will update the story if we hear back.

Read the full article at The Hacker News