news.mlab.sh
Back to the feed
threat-intel

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Medium
Summary

Deceptive developers are exploiting Google Play's Early Access program to trick users into downloading apps that appear legitimate but are actually designed to generate revenue through aggressive advertising. These apps, often disguised as casino games or other popular titles, lure users in via misleading social media ads promising rewards that never materialize, leading to a flood of intrusive advertisements. This abuse of a beneficial program highlights a significant problem with deceptive practices on the platform.

Google Play’s Early Access program allows developers to gather feedback on in-development apps before their official public launch. However, this program lacks user-to-user ratings and reviews, a vulnerability that malicious actors are exploiting. Dubious developers are adding deceptive apps to the Early Access program and then driving users through external advertising – primarily on platforms like TikTok and Facebook – to download the apps directly. These ads frequently promise cash rewards (PayPal payouts, cryptocurrency earnings, gift cards, or casino jackpots), but upon installation, the promised rewards are never delivered.

Instead, the application continues serving advertisements, which is the intended purpose for the developers: to generate revenue by showing ads to as many people as possible. Examples include ‘ghost casino’ apps resembling legitimate gambling acts but avoiding regulations, and titles like ‘Chicken Road’ and ‘Ice Fishing’ – and variants – that are designed to mislead users. Trademark abuse is also common, with ‘Grand Theft Auto (Early Access)’ being used to redirect users to deceptive apps.

The same game will have a completely different title and screenshots (AI-generated, not representative of gameplay) after being indexed by Google Search. The entire game is designed to serve aggressive ads, and if a user manages to play the game, it will look nothing like what’s being presented in the advertisement. Bitdefender’s research indicates this is a widespread issue, with some developers appearing multiple times and listings showing thousands of installs.

This process does not involve using Google’s Early Access to deliver malware, and developers are not being accused of any illegal activity. However, it represents a clear misuse of a beneficial Google service, being exploited to generate revenue through deceptive advertising practices. The developers benefit from the sale of advertisements, and they trick people into providing hardware to facilitate this.

Read the full article at SecurityWeek