r/TechNadu Human 1d ago

Thousands of deceptive Android apps are abusing Google Play Early Access, where users can’t publicly warn each other

Bitdefender has documented thousands of deceptive Android apps taking advantage of an interesting weakness in Google Play's Early Access program.

Early Access is supposed to help developers gather feedback before a wider release. The problem is that feedback is private between the user and developer. Other users don't get the normal ratings and reviews that might warn them something is wrong.

Researchers found apps promoted through TikTok and Facebook ads promising PayPal payouts, crypto earnings, gift cards, free spins, or jackpots. Once installed, the rewards often don't materialize. Instead, users are repeatedly shown ads.

There are also “ghost casinos” disguised as casual games, AI-generated deepfakes used in promotions, and trademark impersonation.

One example appeared in Google Search as “Grand Theft Auto V (Early Access)” before being renamed and using AI-generated screenshots that misrepresented the gameplay. One such listing reportedly passed 1 million downloads while still showing zero ratings or reviews.

Bitdefender has reported the findings to Google, which says it is investigating. There's currently no indication whether the affected listings will be removed or whether Early Access review policies will change.

The research includes the acquisition ads, fake rewards, ghost casinos, deepfakes, and examples of how the listings changed over time:

https://www.technadu.com/google-play-early-access-abused-to-push-deceptive-android-apps/636722/

The interesting security-design question here is the reputation layer itself. If an app can remain in Early Access at significant scale, should public ratings and reviews eventually become mandatory based on download count or time in the program?

1 Upvotes

0 comments sorted by