- Malicious actors are abusing Google Play’s Early Access program to distribute deceptive apps with no public reviews or ratings.
- A fake Grand Theft Auto game called “Vice Streets: Open World” amassed over 1 million downloads on Google Play.
- The fraudulent apps promise cash rewards, cryptocurrency earnings, and casino jackpots, but profit mainly by serving ads.
- New Android malware families, including Hagaseca, Mantax Otax, StreamRat, and Vwork, add to the threat landscape.
On Sep 10, 2026, Bitdefender revealed that malicious actors are abusing Google Play’s Early Access program to push deceptive apps offering money, rewards, casino winnings, and premium content. The feature blocks public reviews and star ratings, removing key trust signals for users.
The findings include a Grand Theft Auto imitation named “Vice Streets: Open World” with over 1 million downloads before it disappeared from the Play Store. “The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,” the company stated.
Threat actors promote these apps through TikTok, Facebook, and other platforms using bogus ads, including AI-generated celebrity deepfakes. According to Bitdefender’s report, suspicious titles promise cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins, and casino jackpots.
These apps follow a consistent engagement loop: users receive virtual rewards after installation, but progression slows dramatically near withdrawal thresholds. The promised payout never arrives, while the operator profits by serving ad after ad.
Casino-style apps also sidestep licensing, geofencing, and age verification rules by masquerading as casual slot and puzzle games. Lures extend beyond gambling to PDF readers, QR scanners, phone trackers, utilities, and trademark-themed games.
The disclosure coincides with multiple Android malware families. Hagaseca is a remote access trojan with a worm component that scans exposed Android Debug Bridge services, while Mantax Otax combines spyware with ransomware, primarily targeting older Android devices and Indonesian users.
Another threat, StreamRat, abuses Android accessibility services and MediaProjection to control infected devices, targeting Spanish speakers through a fake streaming service. Separately, GoldFactory is using the Gigabud banking trojan to install Vwork, a weaponized fork of Shelter, to clone banking apps. “With full remote control, and where relevant a cloned banking app in place, the operator carries out transactions directly on the victim’s phone while a black screen hides what is happening,” Group-IB said.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
