Threat Intelligence

Scammers Exploit Google Play's Early Access Feature to Spread Fake Reward Apps

The Hacker News · 11 Sept 2026
Key Takeaway Treat any app promising quick cash, crypto, or casino winnings with suspicion, especially if it has no reviews or ratings, and only install apps from established, well-reviewed developers.

Security researchers at Bitdefender have found that cybercriminals are exploiting Google Play's Early Access program, a feature meant to let developers gather feedback before an app's full release, to push deceptive applications at scale. Because apps in Early Access cannot receive public reviews or star ratings, users lose the usual warning signs that would flag a scam app, letting fraudulent listings gain downloads without scrutiny.

One example is a Grand Theft Auto imitation called 'Vice Streets: Open World', which reached over one million downloads despite having no reviews. It has since disappeared from the Play Store, though it is unclear whether Google or the developer removed it. Many of these apps promise cash, PayPal payouts, cryptocurrency, gift cards, or casino jackpots, and are promoted through ads on TikTok and Facebook, some using AI-generated celebrity deepfakes to appear legitimate.

Bitdefender describes a common pattern: users install the app after seeing an ad, receive small rewards early on to build trust, then find that further progress and payouts stall indefinitely. The promised money or prizes never actually arrive, leaving users with a useless app and, in some cases, exposure to further scams or data harvesting.

Android security Google Play mobile scams app fraud social engineering

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.