Cybersecurity researchers at Bitdefender have uncovered a widespread campaign wherein threat actors are abusing Google Play's Early Access program to distribute deceptive and financially predatory Android applications to millions of users worldwide.
Google Play introduced Early Access to allow developers to distribute pre-release builds and gather private bug reports before a full market rollout. However, a structural characteristic of the program—the complete suppression of public user reviews and star ratings—has been inverted by scam syndicates into an effective cloaking mechanism.
Bypassing the Community Immune System
Under normal circumstances, when a mobile app exhibits scam behavior, aggressive ad-spamming, or failing payout promises, user reviews plummet to one star, alerting prospective downloaders. In Early Access, users cannot view or post public feedback.
Bitdefender identified dozens of high-traffic Early Access titles, including a Grand Theft Auto clone titled "Vice Streets: Open World" (package: com.gamblechaos.withfriends.game), which amassed more than 1 million installs with zero public rating indicators.
Deepfake Social Media Funnels
The operational cycle relies on highly deceptive user acquisition pipelines:
- AI-Generated Deepfake Advertising: Threat actors run coordinated ad campaigns across TikTok, Instagram, and Facebook featuring AI-cloned voices and deepfakes of high-profile celebrities endorsing "instant cash games" and guaranteed PayPal transfers.
- The Artificial Progression Loop: Upon installation from Google Play, users are presented with casino or puzzle mechanics that initially credit hundreds of dollars in virtual balances.
- The Withdrawal Trap: As the victim approaches the cash-out threshold, progress artificially decelerates, ultimately requiring users to watch dozens of unskippable ads or purchase "verification tokens" that yield nothing.
"The same mechanism designed to shield developers from early unfair reviews removes the primary defense consumers rely on. Without community feedback, deceptive software can scale unchecked."
Security Recommendations for Enterprise Mobile Fleets
Enterprise mobile device management (MDM) administrators should implement the following policy controls:
- Restrict Early Access Installations: Configure corporate Android Enterprise policies to restrict managed work profiles from installing non-production, Early Access builds from Google Play.
- Blacklist Side-Loaded and Unrated Packages: Enforce EDR application verification on corporate mobile fleets, flagging any application that lacks public store telemetry and verification markers.
- User Awareness Training: Educate staff regarding social media ad lures featuring deepfake celebrity endorsements for gambling and financial reward utilities.



