started · updated
Google Play Early Access exploited by malicious app developers
Security firm Bitdefender has warned that cybercriminals are exploiting Google Play’s Early Access program to distribute deceptive and malicious applications. Because the program is designed to allow developers to test unfinished software, it lacks public ratings and user reviews, creating a blind spot that prevents users from identifying fraudulent content.
Researchers identified thousands of suspicious apps, including fake casino games, reward-based apps that fail to pay out promised earnings, and utilities like QR scanners that request excessive permissions, such as becoming a phone's home screen launcher. Some attackers use high-profile names to intercept searches, such as apps titled ‘Grand Theft Auto V (Early Access)’ that later rename themselves after gaining significant downloads.
Many of these applications are promoted via social media platforms like TikTok and Facebook using AI-generated deepfakes of celebrities to build false trust. While the Early Access feature functions as intended for legitimate developers, Bitdefender notes that malicious actors are leveraging its design to bypass the community feedback mechanisms that typically protect users.