Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users
Deceptive Android Apps Exploit Google Play Early Access to (TL-2026-2655) is a medium-severity malware campaign, first published 2026-09-25. It has no confirmed attribution, affects Google Google Play Store (Early Access program), maps to 10 MITRE ATT&CK techniques (T1036, T1111, T1204.002), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2655
- Threat ID
- TL-2026-2655
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, gaming, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Deceptive Android Apps Exploit Google Play Early Access to
Malware and tooling: Chaos With Friends, Chicken Road, Grand Theft Auto V (Early Access), Ice Fishing, Vice Streets: Open World
Bitdefender Labs and Zimperium disclose a large-scale campaign abusing Google Play's Early Access program, which disables public ratings and reviews, to distribute thousands of deceptive Android apps — fake casino and reward games, misleading utilities, and trademark-infringing titles — to millions of users. The apps are promoted through TikTok and Facebook ads featuring AI-generated celebrity deepfakes, promise cash, PayPal, crypto, and gift-card payouts that never arrive, and monetize users via endless advertisements; at least one disguised utility requested Android launcher privileges capable of credential and 2FA capture. Google has been notified and is investigating.
How Deceptive Android Apps Exploit Google Play Early Access to works
On 10 September 2026, Bitdefender Labs security analyst Silviu Stahie published an investigation showing that Google Play's Early Access program has become a blind spot abused by deceptive app developers. The Early Access program strips public star ratings and written reviews from app listings while they remain in Early Access, removing one of Google Play's most important trust signals. Bitdefender's telemetry identified thousands of Early Access apps exhibiting deceptive patterns: fake casino games, slot-machine imitations, reward and 'earn money' applications, misleading utilities (PDF readers, QR scanners, phone trackers), and games abusing recognizable third-party trademarks. Because listings can remain in perpetual Early Access, several accumulated hundreds of thousands to over one million installs with zero public feedback available to warn prospective users. As Bitdefender noted, the same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted.
The campaign exploits trust in the official distribution channel itself. Users are far more willing to install an app that comes from the Google Play Store, and the absence of ratings removes the standard red flag. Named deceptive apps documented across the investigation include at least two titles uploaded as 'Grand Theft Auto V (Early Access)' and later renamed once they had been indexed by Google search, with AI-generated screenshots that do not reflect actual gameplay; one such title, the GTA-styled game 'Vice Streets: Open World' (Android package com.gamblechaos.withfriends.game), surpassed 1,000,000 downloads with no reviews or ratings before it was removed from the store. After its removal, new listings carrying the same 'Grand Theft Auto V (Early Access)' name appeared. Third-party APK mirrors record the same package also being published under the label 'Chaos With Friends' by the Google Play developer account 'STOCK AGE INTERNATIONAL' (version 0.3, last updated 11 August 2026, Android 7.1+). Additional named lures include the fake money games 'Chicken Road' and 'Ice Fishing', which promise cash multipliers while operating an engagement loop: users receive generous virtual rewards immediately, but progress slows dramatically at the withdrawal threshold, PayPal or cryptocurrency payouts never arrive, and the app serves advertisement after advertisement — illicit ad revenue being the intended income stream. Many casino-style apps disguise themselves as casual slot and puzzle games to sidestep gambling licensing, geofencing, and age-verification requirements.
Promotion is aggressive and channel-abusing: deceptive apps are advertised on TikTok, Facebook, and other social platforms using AI-generated deepfakes of celebrities, athletes, and public figures endorsing the apps, alongside fake videos of TikTok users 'instantly receiving money'. Ad lures include claims such as 'you're getting 250 spins for free' or doubling money by helping a chicken cross a road. Ads point users directly to Early Access listings in Google Play or to gambling websites. TikTok and Facebook typically take these ads down quickly, but the operators keep producing fresh ones. Bitdefender also flagged that many PDF readers and QR scanners are the same app uploaded by seemingly different developers, with some developers repeating under different names — a pattern consistent with bulk app-production operations.
The abuse can escalate beyond fake payouts. During its investigation Bitdefender examined a QR-scanning Early Access app that attempted to convince a Pixel user to replace the official Android launcher. A QR scanner requires only camera access and has zero legitimate reason to act as a home-screen replacement. If granted launcher status, such an app could run continuously in the background, silently load hidden WebViews to click advertisements (clickjacking), display fake login screens, intercept taps, and capture two-factor authentication codes delivered through notifications. Stahie warned that the developers behind these apps could push an update that makes them 'extremely dangerous' once they accumulate popularity, evolving a benign-looking utility into a fully malicious threat.
Google was notified of the findings and confirmed it is investigating. Zimperium's Mobile Threat Watch summary (25 September 2026) framed the activity for mobile defenders as the abuse of a trusted mobile distribution channel as an entry point for social engineering. Recommended defenses include evaluating app behavior beyond installation, limiting downloads to verified sources, deploying mobile threat defense, provisioning Android Enterprise Work Profiles on BYOD devices to isolate work data from personal apps, and using Google Workspace admin controls to disable or restrict Early Access app installation across the organization.
MITRE ATT&CK techniques used in TL-2026-2655
Defense Evasion
T1036 Masquerading; T1684.001 Impersonation
Credential Access
T1111 Multi-Factor Authentication Interception; T1417 Input Capture
Execution
T1204.002 User Execution: Malicious File
Collection
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware
Affected products and versions in Deceptive Android Apps Exploit Google Play Early Access to
- Google — Google Play Store (Early Access program)
Vulnerable versions: All current Google Play client versions supporting Early Access listings; Perpetual Early Access listings — program feature disables public ratings and reviews - Google — Android
Vulnerable versions: Android 7.1 and later (minSdkVersion of observed deceptive apps)
Remediation for Deceptive Android Apps Exploit Google Play Early Access to
Immediate actions
- Use mobile threat defense / MDM to blocklist package com.gamblechaos.withfriends.game and any Early Access listings from unknown or newly created developer accounts
- Enable Google Play Protect enhanced scanning and review its alerts on managed devices
- Disable Early Access app availability for the organization (or by organizational unit/group) in Google Workspace admin
- Audit and revoke launcher/home-screen (CATEGORY_HOME), notification-access, and overlay permissions granted to utility apps such as QR scanners and PDF readers
- Warn users: Play Store listings without public ratings or reviews (Early Access) carry elevated scam risk
Workarounds
- Treat any Early Access listing as untrusted until public reviews and ratings are available
- Block installs from unofficial APK mirror sites (e.g., apkcombo.com, apkpure.com) that rehost delisted deceptive packages
- Limit social-media click-through to app installs by default on managed devices
Longer-term hardening
- Provision Android Enterprise Work Profiles on BYOD devices to separate and sandbox personal apps from work data
- Stand up app-vetting and continuous mobile monitoring; evaluate app behavior (permissions, background processes, WebView activity) beyond installation
- Deliver employee security awareness focused on review-evading store listings, deepfake-ad lures, and promised-payout scams
- Pressure and monitor platform remediation: Google Play Early Access abuse verification and faster enforcement on trademark-infringing listings
Timeline of Deceptive Android Apps Exploit Google Play Early Access to
- Deceptive app 'Vice Streets: Open World' / 'Chaos With Friends' (package com.gamblechaos.withfriends.game) last updated as version 0.3 by Google Play developer account STOCK AGE INTERNATIONAL; listing remained in Early Access with no public ratings while accumulating installs (APK mirrors record the metadata after delisting).
- Operators continue reposting TikTok and Facebook ads built around AI-generated celebrity deepfakes (e.g., '250 free spins' lures, instant-cash claims) after each ad takedown; ads point directly to Early Access Play listings or gambling websites.
- The GTA-styled fake 'Grand Theft Auto V (Early Access)' game 'Vice Streets: Open World' (package com.gamblechaos.withfriends.game, over 1,000,000 downloads, no reviews) is no longer available on Google Play; Bitdefender observes new listings popping up under the same GTA V name afterward.
- Bitdefender notifies Google of the fraudulent Early Access listings; Google confirms it is investigating the situation.
- Bitdefender Labs (security analyst Silviu Stahie) publishes its investigation showing thousands of deceptive Early Access apps on Google Play - fake casino games, reward/earn-money apps, misleading utilities, and trademark-infringing titles - abusing the program's lack of public ratings and reviews.
- CSO Online details a QR-scanner Early Access app that prompted a Pixel user to replace the official Android launcher, a privilege that would enable hidden-WebView ad clicking, fake login screens, tap interception, and capture of 2FA codes from notifications; advises Android Enterprise Work Profiles for BYOD.
- Zimperium's Mobile Threat Watch summarizes the Bitdefender investigation for mobile defenders, framing the campaign as exploitation of trusted mobile distribution channels as an entry point for social engineering.
Sources cited for Deceptive Android Apps Exploit Google Play Early Access to
- Deceptive Apps Exploit Google Play Early Access to Reach Mobile Users
- Google Play's Early Access program may be exploited by potentially deceptive apps
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
- Google's Early Access is creating a blind spot for malicious apps
- Google Play Early Access Abused to Push Deceptive Android Apps
- Deceptive apps abuse Google Play Early Access
- Google's Early Access is creating a blind spot for malicious apps (syndicated coverage)
More in malware
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
- TokenGrabber: Python-based MaaS Infostealer Builder
Detection coverage for TL-2026-2655
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2655 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.