Google Play’s Early Access program becomes a new home for malicious apps

Thousands of applications available through Google Play’s Early Access program include fake reward apps and casino games equipped with tons of ads.
Bitdefender security researchers have discovered that scammers are increasingly interested in Google Play’s Early Access program.
Google’s Early Access program allows developers to test their apps with users before officially releasing them in the Play Store. It’s a way to collect feedback from early adopters to see how they feel about the app’s features and, potentially, fix bugs to improve the overall user experience.
The Early Access program not only offers feedback from the community; developers also avoid poor ratings and negative public reviews that would normally be displayed in the comment section once their app is available in the Play Store.
However, therein lies the risk for users. Because reviews aren’t publicly available in Google Play’s Early Access program, new users can’t be warned about malicious apps. And scammers are well aware of this.
Bitdefender security researchers identified thousands of Early Access apps promising fake cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins, or casino jackpots.
These apps are promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes.
However, once installed, the app aggressively serves advertisement after advertisement, showing the developer’s true colors: making money by showing ads to as many people as possible.
Bitdefender identified a large number of applications spanning several recurring categories, including casino games, slot machines, fake reward apps, earn money apps, PDF readers, QR scanners, utility apps, and games that abuse third-party trademarks.
“Some developers appear multiple times under different application names, and many games and apps are virtually identical, with small differences. Several listings also accumulated thousands of installs or more despite remaining in perpetual Early Access,” security researchers say in an extensive blog explaining how the Early Access scam works.
The analysis shows that the current implementation of Google Play’s Early Access program creates an environment where deceptive and malicious apps can operate with less public scrutiny than fully released apps in the Play Store.
Unfortunately, Bitdefender doesn’t offer a solution for the problem. Instead, users should be vigilant about ads on social media promoting pre-released software, especially when they promise high rewards and quick payouts.
The cybersecurity firm has notified Google of its findings. The tech company confirmed they are investigating the matter.