Threat actors are exploiting Google Play’s Early Access program to distribute thousands of deceptive Android apps without public ratings or reviews, depriving prospective users of a key fraud warning signal. Promoted through TikTok, Facebook, and other social-media ads—including alleged AI-generated celebrity deepfakes—the apps promise cash, cryptocurrency, gift cards, casino winnings, premium content, or free spins but instead subject users to aggressive advertising and never deliver payouts.
Bitdefender identified recurring fraudulent game themes such as Chicken Road and Ice Fishing, alongside casino apps disguised as casual games to bypass gambling licensing, geofencing, and age-verification controls. Operators also use trademark-abuse and search-indexing tactics, initially publishing titles such as “Grand Theft Auto V (Early Access)” before renaming them; one GTA-themed imitation, “Vice Streets: Open World,” reportedly surpassed one million downloads before its removal. The campaign is primarily ad fraud rather than malware delivery, but can affect thousands of users per listing.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The Grand Theft Auto-impersonating app “Vice Streets: Open World,” using package name com.gamblechaos.withfriends.game, was no longer available on Google Play after reportedly exceeding one million downloads without ratings or reviews. It was unclear whether Google or the uploader removed the app.
Bitdefender identified thousands of deceptive Android apps abusing Google Play Early Access listings, which lack public ratings and reviews. The apps use social-media ads, including celebrity deepfakes, to lure users with false reward, gambling, utility, and trademark-themed offers while generating advertising revenue rather than delivering promised payouts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcexakep.ru
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.