Early Access Loophole Floods Play Store With Scams

The Hacker News · Medium sophistication
Last updated September 10, 2026

Researchers say criminals are abusing Google Play’s “Early Access” program to distribute deceptive apps that promise cash, rewards, or casino winnings. The apps are promoted through social media ads (including AI celebrity deepfakes) and use a “never-ending payout” loop to keep people watching ads while no real reward is delivered.

Key findings

  • Threat actors are pushing thousands of deceptive apps via Google Play’s Early Access program, where users can’t leave public reviews or star ratings.
  • The lures commonly promise cash, PayPal payouts, crypto earnings, gift cards, free spins, or casino jackpots.
  • Apps are promoted through TikTok/Facebook ads, including AI-generated celebrity deepfake videos.
  • A common pattern is an engagement loop: quick early “rewards,” then progress slows at the withdrawal threshold and payouts never arrive, while users are shown ads repeatedly.
  • Some casino-style apps masquerade as casual games to sidestep licensing, geofencing, and age-verification controls and may route users to gambling websites.

Who’s being targeted

  • Commonly targeted roles: All employees, Mobile/BYOD users, Executives, Finance, IT and Mobility/MDM administrators.
  • Affected industries: Technology platforms / app marketplaces, Any organization with employees using Android devices (BYOD or corporate phones).
  • Attack channels: website.
  • Impersonated: A rewards/cashback app promoted via TikTok or Facebook ads, A celebrity (deepfake) endorsing a casino/slot app.

Awareness takeaways

  • Treat “get paid” app ads on social media as suspicious, especially those promising PayPal, crypto, or gift cards.
  • Don’t rely on reviews/ratings as a safety check for Early Access apps; use stricter internal rules for installing apps on work devices.
  • Be skeptical of celebrity endorsements in ads, AI deepfakes are being used to make scams look legitimate.
  • Watch for “withdrawal threshold” manipulation, scam apps may give quick early rewards, then block payouts while showing more ads.

Red flags to watch for

  • Promises of easy money (PayPal/crypto/gift cards) for installing an app
  • App is in Early Access with no public reviews/ratings available
  • Progress slows when trying to withdraw and the payout never arrives
  • Celebrity endorsement video that seems off (possible deepfake)
  • Casino/jackpot claims paired with an Early Access app that lacks normal trust signals
  • Ad tries to funnel users from social media directly to installs or gambling sites
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re scrolling TikTok and see an app that “pays cash to PayPal” just for playing, straight from Google Play Early Access. You install it. At first, fake coins fly in and your balance jumps. But when you hit the withdrawal threshold, progress crawls, ads loop nonstop, and the promised payout never arrives. Some ads even use AI celebrity deepfake videos to push Early Access “slot” apps that secretly funnel you to gambling sites, with no public reviews or ratings to warn you. If any social ad promises PayPal, crypto, or gift cards for installing an Early Access app, don’t touch it on your work phone, close the ad and stick to approved apps only.

Categories

Similar attacks

Early Access Apps Hide Risks From Employees

Early Access Apps Hide Risks From Employees

Bitdefender reports that Google Play’s “Early Access” apps can’t be publicly rated or reviewed, reducing a key warning signal employees use to spot deceptive apps. The research found thousands of suspicious Early Access apps (including fake casino/reward apps and utilities) promoted on social…

September 11, 2026
Fake Reward Apps Abuse Google Play Early Access

Fake Reward Apps Abuse Google Play Early Access

Researchers say scammers are using Google Play’s “Early Access” listings to push deceptive Android apps that don’t show public ratings or warnings. Victims are lured by TikTok/Facebook ads promising cash rewards or free casino spins, but the apps primarily bombard users with ads and never deliver…

September 10, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026
Meta Ads Lure Users Into StreamRat Android Takeover

Meta Ads Lure Users Into StreamRat Android Takeover

Researchers reported a real malvertising campaign where ads on Meta platforms promoted a fake TV-streaming app to Spanish-speaking users, leading them to sideload an Android app. After victims approved a chain of permissions (including Accessibility), the StreamRat trojan could remotely control the…

September 2, 2026
Fake Streaming Ads Push StreamRat Android Trojan

Fake Streaming Ads Push StreamRat Android Trojan

Researchers found a real malicious ad campaign on Meta platforms (and reused on TikTok) that pushed a fake “free TV streaming” service to Spanish-speaking users, mainly in Spain. Clicking the ad led to a tailored website that coached Android users through installing an app from outside Google Play,…

September 3, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026