The Risks of Undisclosed Early Access Software

Google’s Early Access program, designed to help developers refine their products before a full launch, is increasingly being exploited by malicious actors. Recent findings from security firm Bitdefender highlight that this platform has become a breeding ground for scams, malware, and deceptive software.


The Absence of Transparency

Unlike the standard Google Play Store, where user ratings and written reviews serve as a primary defense mechanism, the Early Access section completely omits these features. In the main store, users can gauge an app's legitimacy through community feedback; however, in the Early Access environment, this layer of security is entirely missing. This prevents victims from warning others about fraudulent apps, allowing malicious software to remain active and continue accumulating downloads.


Deceptive Marketing and Deepfakes

Scammers are driving traffic to these dangerous apps through aggressive advertising campaigns on social media platforms like TikTok and Facebook. According to Bitdefender, attackers are using sophisticated tactics to lure unsuspecting users:

  • Celebrity Impersonation: Advertisements often feature deepfakes of public figures, such as Cristiano Ronaldo, Jason Statham, and Andrew Tate, to promote fake gambling platforms.
  • Financial Incentives: Some apps promise unrealistic returns, such as doubling investments for completing simple tasks.
  • Brand Impersonation: Scammers frequently exploit the popularity of upcoming game releases, like the Grand Theft Auto series, using stolen screenshots to appear authentic.

A Recurring Cycle of Malware

The malicious activity extends beyond casino and gaming applications. Researchers identified numerous utility tools—such as PDF readers and QR code scanners—that were uploaded repeatedly by various developers to maximize exposure. Even when these fraudulent apps are identified and removed, they are frequently replaced by identical versions that maintain the same malicious functionality.


As Bitdefender concludes,

"Google Play's reputation relies on users being able to trust the apps they are downloading, but the Early Access program removes almost every way users can detect a malicious app before installing."
The current structure of the program significantly lowers the barrier for cybercriminals, necessitating a more robust vetting process to protect the platform's user base.