Google created the Early Access program to help developers gather feedback before releasing finished applications. However, the feature appears to have become an attractive destination for some developers who may exploit one important aspect: users cannot leave public reviews or ratings while an app remains in Early Access.
An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities.
Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes.
The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software.
Key Takeaways
Google’s Early Access program disables public ratings and reviews.
Many deceptive developers appear to exploit this limitation.
Numerous Early Access listings promise money, rewards, casino winnings, or premium content.
Users cannot publicly warn others if an app is misleading.
Trademark-infringing titles are also appearing inside Early Access.
The lack of transparency makes it significantly harder for consumers to distinguish legitimate beta software from deceptive applications.
What is Google Play Early Access?
Google launched Early Access to give developers a platform to publish unfinished or still-in-development applications and collect feedback from early adopters.
Instead of waiting for a polished release, developers can test features, fix bugs, and improve performance based on user experiences. This platform would also help independent developers avoid poor ratings due to temporary bugs or missing features.
This sounds great, in theory, but the problem is that Early Access removes one of Google Play’s most important trust signals: public reviews and star ratings.
New users can’t see whether previous users faced scams, annoying ads, fake casino payouts, or other misleading claims.
Why scammers are increasingly attracted to Early Access
Several characteristics make Early Access unusually attractive to operators running misleading applications.
Public reviews disappear. The biggest incentive is simple. Users can’t publicly warn one another if the app floods users with ads, if a reward app never actually pays or if a fake utility app demands excessive permissions. And that’s only a handful of “ifs” as there are countless other scenarios in which users cand be tricked.
A normal release would quickly accumulate one-star reviews, which would be a good signal for others to avoid it.
Fake money-making apps become much harder to identify. A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots.
Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive.
Instead, the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.
The anatomy of an “Early Access ghost casino”
Legitimate gambling applications face strict regulatory requirements. Depending on jurisdiction, they often require licensing, geofencing, age verification and many other regulatory measures.
Many suspicious Early Access casino-style apps avoid those expectations entirely because they don’t necessarily present themselves as regulated gambling products.
Instead, they resemble casual slot games, reward games, or puzzle titles. People are first tricked into installing the apps by being redirected from ads on social media. Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free. Of how you only need to cross the road as a chicken without being run over.
Random users on TikTok, for example, make videos of themselves instantly receiving the money in their accounts. To be fair, TikTok or Facebook are usually quick to take down these ads and videos, but that doesn’t stop the attackers from coming up with new scenarios.
Here are some screenshots from TikTok ads using deepfakes:
When active, some of these ads pointed to Early Access apps in the Google Play Store or directly to various gambling websites.
Chicken Road or Ice Fishing games
Some of the most abused titles for game are Chicken Road or Ice Fishing (or variations on the same theme) that all promise the same thing: to multiply the money you invest. The ads make it seem like it’s very easy. Just help the chicken cross the road, and every time you don’t get hit by a car, you double your money.
This is just one example, but there are numerous others. This one is still active; others have been deleted and new ones arrive all the time.
Trademark abuse appears surprisingly common
The Early Access catalog also contains applications that appear to borrow well-known intellectual property, some more blatantly than others.
Some titles appear to be designed to resemble legitimate games or established brands, despite having no visible connection to the original publishers.
A popular strategy is to add an app to the Google Play Store using an established name. Let’s take the GTA franchise. As it stands right now, there are at least two games that use this technique. Both of them were uploaded with the name Grand Theft Auto V (Early Access), only to be renamed later, after being indexed by Google search, to something entirely different.
The screenshot below illustrates only a small sample of Early Access listings collected during the investigation, including multiple apps referencing recognizable brands and casino-style mechanics.Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.
Keep in mind that they boast more than 1 million downloads, but the game has no reviews or ratings, which is usually a good indicator that it’s in the Early Access program.
Evidence suggests the problem is widespread
During this investigation, a review of Early Access listings identified a large number of applications spanning several recurring categories.
These included:
casino games
slot machines
fake reward apps
“earn money” applications
PDF readers
QR scanners
phone trackers
utility apps
trademark-themed games
Some developers appear multiple times under different application names, and many games and apps are virtually identical, with small differences. Several listings also accumulated thousands of installs or more despite remaining in perpetual Early Access.
In fact, we also noticed a large number of PDF readers and QR scanners present in the Early Access program, many of which were actually the same app uploaded by seemingly different developers.
The screenshots collected during the investigation represent only a fraction of the overall catalog.
Why this matters
Google Play’s reputation depends on trust. Ratings and reviews help users make informed decisions, but when those indicators are not present, it makes the users’ job a lot more difficult when they are trying to spot fakes.
Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community’s strongest defenses against deceptive software.
Conclusion
Google’s Early Access program remains a valuable tool for developers testing new ideas. However, our insights suggest that its current implementation also creates an environment where deceptive applications can operate with far less public scrutiny than fully released apps.
When users cannot leave reviews, future users lose one of the most effective warning systems available on any app marketplace.
As fake reward apps, casino-style games, and misleading utilities continue appearing under the Early Access banner, the question is no longer whether the program can be abused.
Users are much quicker to trust an app or game that comes from an official source like the Google Play Store, which is why the Early Access feature is so dangerous.
This article is published for informational and educational purposes only. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. All trademarks mentioned belong to their respective owners. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
Bitdefender has released research detailing SilkParasite, an active, year-long China-nexus cyberespionage campaign targeting government bodies across Central Asia. The operation is using seven custom remote access tools (RATs), five of them newly identified.
SilkParasite is the latest evidence of a trend Bitdefender has tracked since early 2025: as Russia’s regional influence recedes, China-nexus threat actors are expanding operations into Central Asia, targeting government officials who manage the region’s deepening economic ties with Beijing. The objective is spying, not disruption or financial gain.
Key findings:
An active, year-long campaign using seven custom RATs against Central Asian government targets
Professionally engineered, modular toolset built for minimal footprint and evasion, using AI only to speed development, unlike poorly written AI-generated malware elsewhere
Command/Control (C2) traffic routed through legitimate cloud services, including Google Drive, to blend in with normal network traffic
Why it matters: China-nexus tooling typically resurfaces elsewhere, putting organizations across the globe at risk for similar attacks.
Bitdefender has published research detailing an active campaign that leverages the popularity of The Odyssey to target those searching for pirated copies and distribute Lumma Stealer malware in the process.
Key findings include:
Malicious .exe files are disguised as 1080p and Blu-ray movie downloads, with icons spoofed to look like VLC Media Player. Since Windows hides file extensions by default, victims can’t easily tell it’s a program and not a video.
Once executed, Lumma Stealer harvests browser passwords, authentication cookies, saved payment data, and cryptocurrency wallets, and can hijack active sessions even when multi-factor authentication is enabled.
The campaign is nearly identical to a 2025 operation that abused Mission: Impossible – The Final Reckoning torrents, showing attackers simply recycle the playbook around whatever film is dominating search traffic.
Bitdefender have released research documenting three previously undocumented attack techniques that abuse a legitimate Windows feature called bind links to bypass endpoint detection and response (EDR) and built-in Windows defenses, including AMSI, AppLocker, Windows Firewall, and Sysmon.
The techniques abuse a virtualization feature built into Windows 10 RS4+ and Windows 11 to redirect trusted file paths to attacker-controlled files — without modifying files on disk.
Key findings:
Three novel bind link attack techniques (File-Binding, Process-Binding, and Silo-Binding) evade security detection at the kernel level
Silo-Binding, the most advanced of the three, splits the filesystem into two views so malicious code executes inside an isolated container while security tools outside see only clean, legitimate files
Bitdefender successfully verified the techniques in a live environment, bypassing EDR defenses with the infostealer Invoke-Mimikatz
Think your small business is too small to be targeted by ransomware?
That’s precisely the assumption cybercriminals hope you’ll make.
Bitdefender Antispam researchers have uncovered a phishing campaign targeting small businesses across Europe, Asia, the Middle East, and the United States with fake investigation emails impersonating law enforcement officials.
The messages claim to contain evidence of suspicious company activity, but there’s a catch: The attached ‘evidence’ is actually ransomware.
Key takeaways
Researchers at Bitdefender Antispam Lab have identified a malicious campaign impersonating Interpol
The emails claim to contain evidence of suspicious company activity and pressure recipients into opening a password-protected archive.
Recipients are directed to a Proton Drive-hosted file that ultimately delivers ransomware.
The ransomware appears to be a custom-built payload rather than a known ransomware family.
The operation targeted organizations across Europe, Asia, the Middle East, and the United States.
Small businesses are particularly at risk because many lack dedicated IT and cybersecurity resources.
How the attack works
The emails arrive with an urgent tone, claiming to be from Interpol’s cybercrime investigation unit, which is conducting a compliance or security review.
Recipients are told that investigators have obtained information and video material related to their organization and are encouraged to review the evidence as soon as possible.
The message is carefully crafted to create anxiety. Nobody wants to receive an email suggesting their company may be involved in suspicious or fraudulent activity or under investigation.
To review the alleged evidence, recipients are directed to a Proton Drive link containing a password-protected archive. The password is conveniently included in the email itself.
Once opened, the archive appears to contain a video file documenting the supposed activities under investigation.
Instead, the victim is greeted with malware.
The attackers use a familiar trick: disguising an executable as a video file in the hope that recipients won’t notice the difference before opening it.
The malware isn’t sophisticated. The social engineering is.
According to researchers Viorel Vrabie and Andrei Mogage, the fake video contains a ransomware payload hidden within multiple archive layers.
Once executed, the malware seeks to encrypt files across available drives and presents victims with a ransom message:
“Your computer has been compromised, and you will not be able to recover your encrypted files without the decryption key.
Do not delete any files or change their locations. Do not scan your computer, as this may complicate the recovery process.
We are available only through Tox.”
One interesting detail is what the ransom note doesn’t say:
Unlike older ransomware attacks that immediately demanded a fixed payment amount, this note doesn’t specify a ransom at all. Instead, victims are instructed to contact the attackers through a Tox chat channel.
This approach has become increasingly common among ransomware operators. Rather than demanding the same amount from every victim, attackers often prefer to negotiate after establishing contact. The final ransom may depend on the size of the organization, the perceived value of its data, and its ability to pay.
The researchers also found that the malware itself is relatively simple. The code contains hardcoded values, including the password used during encryption and decryption, and lacks many of the features typically associated with large ransomware operations.
Bitdefender researchers observed the campaign targeting organizations across multiple industries, including food and agriculture, legal services, pharmaceuticals, media, technology, and finance.
The campaign was also geographically diverse, with targets identified across Europe, Asia, the Middle East, and the United States.
Is this attack linked to a major ransomware gang?
In fact, the malware seems much simpler than the tools typically used in major ransomware operations. Beyond the relatively basic code observed by our researchers, another notable difference is how victims are instructed to make contact.
Most modern ransomware-as-a-service (RaaS) groups direct victims to a dedicated negotiation portal hosted on the dark web, where they can exchange messages, receive payment instructions, and negotiate the ransom.
In this campaign, however, the attackers simply provide a Tox chat ID. There is no dedicated negotiation portal or victim site, which is another indication that this is likely a custom-built operation rather than the work of an established ransomware group.
This suggests the malware may have been custom-built or assembled using publicly available code and tools.
The campaign highlights an important trend: cybercriminals no longer need the resources or expertise of a large ransomware gang to launch disruptive attacks. Even relatively simple malware can become a serious threat when paired with convincing social engineering.
In this case, the fake investigation email does much of the heavy lifting. The attackers rely on fear, urgency, and authority to persuade victims to launch the malware themselves.
Why small businesses remain attractive targets
Small businesses are often viewed as easier targets than large enterprises.
Many operate without dedicated IT teams or cybersecurity staff. Security responsibilities are often shared among employees who already wear multiple hats, and limited budgets can make it difficult to invest in advanced security measures or ongoing training.
When an alarming email arrives claiming to involve investigators, compliance issues, or evidence of misconduct, there may be no formal process for verifying the claims before someone clicks.
Attackers understand this reality and design campaigns specifically to exploit it.
What should you do if you opened the file?
If you downloaded and opened a file like the one used in this campaign, don’t panic, but don’t ignore it either. Acting quickly can make a big difference.
Disconnect the affected device from the network. If ransomware or other malware is running, taking the computer offline may help prevent it from communicating with attacker-controlled servers or spreading to shared drives and other devices.
Run a full security scan. Use a trusted security solution, such as Bitdefender Ultimate Small Business Security, to perform a complete scan of the affected device. Even if nothing appears unusual, remember that some threats are designed to remain hidden until they’ve completed their job.
Notify your IT administrator or managed service provider, where possible. If you’re part of a business, don’t try to deal with the incident alone. The sooner your IT team is aware, the faster they can isolate affected systems and prevent additional damage.
Inform your team about the attack. Awareness can also make a huge difference in protecting your business, devices, data, and reputation.
Change important passwords from a clean device. If there’s any chance the malware also harvested credentials, update passwords for your business email, cloud storage, financial accounts, and collaboration platforms. Use strong, unique passwords and enable multi-factor authentication wherever it’s available.
Look for signs of suspicious activity. Watch for unexpected login alerts, password reset emails, unfamiliar transactions, or files that suddenly become inaccessible. Continue monitoring your accounts over the following days, as some attacks don’t reveal their full impact immediately.
Report the incident. Report the phishing email through your email provider’s “Report phishing” feature and notify the organization being impersonated when appropriate. If your business has been infected or you suspect ransomware was executed, consider reporting the incident to your national cybersecurity agency. Sharing information about active campaigns helps authorities warn other organizations and better understand emerging threats.
Campaigns like this prove that ransomware attacks don’t always begin with sophisticated hacking techniques. Often, they start with a message designed to create panic.
To reduce the risk of your small business falling victim to a similar ransomware attack:
Verify all unsolicited correspondence before acting: If you receive a message claiming to come from law enforcement, regulators, or another authority, don’t rely on the contact details provided in the email. Reach out through official channels to confirm whether the communication is legitimate.
Note: One of the biggest red flags in this campaign is the delivery method itself. While the attackers impersonate Interpol, legitimate law enforcement agencies don’t send unsolicited emails containing Proton Drive links to password-protected files and ask organizations to review alleged evidence of wrongdoing. If you receive a message like this, resist the urge to investigate on your own. Instead, verify the communication through official channels before opening any attachments or downloading files.
Treat password-protected archives with caution, especially when the password is included in the email.
Show file extensions on Windows devices: This makes it easier to spot executables masquerading as videos or documents.
Enable multi-factor authentication wherever possible. MFA won’t stop ransomware that’s already running, but it can prevent attackers from accessing your business accounts if they also try to steal passwords.
Keep systems and software up to date. Regular security updates help close vulnerabilities that attackers may exploit before or after a phishing attack.
Train employees to recognize scams: Criminals increasingly rely on fear and urgency rather than technical exploits.
Maintain secure backups: Reliable backups remain one of the best defenses against ransomware.
Use layered security designed for small businesses: Even well-trained employees can have an off day, and attackers count on those moments. Solutions such as Bitdefender Ultimate Small Business Security add another layer of defense by helping block phishing emails, detecting malicious downloads, identifying suspicious behavior, and stopping ransomware in its tracks.
This article is published for informational and educational purposes only. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
Bitdefender, a global cybersecurity leader, today announced the launch of Bitdefender RealCheck, a standalone solution that helps consumers evaluate the authenticity of video content circulating across digital platforms and whether it carries malicious intent — such as financial fraud, credential theft, or defamation. As deepfakes proliferate across social media at an unprecedented pace, Bitdefender RealCheck gives consumers a powerful and accessible tool to separate fact from fabrication before they trust, share, or act on what they see.
Deepfakes have become one of the most effective tactics in a cybercriminal’s playbook. Deloitte predicts generative AI could drive fraud losses to $40 billion in the U.S. alone by 2027. According to a Bitdefender global survey of 7,000 consumers, AI-powered deepfake scams ranked as the top security concern — and social media has now surpassed every other channel as the leading medium for successful scams. The same survey found that consumers correctly identify high-quality deepfakes only 24% of the time.
Bitdefender RealCheck is a standalone solution for Android and iOS devices. Once installed, users simply submit a video link or upload a file for analysis. Bitdefender RealCheck conducts a structured, multi-layered analysis, recognizing that not all synthetic or altered videos are malicious (some are clearly satirical or entertainment-driven) and delivers a detailed report covering manipulation likelihood, deceptive intent, and transcript-level indicators. Rather than a simple yes-or-no verdict, Bitdefender RealCheck arms consumers with the context they need to make informed decisions.
Key features and benefits include:
Validate deepfakes across all major social media platforms — Bitdefendeer RealCheck assesses video content from local uploads, web-hosted videos, and posts across X, YouTube, Instagram, Facebook, and TikTok. It also identifies public figures, including celebrities, well-known business executives, and politicians, who are currently being impersonated or misused in active deepfake campaigns.
In-depth analysis and actionable reports — Bitdefender RealCheck delivers a thorough, multi-layered analysis of video content and associated audio, assessing manipulation likelihood and deception risk at the transcript level — evaluating speech segment by segment to pinpoint exactly where manipulation may have occurred. Rather than a simple yes-or-no result, consumers receive a detailed, structured report telling them what they are looking at and whether it was designed to steal their money, credentials, or personal information.
Protect the people you care about — Bitdefender RealCheck analysis and reports are shareable and can be sent to family and friends, even if they don’t have an account. In a world where a single convincing deepfake can spread quickly through a family group chat, the ability to share verified findings is a meaningful line of defense.
Availability: Bitdefender RealCheck is available now for Android and iOS devices in English across 14 countries, including the U.S., U.K., Australia, Canada, Germany, Italy, Spain, and France. Support for additional languages is planned for future releases.
Bitdefender today released the Bitdefender 2026 Global Scam Intelligence Report, a comprehensive analysis of the global scam landscape over a 12-month period. The report examines how scams have evolved into a sophisticated, cross-platform criminal industry, revealing the tactics, channels, and behavioral patterns that fraudsters use to target consumers worldwide.
Online scams and fraud continue to escalate at an alarming rate. Losses due to scams globally have reached nearly half a billion US dollars in 2025 alone. Bitdefender’s independent global survey of 7,000 consumers reinforces the severity of the problem with 1 in 7 (14%) reporting falling victim to a scam in the past year, a finding that confirms scams as not merely a cybersecurity issue, but a serious threat to consumers’ financial security and digital identity.
The Bitdefender 2026 Global Scam Intelligence Report is built from real-time insights spanning trillions of URLs, billions of messages, live ad ecosystems, call honeypots, and direct consumer submissions. This telemetry captures scam activity as it happens, tracking campaigns across platforms and documenting attacker behavior in motion. The result is a field report that gives both consumers and the security community a comprehensive, data-driven view of how scams operate at scale.
Key findings include:
Younger generation is highly targeted – Younger consumers are now twice as likely to fall victim to scams as older generations, with a victimization rate of 20% compared to 9.7% among those 55 and older. Scammers have followed their audience to the social platforms, gaming environments, and messaging apps where younger users spend the most time.
1 in 20 text messages shows signs of fraud – Extensive analysis of SMS traffic found that 5.2% of all messages analyzed (roughly 1 in 20) exhibited characteristics consistent with scam infrastructure or coordinated fraud activity. For a communication channel people inherently trust, that exposure rate is a serious cause for concern.
Voice calls remain a high-yield fraud channel – Bitdefender analyzed nearly 150 million incoming calls during the reporting period. More than 23 million were classified as unwanted, meaning about 1 in 6 calls reaching protected devices was deemed fraudulent or unsolicited. The system processed more than 52 million unique phone numbers, with over half a million flagged as unwanted.
Finance scams dominate across every channel – Investment fraud, banking phishing, and crypto-themed scams appear consistently across SMS, social ads, WhatsApp, voice calls, and email. The lure changes with the platform, but the objective remains constant: quickly move the victim toward a financial decision before skepticism has a chance to intervene.
To download a complimentary copy of the Bitdefender 2026 Global Scam Intelligence Report, visit here.
Bitdefender has released new research documenting how attackers continue to abuse Microsoft’s legacy MSHTA utility to deliver malware through stealthy, multi-stage attack chains. The abuse of MSHTA affects both businesses and consumers who run Windows.
Despite Internet Explorer reaching end of support years ago, MSHTA remains enabled by default on Windows systems and continues to be heavily exploited by cybercriminals to execute malicious scripts, retrieve remote payloads, and evade detection using trusted Microsoft-signed processes.
Key findings include:
MSHTA used to silently deliver multiple malware families, including LummaStealer, Amatera, ClipBanker, PurpleFox, and CountLoader
Multi-stage, fileless attack chains using HTA scripts, PowerShell, and in-memory payloads to bypass traditional detection tools
Use of ClickFix-style lures and fake software downloads designed to trick users into manually launching malware infections
The research highlights how legacy Windows utilities continue to pose risks to general users and organizations by providing attackers with trusted tools that blend malicious activity into legitimate system behavior.
UPDATE: Adrian Culley, Senior Sales Engineer, SafeBreach has this comment:
Adrian has extensive global cyber investigations experience, including technical roles at SafeBreach, Trellix, Palo Alto Networks, Norse, and the London Metropolitan Police Service.
“Reporting this week of a fresh surge in malware campaigns abusing mshta.exe should surprise nobody who has spent any time on the offensive side of the trade. The Windows utility has been shipping for 26 years, it is signed by Microsoft, it runs script in a trusted process context, and it is allow-listed by default in most enterprise estates. From APT28 to FIN7, from MuddyWater to whichever commodity loader is fashionable this month, attackers reach for it for the same reason burglars reach for unlocked doors.
There is no patch for this, because mshta is working as designed. What isn’t working is the quiet assumption — held in nearly every security organisation I walk into — that the AppLocker rule, the ASR policy, the EDR behavioural detection written eighteen months ago all still fire today. Estates drift. Exceptions accumulate. Rules quietly degrade. And almost no defender can prove, on demand, that they don’t.
The fix isn’t another product. It’s a discipline: safely run the attack on your own production estate, on a continuous schedule, and watch your stack respond. Replace “we believe we’re covered” with “we proved we are.”
Bitdefender has released new research on a large-scale global smishing campaign targeting consumers with fake toll, parking, and traffic fine-themed messages designed to steal money and personal information or remotely control devices. The campaign remains active across 12 countries.
Researchers identified more than 79,000 fraudulent text messages and over 31,900 malicious URLs, using techniques such as sender ID spoofing, rotating domains, and masked links to evade detection.
The messages impersonate trusted transport authorities and pressure victims into making payments through fake websites or, in many cases, installing malware.
Key takeaways from the research:
Over 79,000 fraudulent messages have already been detected in 40 distinct SMS scam campaigns
The scams impersonate DMVs, toll operators, and parking authorities from all over the world
Victims are redirected to fake payment sites or, in some cases, malware downloads
Its infrastructure is characterized by rapid domain generation, sender-ID spoofing, and multiple evasion techniques targeting mobile operating systems
Bitdefender today announced Bitdefender GravityZone Extended Email Security, unifying email and endpoint protection within a single platform. Built for organizations, managed service providers (MSPs) and their customers, it leverages an Integrated Cloud Email Security (ICES) approach to deliver continuous protection before and after delivery against modern email-borne threats including phishing, business email compromise (BEC), ransomware, impersonation, and insider-driven attacks.
“Email threats are growing more sophisticated and effective as total business email compromise-related payments crossed the $6 billion threshold in 2024”, according to Gartner®.¹ In a global survey of 1,200 IT and security professionals, 42% identified BEC as the greatest threat to their organization, while 66% reported an increase in these types of attacks.
Legacy email security solutions often focus on pre-delivery filtering, leaving gaps once threats reach user inboxes. Siloed email and endpoint security tools further create blind spots attackers exploit, increasing dwell time and delaying detection.
Bitdefender GravityZone Extended Email Security is a native email security solution that closes this gap by combining secure email gateway (SEG) filtering with API-based post-delivery protection. This dual-layer approach stops threats before delivery and continuously detects and remediates them after they reach inboxes, helping ensure complete protection across the email threat lifecycle. The solution builds on technology gained through Bitdefender’s acquisition of Mesh Security, further strengthening its email protection capabilities.
Fully integrated into Bitdefender GravityZone, the company’s unified security, risk analytics, and compliance platform, GravityZone Extended Email Security extends protection from endpoint to inbox. It integrates seamlessly into existing environments, enabling rapid deployment and time to value.
Key Benefits of GravityZone Extended Email Security include:
Unified email and endpoint protection – GravityZone Extended Email Security uses artificial intelligence (AI) and real-time threat intelligence to stop phishing, BEC, impersonation, ransomware, and other advanced threats. Emails are inspected before delivery and continuously monitored after delivery, enabling automated quarantine and remediation to reduce dwell time and limit user exposure.
Consolidates tools and reduces security team workload – The platform streamlines security management by unifying tools and automating detection and response across the email attack chain. Continuous monitoring and automated remediation reduce manual effort and improve response times.
Improves efficiency and scales security operations – Built for modern environments and service delivery models, GravityZone Extended Email Security enables efficient, scalable security for businesses and MSPs. Centralized management, continuous policy enforcement, and streamlined workflows support multi-tenant environments and simplify security across distributed infrastructures.
Fast, flexible deployment across any environment – Organizations and MSPs can deploy the solution as a SEG across Microsoft 365, hybrid, and diverse environments, with API-based and combined deployment models supported for Microsoft 365.
Availability
Bitdefender GravityZone Extended Email Security is available now as an add-on to GravityZone endpoint security deployments. For more information, visit here.
¹Gartner, How to Develop an Email Security Strategy, Max Taggett, Nikul Patel, August 20, 2025.
Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.
Guest Post: Google Play’s Early Access program may be exploited by potentially deceptive apps
Posted in Commentary with tags Bitdefender on September 10, 2026 by itnerdGoogle created the Early Access program to help developers gather feedback before releasing finished applications. However, the feature appears to have become an attractive destination for some developers who may exploit one important aspect: users cannot leave public reviews or ratings while an app remains in Early Access.
An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities.
Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes.
The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software.
Key Takeaways
What is Google Play Early Access?
Google launched Early Access to give developers a platform to publish unfinished or still-in-development applications and collect feedback from early adopters.
Instead of waiting for a polished release, developers can test features, fix bugs, and improve performance based on user experiences. This platform would also help independent developers avoid poor ratings due to temporary bugs or missing features.
This sounds great, in theory, but the problem is that Early Access removes one of Google Play’s most important trust signals: public reviews and star ratings.
New users can’t see whether previous users faced scams, annoying ads, fake casino payouts, or other misleading claims.
Why scammers are increasingly attracted to Early Access
Several characteristics make Early Access unusually attractive to operators running misleading applications.
Public reviews disappear. The biggest incentive is simple. Users can’t publicly warn one another if the app floods users with ads, if a reward app never actually pays or if a fake utility app demands excessive permissions. And that’s only a handful of “ifs” as there are countless other scenarios in which users cand be tricked.
A normal release would quickly accumulate one-star reviews, which would be a good signal for others to avoid it.
Fake money-making apps become much harder to identify. A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots.
Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive.
Instead, the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.
The anatomy of an “Early Access ghost casino”
Legitimate gambling applications face strict regulatory requirements. Depending on jurisdiction, they often require licensing, geofencing, age verification and many other regulatory measures.
Many suspicious Early Access casino-style apps avoid those expectations entirely because they don’t necessarily present themselves as regulated gambling products.
Instead, they resemble casual slot games, reward games, or puzzle titles. People are first tricked into installing the apps by being redirected from ads on social media. Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free. Of how you only need to cross the road as a chicken without being run over.
Random users on TikTok, for example, make videos of themselves instantly receiving the money in their accounts. To be fair, TikTok or Facebook are usually quick to take down these ads and videos, but that doesn’t stop the attackers from coming up with new scenarios.
Here are some screenshots from TikTok ads using deepfakes:
When active, some of these ads pointed to Early Access apps in the Google Play Store or directly to various gambling websites.
Chicken Road or Ice Fishing games
Some of the most abused titles for game are Chicken Road or Ice Fishing (or variations on the same theme) that all promise the same thing: to multiply the money you invest. The ads make it seem like it’s very easy. Just help the chicken cross the road, and every time you don’t get hit by a car, you double your money.
This is just one example, but there are numerous others. This one is still active; others have been deleted and new ones arrive all the time.
Trademark abuse appears surprisingly common
The Early Access catalog also contains applications that appear to borrow well-known intellectual property, some more blatantly than others.
Some titles appear to be designed to resemble legitimate games or established brands, despite having no visible connection to the original publishers.
A popular strategy is to add an app to the Google Play Store using an established name. Let’s take the GTA franchise. As it stands right now, there are at least two games that use this technique. Both of them were uploaded with the name Grand Theft Auto V (Early Access), only to be renamed later, after being indexed by Google search, to something entirely different.
The screenshot below illustrates only a small sample of Early Access listings collected during the investigation, including multiple apps referencing recognizable brands and casino-style mechanics.Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.
Keep in mind that they boast more than 1 million downloads, but the game has no reviews or ratings, which is usually a good indicator that it’s in the Early Access program.
Evidence suggests the problem is widespread
During this investigation, a review of Early Access listings identified a large number of applications spanning several recurring categories.
These included:
Some developers appear multiple times under different application names, and many games and apps are virtually identical, with small differences. Several listings also accumulated thousands of installs or more despite remaining in perpetual Early Access.
In fact, we also noticed a large number of PDF readers and QR scanners present in the Early Access program, many of which were actually the same app uploaded by seemingly different developers.
The screenshots collected during the investigation represent only a fraction of the overall catalog.
Why this matters
Google Play’s reputation depends on trust. Ratings and reviews help users make informed decisions, but when those indicators are not present, it makes the users’ job a lot more difficult when they are trying to spot fakes.
Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community’s strongest defenses against deceptive software.
Conclusion
Google’s Early Access program remains a valuable tool for developers testing new ideas. However, our insights suggest that its current implementation also creates an environment where deceptive applications can operate with far less public scrutiny than fully released apps.
When users cannot leave reviews, future users lose one of the most effective warning systems available on any app marketplace.
As fake reward apps, casino-style games, and misleading utilities continue appearing under the Early Access banner, the question is no longer whether the program can be abused.
Users are much quicker to trust an app or game that comes from an official source like the Google Play Store, which is why the Early Access feature is so dangerous.
This article is published for informational and educational purposes only. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. All trademarks mentioned belong to their respective owners. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
Leave a comment »