Security1 publisher2 min readPublished
Ghost casino apps exploit Google Play's ratings-free Early Access channel
Bitdefender says developers list deceptive apps in Google Play's Early Access program, where feedback goes only to the developer, then buy TikTok and Facebook ads to drive installs straight past the review layer.
The Watch · Security desk

What happened
- Bitdefender says deceptive developers list apps in Early Access and then buy TikTok and Facebook ads promising PayPal payouts, cryptocurrency earnings, gift cards or free casino spins to drive direct installs.
- One recurring trick is uploading a listing as 'Grand Theft Auto V (Early Access)', waiting for Google Search to index it, then renaming the app so searches for the real game still land on it.
- Bitdefender describes the problem as widespread, with some developer accounts appearing multiple times and some listings showing thousands of installs.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint The check most users and helpdesks make first, does this app have reviews and what do they say, produces nothing inside this channel, because no listing in it has reviews to compare against.
- exposure Mobile policies written around install provenance still admit these apps, since Google Play is the distributor; the reputational filtering those policies implicitly leaned on does not extend to Early Access.
- capability Rename-after-indexing makes a search result or a shared store link an unstable pointer to a specific app, a technique that works for anything that benefits from borrowed search traffic.
- contradiction Bitdefender's widespread-abuse framing sits against SecurityWeek's note that no malware is involved and nothing clearly illegal is alleged, which decides whether the answer is takedowns or a change to Google's program rules.
Play Protect has nothing to flag here. Bitdefender's account describes apps that serve ads, not payloads [11]. The control that fails is the reputational one, and it fails by design: Early Access routes feedback from the user to the developer and never between users, so a listing carries no star rating, no review text and no warning [1]. An empty review count would normally be reason enough to back out of an ordinary Play listing, but inside Early Access it is the expected state, so the fastest check available returns the same result for a fraudulent listing and an honest one [13].
Store search is not in the path either. Users arrive from paid social ads and click through to the install [2], which leaves Play's ranking and review surfaces outside the sequence entirely [14]. For device policy the distinction is narrower than it looks: these apps are distributed by Google Play, so an allowlist or MDM rule that gates on install provenance passes them without complaint [15]. The research as reported describes no enterprise incident, no managed-device targeting and no policy bypass [18]. The gap sits in the review signal; the provenance signal still checks out.
Revenue is ad impressions. The promised payout never arrives and the app keeps serving advertisements, which Bitdefender reads as the purpose of the build [4]. Chicken Road and Ice Fishing, or variants on those names, are the two recurring shells [7], and the casino-style titles present as casual slot or puzzle games, which is also how they stay clear of the regulation a licensed gambling operator would face [5]. Many of the ads use deepfakes of athletes and actors offering free spins [6], and the renamed listings show AI-generated screenshots that do not match gameplay [9]. Scope is where the reporting stops being specific: repeat developers, and some listings at thousands of installs [10], with no dates and no developer names given [16].
The ad platforms currently handle enforcement. Bitdefender credits social networks with getting good at spotting and pulling these campaigns, and notes in the same breath that relaunching one is easy [12]. Nothing here ships as a patch and there is no deadline to name. The remedy on offer is a Google policy change that puts a rating facility or a warning on Early Access listings, and until that exists, Play's review layer offers coverage with a documented hole, one that belongs to Early Access and not to the wider store.
What to watch
- Whether Google adds a rating facility, a warning label or enrollment limits to Early Access listings.
- Whether an Early Access listing is later found delivering a payload, which moves this from ad fraud to malware distribution.
- Whether Bitdefender or Google publishes developer names and install totals, turning 'widespread' into a measurable footprint.