A Grand Theft Auto imitator named "Vice Streets: Open World" (APK package: com.gamblechaos.withfriends.game) accumulated more than 1 million downloads while showing no public reviews or star ratings on Google Play, according to reporting shared with The Hacker News.
How Google Play’s Early Access feature is being repurposed
Google Play's Early Access program is intended to let developers solicit user feedback on apps before full release. One built-in feature removes the ability for users to post public reviews or star ratings for Early Access titles. That removal, Bitdefender told reporters, “shields developers from unfair criticism” but also “strips users of the earliest warning that an app cannot be trusted.” The absence of community review signals has created an opening that bad actors are exploiting to promote deceptive apps at scale.
Bogus promotions on TikTok and Facebook, and celebrity deepfakes
Security researchers told The Hacker News that many suspect Early Access apps are driven to installs by paid and organic posts on TikTok, Facebook, and other social platforms. Ads often include AI-generated celebrity deepfakes to lend credibility. According to the Romanian cybersecurity company behind the analysis, users “install the app after watching an advertisement on TikTok or Facebook.” Initial installs may yield generous virtual rewards, the company said, but when users reach a withdrawal threshold “progression slows dramatically. The promised payout will never arrive.”

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageCasino-style apps, regulatory evasion, and the ad-revenue motive
Researchers described a recurring motif: Early Access titles promise cash, PayPal payouts, cryptocurrency earnings, gift cards, free spins, or casino jackpots. Operators use casual-game facades—slots, puzzles, or simple arcade mechanics—to avoid licensing, geofencing, and age-verification controls that legitimate gambling apps must follow. The reported end goal is straightforward: “generate illicit revenue by serving ad after ad.” By routing victims to Early Access listings or directly to gambling websites, operators bypass the checks that legitimate wagering platforms would face.
Notable examples and linked Android threats
Beyond "Vice Streets: Open World," the reporting links the Early Access abuse trend to multiple Android-oriented threats and criminal toolchains. The disclosure accompanies accounts of new and active malware families:
- Hagaseca — a remote access trojan spread via the THost9 loader that includes a worm component. It scans exposed Android Debug Bridge (ADB) services to install the malware for persistence and remote control, enabling shell execution, file transfers, tunneling, and downloadable modules.
- Mantax Otax — described as hybrid mobile malware with spyware and ransomware capabilities that can steal sensitive data and, on older Android versions (Android 9 or earlier), encrypt data and lock the device screen to demand payment. Language indicators and victim files suggest activity primarily focused on Indonesian targets.
- StreamRat — which abuses Android accessibility services and the MediaProjection API to control infected devices, serve overlays, and harvest data. Operators used Meta and TikTok ads to funnel Spanish-speaking users to counterfeit sites by posing as a free TV-streaming service called StreamTV Esp.
- GoldFactory/Gigabud/Vwork — a campaign that used the Gigabud banking trojan to install an Android companion app named Vwork, described as a weaponized fork of Shelter. The technique clones a target app inside a work profile so an operator with remote control can “carry out transactions directly on the victim's phone while a black screen hides what is happening,” Group-IB said. The cloned environment helps evade fraud protection controls.
What this means for technologists, policymakers, and end users
- Technologists and security teams: Watch for the specific technical indicators mentioned in the report—ADB exposure (Hagaseca), misuse of accessibility APIs and MediaProjection (StreamRat), and cloned work-profile apps used for fraud (Vwork/Shelter fork). Those artifacts tie deceptive distribution to operational malware capabilities.
- Policymakers and regulators: The analysis highlights a regulatory gap: casino-style mechanics hidden behind casual games and deployed through Early Access can sidestep licensing, geofencing, and age checks. Regulators overseeing online gambling and consumer protection may need to consider how distribution programs interact with existing compliance frameworks.
- End users and the public: Ads that promise real-world payouts or show deepfaked celebrities can be persuasive; the report underlines that Early Access listings will not display public reviews or ratings, removing a common community-level warning sign. Users encountering such ads should be skeptical of promised payouts and mindful that initial virtual rewards may be a lure, not a real payment pathway.
The Hacker News said it has contacted Google for comment and will update the story if it hears back. For now, the combination of a review-free Early Access channel, aggressive social promotion, AI-generated creative, and established Android malware toolchains presents a coordinated set of risks that researchers say has already delivered wide reach—at least one imitation title passed the million-download mark while leaving no public trace of user experience.




