ZeroHour
CSO Onlinepublished ()ingested
Part of a story covered by 6 sources: “Google Play 'Early Access' Abuse and Mantax Otax Android Ransomware: Key Developments” — merged summary and timeline →

Google’s Early Access is creating a blind spot for malicious apps

mediumMalwareimportance 45
AI summary · glm-5.3-flash

Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.

Bitdefender Labs analyzed Google Play apps installed by its users and identified thousands of Early Access applications that appeared deceptive, including fake casino and reward games, misleading utilities, and apps using third-party trademarks, many promoted via social ads with AI deepfakes. Early Access apps cannot receive public reviews, removing a key warning signal users normally rely on. Some apps requested unusual permissions, such as a QR scanner seeking to replace the device launcher, which could enable hidden web views that click ads and potentially display fake login screens or capture two-factor codes. Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization.

  • Thousands of Early Access apps show fake casino games and misleading utilities
  • Early Access hides user reviews, removing a common warning mechanism
  • A QR scanner requested launcher rights, enabling ad click fraud and possible credential capture
  • Bitdefender recommends Work Profiles; Workspace admins can disable Early Access apps
Full article661 words · extracted from csoonline.com · click to collapse

Google’s Early Access program is meant to give developers a place to release unfinished apps, gather feedback and handle bugs before a full launch.

But new research from Bitdefender Labs suggests the feature may also be giving potentially deceptive applications an unusual advantage, as users cannot publicly rate or review an app while it remains in Early Access.

An analysis of Google Play applications installed by Bitdefender users identified thousands of Early Access apps that appeared to include fake casino and reward games, potentially misleading utilities and applications using recognizable third-party trademarks. Many were also promoted through TikTok, Facebook, and other social platforms, including advertisements featuring AI-generated deepfakes of celebrities and other public figures.

For enterprises, the concern isn’t simply that an employee might waste time on a fake casino game.

Bitdefender Security Analyst Silviu Stahie said some of the seemingly ordinary utilities the company examined requested unusual permissions or exhibited behavior that could create a much more serious problem if such an application were installed on an employee’s Android device.

A QR scanner wanted to become the phone’s launcher

Stahie told CSO that most of the applications discovered were primarily focused on serving advertisements, but some raised more serious concerns.

In one case, a QR-reading application attempted to persuade the user to replace the official Android launcher on a Pixel phone. That is an unusual request for an application whose basic function is scanning QR codes, Stahie noted.

“A QR code scanner only requires Camera access,” he said, adding that it may optionally need access to photos or storage for scanning saved images. “It has zero legitimate reasons to act as a home screen replacement. The most likely scenario is that the developer wanted the app to run continuously in the background.”

As a launcher, it could silently load hidden web views to continuously click on advertisements, a technique known as Clickjacking.

But the same behavior could potentially be used to display fake login screens, intercept taps, and even capture two-factor authentication codes delivered through notifications, Stahie said.

The research found suspicious applications across categories including PDF readers, QR scanners, phone trackers and utility applications, alongside casino, reward and “earn money” applications. Some have accumulated thousands of installs or more while remaining in Early Access.

Enterprises have ways to limit the risk

Bitdefender said it cannot determine whether the devices on which these applications were observed were being used for work or personal purposes. But Stahie argues that the unusual permissions themselves should be treated as a warning sign.

“If one of these apps becomes popular, the developers could push an update to make them extremely dangerous and evolve into a much more malicious threat,“ he said.

That possibility is concerning because Early Access removes one of the mechanisms users normally rely on to identify problematic software. A conventional Play Store application can quickly accumulate negative reviews when users discover misleading behavior. With Early Access, those warnings aren’t publicly available.

For organizations allowing employees to use personal Android devices for work, Stahie recommends using the “Android Enterprise Work Profile” feature that separates work applications and data from employees’ personal environment. Companies can use a Device Policy Controller, such as an enterprise management solution, to provision the work profile on employee-owned devices.

“If the company supplies and owns the phone, then the organization owns the full operating system, but provisions an isolated Work Profile alongside a Personal Profile,” Stahie said. “Everything related to work, email clients, and any other apps runs in its own separate sandbox, and the user can’t install anything they shouldn’t in the Work Profile.”

While this is not a “perfect solution,” Stahie believes that, when paired with dedicated mobile security and employee training around suspicious applications, it can help.

Google itself allows Workspace administrators to turn Early Access applications off for their entire organization or restrict access by organizational unit or group, giving enterprises a way to limit exposure if they deem the risk too high.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4221068/googles-early-access-is-creating-a-blind-spot-for-malicious-apps.html