Google Play 'Early Access' Abuse and Mantax Otax Android Ransomware: Key Developments
Bitdefender found thousands of deceptive Google Play Early Access apps — which cannot receive public reviews or ratings — promoted with AI celebrity deepfake ads on TikTok and Facebook, including a GTA imitator that topped 1,000,000 downloads before…
Bitdefender research, reported on 2026-09-10 by SecurityWeek and The Hacker News and expanded on 2026-09-11 by CSO Online, documents widespread abuse of Google Play's Early Access program, in which published apps cannot receive public reviews or ratings — removing a key trust signal users normally rely on — allowing developers to push thousands of deceptive casino, reward, and utility apps. The apps are promoted through TikTok and Facebook ads using AI/deepfake celebrity videos promising cash rewards, PayPal payouts, crypto earnings, gift cards, and offers such as 250 free spins, but users receive only aggressive, endless advertising and the promised payouts never arrive; SecurityWeek notes no malware is delivered and some listings show thousands of installs, while CSO Online separately describes ad-fraud-capable utilities requesting excessive permissions. The Hacker News reports the GTA imitator 'Vice Streets: Open World' surpassed 1,000,000 downloads before disappearing from the Play Store. Named examples include the casino-style games 'Chicken Road' and 'Ice Fishing' and trademark abuse with apps named 'Grand Theft Auto V (Early Access)' that were later renamed; casino-style apps also sidestep gambling licensing, geofencing, and age-verification requirements. CSO Online adds that some Early Access apps requested unusual permissions — e.g., a QR scanner seeking to replace the device launcher — potentially enabling hidden web views that click ads, display fake login screens, or capture two-factor codes; Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization. The Hacker News also notes its report coincides with disclosures on Android malware families Hagaseca, Mantax Otax, StreamRat, and GoldFactory's Gigabud banking trojan with its Vwork companion app used for cloned-app financial fraud. Separately, Zimperium researchers (GBHackers attributes the analysis to zLabs and Zimperium) describe Mantax Otax — sources use 'Mantax Otax' and 'Mantax OTAX' for the same family — Android malware combining ransomware, spyware, and harassment, distributed via malicious sideloaded APKs hosted outside Google Play on third-party file-sharing services through phishing, social engineering, and messaging lures; BleepingComputer reports it targets Indonesian users, while GBHackers and Cyber Security News link it to Indonesian threat actors. The malware abuses device-administrator and…
- Bitdefender identified thousands of deceptive Google Play Early Access apps, which cannot receive public reviews or ratings, promoted via TikTok and Facebook ads using AI/deepfake celebrity videos (SecurityWeek and The Hacker News,…
- Deepfake ads promised cash rewards, PayPal payouts, crypto earnings, gift cards, and 250 free spins; users received only aggressive advertising and the promised payouts never arrive (SecurityWeek, The Hacker News).
- SecurityWeek reports no malware is delivered by the Early Access apps, though some listings show thousands of installs; CSO Online separately describes ad-fraud-capable utilities requesting excessive permissions.
- The GTA imitator 'Vice Streets: Open World' surpassed 1,000,000 downloads before disappearing from the Play Store (The Hacker News).
- Named examples include casino-style games 'Chicken Road' and 'Ice Fishing', and trademark abuse with apps named 'Grand Theft Auto V (Early Access)' later renamed (SecurityWeek).
- Casino-style Early Access apps sidestep gambling licensing, geofencing, and age-verification requirements (The Hacker News).
- A QR scanner app requested rights to replace the device launcher, which could enable hidden web views that click ads, display fake login screens, or capture two-factor codes; Bitdefender recommends Android Enterprise Work Profiles, and…
- The Hacker News notes its report coincided with disclosures on the Hagaseca, StreamRat, and GoldFactory Gigabud banking trojan (with Vwork companion app for cloned-app financial fraud) Android malware families.
Coverage timelineoldest first · each row is one article
- · 5d agoDeceptive Android Apps Exploit Google Play Early Access to Evade Reviews
SecurityWeek· 42
Bitdefender reports deceptive Google Play Early Access apps use deepfake celebrity ads and fake rewards to lure users into ad-fraud schemes.
- · 5d agoGoogle Play Early Access Abused to Push Thousands of Deceptive Android Apps
The Hacker News· 50
Bitdefender found abuse of Google Play's review-free Early Access program to push thousands of deceptive casino and reward apps promoted with AI deepfake ads.
- · 5d agoNew Android malware encrypts files, steals data, and harasses victims
BleepingComputer· 48
Zimperium details Mantax Otax, an Android malware combining ransomware, spyware, and harassment, spread via phishing APKs to Indonesian users.
- · 4d agoMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers· 46
New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.
- · 4d agoGoogle’s Early Access is creating a blind spot for malicious apps
CSO Online· 45
Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.
- · 4d agoNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News· 45
Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.