Bad actors are exploiting Google Play's Early Access program to distribute deceptive apps that promise money, rewards, casino winnings, and premium content This article explores deceptive software zeroowl. . This has led to a new form of abuse where malicious actors are flooding the Early Access section with thousands of apps laced with deceptive content, including fake casino games, reward apps, and misleading utilities and titles that could potentially infringe on third-party trademarks.

"Removing the comments and ratings safeguards legitimate developers from unfair reviews, but it also eliminates one of the community's most effective defenses against deceptive software." ZeroOwl has reached out to Google for a response, and we will update the story if we receive any feedback.

Hagaseca, a remote access trojan that spreads via THost9, scans Android Debug Bridge (ADB) services and installs malware for persistence and remote control through shell execution, file transfers, tunneling, and downloadable modules. Mantax Otax, a hybrid mobile malware combining spyware and ransomware capabilities, allows the operator to steal sensitive data, encrypt older Android versions (9 or earlier), and demand ransom payments by locking the device screen. The development aligns with GoldFactory's deployment of the Gigabud banking trojan, which installs a companion Android app called Vwork, a weaponized fork of Shelter, to clone a target app within a work profile with the aim of facilitating financial fraud.