Google Play’s ‘Ghost Casinos’ - How Early Access Became a Gambling Acquisition Loophole

Published on September 17, 2026 at 4:11 PM

On 10 September 2026, Bitdefender published research into something considerably more interesting than a handful of suspicious casino apps appearing on Google Play.

According to the cybersecurity company’s Android telemetry, thousands of Early Access applications showed potentially deceptive characteristics. They included fake casino and reward games, “earn money” apps, slot-style games, applications masquerading as PDF readers and QR scanners, and apps imitating well-known brands.

But one detail in particular caught my attention.

The same, or almost identical, applications appear under different names and different developer accounts.

Bitdefender found, for example, virtually identical PDF and QR applications being distributed by different developers.

That begins to look less like the work of an isolated rogue developer and more like something that can be replicated and scaled.

And from an iGaming perspective, this is where things become particularly interesting.

The ‘Ghost Casino’ Model

Think of it as an Early Access ghost casino.

The user does not necessarily encounter anything saying:

“This is a real-money online casino.”

Instead, the application might appear to be a casual slots game, puzzle game, Chicken Road-style game or rewards app.

The acquisition funnel can begin somewhere entirely different, such as social media advertising promoting free spins, rewards or casino-style gameplay. Bitdefender also documented advertisements using AI-generated celebrity content.

The journey might look something like this:

250 free spins → AI celebrity advert → Google Play → Early Access app

In some cases investigated by Bitdefender, advertisements led to Early Access applications. In others, they led directly to gambling websites.

That distinction matters because an actual real-money gambling application on Google Play is subject to an entirely different set of rules.

Google requires developers distributing eligible gambling apps to complete its gambling application process. They must hold appropriate gambling licences for the jurisdictions in which the application is distributed, prevent access from territories not covered by those licences, restrict under-age users, use the appropriate Adult Only rating and clearly provide responsible gambling information.

Google also states that real-money gambling apps must be published through the production track rather than a test track so that they can be reviewed appropriately.

A ghost casino, however, may not initially look like a gambling application.

And that is the interesting part.

Sometimes the Casino May Not Even Be the Product

Not every suspicious casino-style application necessarily needs to lead to an actual casino.

Bitdefender describes another model in which users install an app and quickly accumulate apparently valuable virtual rewards.

The experience can look something like this:

Install → play → accumulate virtual “money” → approach the withdrawal threshold → progress slows dramatically → withdrawal never materialises → continue seeing advertisements

In that scenario, the player believes the objective is to earn money.

The actual monetisation model may instead be to keep the user inside the application for as long as possible, consuming advertising.

This also demonstrates why conventional malware detection alone cannot solve the problem.

An application does not need to steal passwords, deploy ransomware or install a Trojan to be deceptive or harmful.

Sometimes the business model itself is the problem.

The Early Access Blind Spot

There is another structural characteristic of Early Access that makes this particularly interesting.

Early Access users can provide feedback to developers, but that feedback is not necessarily equivalent to the public review history consumers normally use when deciding whether to trust an established Play Store application.

That distinction becomes important when the product itself may be questionable.

In an ordinary app environment, imagine users repeatedly reporting:

“SCAM! DOESN’T PAY!”

A one-star rating and a wall of similar reviews quickly become part of the next potential user's decision.

With private testing-style feedback, the dynamic is very different:

User reports problem → developer receives feedback → other potential users may never see the warning.

Bitdefender reports that some suspicious applications appeared to remain in Early Access for extended periods while accumulating significant numbers of installations.

In other words, “Early Access” does not necessarily mean a tiny beta involving a few hundred enthusiasts.

It can potentially operate at considerable scale.

More Than One Million Downloads

One example reported in coverage of Bitdefender's research is Vice Streets: Open World, associated with the package:

com.gamblechaos.withfriends.game

The application reportedly exceeded one million downloads while being distributed through Early Access.

That puts the scale into perspective.

We are no longer talking about an obscure test application discovered by a few hundred people.

We are potentially talking about:

1,000,000+ installations without the normal public review history users might expect from an application operating at that scale.

Google Already Recognises the App-to-Gambling Problem

There is another detail in Google's gambling rules that I find particularly relevant.

Google explicitly states that an existing application cannot simply be repurposed into a real-money gambling application.

If an app was previously published with a rating below Adult Only and is subsequently changed to include real-money gambling functionality, Google requires the gambling product to be uploaded as a new application with a new package name.

The reasoning makes sense.

Existing users can reinstall apps and receive updates. Allowing an innocuous application to transform into a gambling product would therefore create an obvious route around Google's gambling approval process.

Google has consequently already recognised the risk represented by:

benign app → gambling app

The Early Access issue appears to expose a slightly different potential weakness.

The Regulatory Question Gets Much More Interesting

Now consider this from the perspective of an offshore gambling operator attempting to acquire players in a jurisdiction where its normal casino application would not be permitted.

The operator does not necessarily need to attempt the obvious route:

Offshore casino → Google Play

A theoretical acquisition funnel could instead look like this:

TikTok / Facebook

AI celebrity / Chicken Road / free spins

casual or reward app

Google Play Early Access

landing page / redirect / casino

In that scenario, the Google Play application becomes an acquisition bridge.

To be very clear, Bitdefender's research does not establish that this exact funnel is being operated by any particular offshore casino operator.

I have not found evidence supporting that conclusion.

What Bitdefender has documented, however, is advertising that directed users towards Early Access applications or gambling websites.

And anyone familiar with aggressive gambling acquisition strategies may recognise the broader architecture.

In search, we have seen variations of:

parasite SEO → doorway → redirect → casino

The mobile equivalent could become:

social advert → Early Access app → gambling destination

Different channel. Very familiar logic.

Why This Matters for Gambling Regulation

Google's legitimate gambling ecosystem is intentionally restrictive.

Real-money gambling applications need appropriate licensing, geographical controls, age restrictions and responsible gambling safeguards. Google also prohibits many other applications from facilitating wagering or directing users towards real-money gambling services outside the permitted framework.

That creates an obvious incentive for operators or affiliates who cannot satisfy those requirements to find another route to the consumer.

The important question therefore isn't merely:

“Are there scam casino apps on Google Play?”

A much more interesting question is:

“Can apparently non-gambling applications become an acquisition layer that sits between advertising platforms and unlicensed gambling operators?”

If the answer eventually proves to be yes at scale, this stops being merely an app-store moderation problem.

It becomes an illegal gambling acquisition and platform governance problem.

Google Is Investigating

There is an important caveat.

At the time of writing, Google has not publicly confirmed Bitdefender's findings as the result of its own investigation, nor has it announced a broad enforcement operation based on the research.

Bitdefender reported its findings to Google, and Google said it was investigating the issue.

I have not yet found a subsequent Google announcement saying that Early Access is being closed, that thousands of developer accounts have been banned, that its gambling policies are being rewritten because of this investigation, or that particular gambling operators have been identified.

So that part of the story remains open.

But Google's existing gambling rules make the issue particularly interesting. Legitimate real-money gambling applications face detailed licensing, geo-gating, age-gating and responsible gambling requirements.

An application that successfully presents itself as an entirely different category of product potentially creates a very different moderation problem.

What I Would Watch Next

The next stage of this story is not simply whether Google removes individual applications.

The really interesting question is what sits behind them.

Do clusters of Early Access apps ultimately connect to the same offshore casino domains?

Do apparently unrelated developer accounts share infrastructure?

Are the same advertising accounts, affiliate networks, tracking parameters, domains or payment providers appearing repeatedly?

Do the applications act as standalone advertising scams, or are some functioning as acquisition funnels for actual gambling operators?

And perhaps most importantly:

Who ultimately receives the player?

If researchers begin connecting these Early Access applications to specific offshore gambling domains, affiliate networks or common developer and advertising infrastructure, this story becomes considerably larger.

Because then we are no longer looking merely at questionable applications exploiting an overlooked corner of Google Play.

We may be looking at another layer of the illegal online gambling acquisition ecosystem.

And that is something worth watching.


Sources

Bitdefender / HotForSecurity — Google Play Early Access investigation (10 September 2026)
Bitdefender's original research into deceptive applications using Google Play's Early Access ecosystem.

Google Play Console Help — Real-Money Gambling, Games and Contests
Google's official policy covering licensing, age restrictions, geo-restrictions, responsible gambling and eligibility requirements for real-money gambling applications.

Google Play Console Help — Common Violations for Gambling Apps
Google's guidance covering test-track restrictions, geo-gating, age verification and its prohibition on repurposing an existing application into a real-money gambling app.

Google Play — Gambling Application Form
Google's application requirements for authorised gambling apps, including package information, licensing and responsible gambling requirements.

The Hacker News — Reporting on the Bitdefender Early Access investigation
Additional reporting on the applications identified by Bitdefender, including examples and reported installation figures.

Add comment

Comments

There are no comments yet.