Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
Cybersecurity researchers from ESET have uncovered a sophisticated fraud scheme involving 28 malicious Android applications on the Google Play Store, collectively downloaded over 7.3 million times. Codenamed CallPhantom, these apps falsely promised users access to call histories, SMS records, and WhatsApp logs for any phone number. Instead of delivering real data, the apps provided randomly generated information after tricking users into paying for subscriptions ranging from $6 to $80. The campaign primarily targeted users in India and the Asia-Pacific region, with activity detected since at least November 2025. Some apps used deceptive tactics, such as mimicking government developer names like Indian gov.in or sending fake notifications to prompt payments. Payments were processed through Google Play billing, third-party UPI services like Google Pay and PhonePe, or direct card forms, violating Google's policies. Although Google has removed the offending applications, victims may still face financial losses if subscriptions are not canceled. This incident highlights significant security vulnerabilities within official app marketplaces and the ongoing threat of social engineering attacks targeting mobile users in specific geographic regions.
Wire timeline
Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads
Cybersecurity researchers from ESET have uncovered a sophisticated fraud scheme involving 28 malicious Android applications on the Google Play Store, collectively downloaded over 7.3 million times. Codenamed CallPhantom, these apps falsely promised users access to call histories, SMS records, and WhatsApp logs for any phone number. Instead of delivering real data, the apps provided randomly generated information after tricking users into paying for subscriptions ranging from $6 to $80. The campaign primarily targeted users in India and the Asia-Pacific region, with activity detected since at least November 2025. Some apps used deceptive tactics, such as mimicking government developer names like Indian gov.in or sending fake notifications to prompt payments. Payments were processed through Google Play billing, third-party UPI services like Google Pay and PhonePe, or direct card forms, violating Google's policies. Although Google has removed the offending applications, victims may still face financial losses if subscriptions are not canceled. This incident highlights significant security vulnerabilities within official app marketplaces and the ongoing threat of social engineering attacks targeting mobile users in specific geographic regions.
The Hacker News