Scam Android Apps on Google Play Garnered Millions of Downloads with Deceptive Pitch
Researchers from ESET uncovered a significant scam involving 28 fraudulent Android applications on the Google Play Store, collectively known as CallPhantom. These apps promised users unauthorized access to private call logs, SMS records, and WhatsApp history for any phone number. Despite the technically impossible nature of these claims, the apps accumulated over 7.3 million combined downloads before being removed. The scheme operated by prompting users to enter a target phone number and pay a fee to unlock the alleged data. Instead of real information, users received fake data generated from hardcoded lists or random numbers. Some variants also employed deceptive tactics, such as fake email alerts, to trap users into subscription cycles. While some transactions used Google Play's official billing system, others directed users to third-party payment methods, complicating refund processes. Google removed all identified apps after ESET reported them in December. This incident highlights persistent security challenges within official app stores, demonstrating how social engineering and dubious promises can exploit user curiosity and malicious intent, leading to widespread financial loss despite platform safety measures.
Wire timeline
Scam Android Apps on Google Play Garnered Millions of Downloads with Deceptive Pitch
Researchers from ESET uncovered a significant scam involving 28 fraudulent Android applications on the Google Play Store, collectively known as CallPhantom. These apps promised users unauthorized access to private call logs, SMS records, and WhatsApp history for any phone number. Despite the technically impossible nature of these claims, the apps accumulated over 7.3 million combined downloads before being removed. The scheme operated by prompting users to enter a target phone number and pay a fee to unlock the alleged data. Instead of real information, users received fake data generated from hardcoded lists or random numbers. Some variants also employed deceptive tactics, such as fake email alerts, to trap users into subscription cycles. While some transactions used Google Play's official billing system, others directed users to third-party payment methods, complicating refund processes. Google removed all identified apps after ESET reported them in December. This incident highlights persistent security challenges within official app stores, demonstrating how social engineering and dubious promises can exploit user curiosity and malicious intent, leading to widespread financial loss despite platform safety measures.
Android Authority