CallPhantom is a fraudulent Android app campaign tracked by ESET that consisted of 28 Google Play applications falsely claiming they could retrieve call logs, SMS records, and WhatsApp call history for any phone number. The apps were downloaded more than 7.3 million times before Google removed them after ESET reported the campaign on 2025-12-16. The operation primarily targeted Android users in India and the broader Asia-Pacific region, reflected by preselected +91 country codes and support for UPI payments. The apps did not contain functionality capable of accessing real communications data and generally did not request the sensitive permissions that would be required to do so. Instead, they generated fabricated results using hardcoded names, country codes, templates, timestamps, call durations, and in some cases randomly generated phone numbers; another cluster asked for an email address and claimed results would be delivered after payment, but no real data was sent. Monetization methods included Google Play billing, third-party UPI payment flows, and embedded in-app card checkout forms; some payment URLs were hardcoded or fetched dynamically from Firebase Realtime Database, allowing operators to change payout accounts. In at least one case, an app used deceptive fake email-style notifications to pressure users into subscribing by claiming results had arrived and redirecting them to a payment screen. ESET associated the campaign with Firebase Cloud Messaging for command-and-control communication and published indicators including Firebase Realtime Database domains call-history-7cda4-default-rtdb.firebaseio.com, call-history-ecc1e-default-rtdb.firebaseio.com, ch-ap-4-default-rtdb.firebaseio.com, and chh1-ac0a3-default-rtdb.firebaseio.com, as well as sample hashes such as 799BB5127CA54239D3D4A14367DB3B712012CF14, 56A4FD71D1E4BBA2C5C240BE0D794DCFF709D9EB, and EC5E470753E76614CD28ECF6A3591F08770B7215.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fraudulent Android app campaign on Google Play that faked call-history lookup results, tricked users into paying subscriptions or fees for fabricated data, and used Google Play billing, third-party UPI payments, or embedded card forms to monetize the scam. The apps had no real capability to access call logs, SMS records, or WhatsApp data.
A cluster of fraudulent Android apps distributed via Google Play that falsely claimed to provide call histories, SMS records, and WhatsApp call logs for arbitrary phone numbers. After payment, the apps returned randomly generated fake data rather than real communications records. The campaign also used Firebase Cloud Messaging for command-and-control communication.
A cluster of fraudulent Android apps on Google Play that pretends to retrieve call histories, SMS records, and WhatsApp call logs for arbitrary phone numbers. The apps instead generate fabricated data or promise email delivery after payment, using subscriptions, UPI payments, or direct card entry to monetize the scam.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.