ESET uncovered a large Android fraud campaign, tracked as CallPhantom, that used 28 apps on Google Play to falsely promise access to call histories, SMS records, and WhatsApp call logs for arbitrary phone numbers. The apps were downloaded more than 7.3 million times, primarily by users in India and the wider Asia-Pacific region, before Google removed them after disclosure in December 2025. Instead of providing real communications data, the apps generated fabricated records from hardcoded values and displayed deceptive previews to convince users the service worked.
The operation monetized victims through multiple payment channels, including Google Play billing, third-party UPI payment flows, and embedded card-entry forms, with the latter methods violating Google Play policy and making refunds harder to obtain. Researchers said some apps also used fake notifications to drive users back into subscription prompts, while backend infrastructure relied on Firebase Cloud Messaging for command-and-control and Firebase databases to manage some payment details. Published reporting also included indicators of compromise such as app SHA-1 hashes, Firebase domains, and related IP addresses tied to the campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public reporting detailed the CallPhantom Android fraud operation, explaining that the apps generated fake records from hardcoded values and used deceptive notifications and payment prompts to pressure victims into paying. The disclosures also described the campaign's payment methods, Firebase-based infrastructure, and published indicators of compromise.
After ESET's disclosure, Google removed the 28 malicious or fraudulent apps from Google Play. Before removal, the apps had amassed more than 7.3 million downloads, primarily affecting users in India and the wider Asia-Pacific region.
ESET reported a fraud campaign involving 28 Android apps on Google Play to Google. The apps falsely claimed they could provide call records, SMS histories, and WhatsApp call logs for arbitrary phone numbers.
ESET assessed that the CallPhantom Android fraud operation was active since at least November 2025. The campaign used fake call-history and messaging-record apps on Google Play to trick users into payments for fabricated data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.