惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
WordPress大学
WordPress大学
N
Netflix TechBlog - Medium
MyScale Blog
MyScale Blog
Stack Overflow Blog
Stack Overflow Blog
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
CallPhantom Android scam reached 7.3 million downloads on...
Anamarija Po · 2026-05-07 · via Help Net Security

Scams targeting Android users in India and across the Asia-Pacific region have grown around a long-standing curiosity gap: the desire to look up call records tied to a phone number. A cluster of 28 fraudulent apps on Google Play exploited that gap and pulled in more than 7.3 million downloads before the store removed them.

ESET researchers, who tracked the campaign and named it CallPhantom, reported the apps to Google on December 16, 2025, and all of them have since been taken down.

Fabricated data sold as real records

The apps advertised access to call histories, SMS records, and WhatsApp call logs for any phone number supplied by the user. Once a victim paid, the apps delivered randomly generated data drawn from hardcoded lists of names, country codes, timestamps, and call durations. None of the apps contained any code capable of retrieving real communications data, and they did not request the sensitive permissions such functionality would require.

ESET first identified the activity in November 2025 after a Reddit post flagged an app called Call History of Any Number, published under the developer name “Indian gov.in.” The app had no connection to the Indian government. Further analysis surfaced 27 additional apps using the same scheme.

Two operating models

Apps in the first cluster generated partial fake results immediately, then asked for payment to reveal the rest. The second cluster collected an email address and promised to deliver the call history after subscription. In one case, the app pushed users who closed it without paying through fake email-style notifications claiming the report was ready. Tapping the alert opened a subscription screen.

Many of the apps preselected the +91 country code and supported UPI, the payment system used widely in India. Negative reviews on the Play Store described the same pattern of users paying and receiving randomized data with no recourse.

CallPhantom Android scam

Various payment options used by CallPhantom apps (Source: ESET)

Payment routes that bypass Google

Three payment methods appeared across the apps. Some used Google Play’s official billing system, which requires apps offering in-app purchases to route through it and which carries Google’s refund coverage. Others routed payments through third-party UPI apps using hardcoded URLs or URLs fetched dynamically from a Firebase realtime database, allowing the operators to swap payout accounts at any time. A third group embedded payment card checkout forms directly in the app interface. The latter two methods violate Google Play’s payments policy.

Subscription pricing varied across the apps. The lowest tier averaged €5, and the highest fee observed was $80, with weekly, monthly, and yearly packages on offer.

Refund prospects

Subscriptions purchased through Google Play billing for the 28 apps were canceled when the apps were removed from the store. Refund eligibility depends on Google’s standard refund window and policies, accessible through the Play Store profile menu under Payments and subscriptions. Purchases made through third-party UPI apps or via card details entered inside a CallPhantom app fall outside Google’s reach. Affected users have to pursue the payment provider or the app developer directly.

ESET, which acts as an App Defense Alliance partner, classifies the apps under the Android/CallPhantom detection family. The campaign also relied on Firebase Cloud Messaging for command-and-control communication, according to the MITRE ATT&CK mapping ESET published alongside the indicators of compromise.

Download: Secure Foundations for AI Workloads on AWS