Sunday, July 19, 2026

Security Researchers Expose CallPhantom Scam: 28 Fraudulent Apps Bilked Users Out of Millions

May 8, 2026

Cybersecurity researchers at ESET have identified a sophisticated fraud scheme operating on Google Play that dupes users into paying for fabricated call histories and SMS records.

The scam centers on a collection of deceptive applications collectively dubbed CallPhantom, which promise users access to call logs, text message records, and WhatsApp communications for any phone number. In reality, the apps generate entirely fictitious data—random phone numbers paired with predetermined names, timestamps, and call durations hardcoded into the application itself.

ESET's investigation uncovered 28 such malicious applications that together accumulated more than 7.3 million downloads before being removed. The research team, working as part of Google's App Defense Alliance, reported their findings to the tech giant, which subsequently took action to eliminate all identified apps from its platform.

The fraudulent apps predominantly affected Android users across India, with the country accounting for 53.7% of all CallPhantom detections globally. The apps were specifically configured for Indian users, featuring the +91 country code pre-selected and accepting UPI payments, India's widely-used digital payment system.

The investigation began in November 2025 when ESET researcher Lukáš Štefanko encountered a discussion on Reddit about an app called Call History of Any Number. Upon examination, the researcher confirmed that the application's entire operation relied on generating fake data rather than accessing genuine telecommunications records. The apps contained no actual functionality to retrieve authentic call logs, messages, or voice call information.

The CallPhantom applications employed a deliberately simple design that avoided requesting invasive permissions from users—primarily because they had no legitimate need to access such data. Instead, the apps focused entirely on monetization through various payment schemes.

The fraudulent applications employed three distinct payment methodologies, with two violating Google Play's official payment policies. Some relied on subscriptions processed through Google's legitimate billing system, while others directed users to enter payment card information directly within the apps or through third-party payment processors.

Pricing structures varied considerably across the different apps. Subscription tiers ranged from weekly to yearly options, with costs spanning from approximately €5 at the lower end to as much as $80 for premium packages.

When Google removed the 28 fraudulent apps, existing subscriptions charged through the official Google Play billing system were automatically canceled. In certain circumstances, users may be eligible for refunds on these purchases. However, users who made payments by entering credit card details within the apps or through external payment services face a more complicated situation—Google cannot reverse these transactions, and affected individuals must contact their payment providers directly to seek restitution.

The discovery underscores the ongoing challenge of maintaining security on major app distribution platforms despite established vetting procedures.

Compare options