logo

Fake call logs, real payments: How CallPhantom tricks Android users

ID: ae67a787-493a-5d0e-a5af-cb7422a62642

STIX ID: report--ae67a787-493a-5d0e-a5af-cb7422a62642

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
55/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

...
...

ESET Research uncovered CallPhantom, a cluster of 28 fraudulent Android apps on Google Play that generated and sold fake call/SMS/WhatsApp logs to users (collectively downloaded >7.3M times); the apps used a mix of Google Play billing, third‑party UPI links, and in‑app card entry to collect payments (complicating refunds), relied on hardcoded/generated fake data rather than accessing real communications, and employed Firebase-hosted endpoints for dynamic behavior and C2; all identified apps were reported and removed, and the report includes IoCs (file hashes, package names, Firebase domains/IPs) and remediation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.