logo

PhantomCall Malware Disguised as Fake Chrome Apps Orchestrates Global Banking Fraud

ID: 7ca93bc3-908a-5933-be26-5b4d543f4c8e

STIX ID: report--7ca93bc3-908a-5933-be26-5b4d543f4c8e

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

PhantomCall, a variant of the Antidot Android malware, is being distributed through fake Chrome update droppers across Europe, North America, the Middle East, and Asia; once installed it requests high-risk permissions and abuses Android accessibility and call-screening services, sends USSD codes, and blocks legitimate calls to silently hijack communications and facilitate financial theft, using social engineering and platform-bypass techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.