# 7.3 Million Android Users Duped by Fraudulent Call History Apps on Google Play Store
ESET uncovers CallPhantom: A sprawling scam campaign impersonating government agencies to steal subscription payments across Asia-Pacific
Cybersecurity researchers have uncovered a massive fraud operation targeting Android users across India and the Asia-Pacific region, where 28 deceptive applications on Google's official Play Store promised users access to private call histories, SMS records, and WhatsApp logs—only to harvest subscription payments in exchange for completely fabricated data.
The campaign, codenamed CallPhantom by Slovakian security firm ESET, accumulated over 7.3 million downloads before removal from the Play Store, with the single most popular variant exceeding 3 million installations. The fraudulent apps exploited a fundamental human vulnerability: the desire to access private communications data for any phone number, a capability that does not exist through legitimate channels.
## The Threat: How the Scam Operated
The CallPhantom apps presented themselves as legitimate utilities offering unprecedented access to telecommunications data. Users downloading these applications encountered interfaces remarkably similar to legitimate productivity apps, with icons and descriptions that suggested functionality related to call logging, contact management, and phone history retrieval.
The deception operated in two distinct variants:
The payment mechanisms deliberately exploited Google Play's billing infrastructure, making recoveries difficult for victims after discovering the fraud. According to ESET researcher Lukáš Štefanko, the activity operated continuously since at least November 2025, suggesting a sustained, organized criminal operation rather than isolated malware incidents.
## Background and Context: Geographic Targeting and Impersonation Tactics
The CallPhantom campaign showed clear operational sophistication in targeting selection and psychological manipulation. The primary victims were Android users in India and broader Asia-Pacific markets, suggesting the operators understood regional demographics most likely to engage with these services—regions where curiosity about surveillance capabilities remains high and app store literacy regarding security risks remains developing.
Most insidious was the explicit impersonation of government authority. At least one prominent variant was published under the developer name "Indian gov.in"—a brazen attempt to create official legitimacy that would bypass users' normal skepticism. This tactic represents a significant evolution in social engineering: rather than relying solely on authentic-looking interface design, the operators directly falsified publisher identity to create institutional trust.
Complete list of identified malicious applications:
| App Name | Package Name |
|----------|--------------|
| Call history: any number deta | calldetaila.ndcallhisto.rytogetan.ynumber |
| Call History of Any Number | com.pixelxinnovation.manager |
| Call Details of Any Number | com.app.call.detail.history |
| Call History Any Number Detail | sc.call.ofany.mobiledetail |
| Call History Any Number Detail | com.cddhaduk.callerid.block.contact |
| Call History Of Any Number | com.basehistory.historydownloading |
| Call History of Any Numbers | com.call.of.any.number |
| Call History Of Any Number | com.rajni.callhistory |
| Call History Any Number Detail | com.callhistory.calldetails.callerids.callerhistory.callhostoryanynumber.getcall.history.callhistorymanager |
| Call History Any Number Detail | com.callinformative.instantcallhistory.callhistorybluethem.callinfo |
| Phone Call History Tracker | com.phone.call.history.tracke |
| Call History Pro | com.all_historydownload.anynumber.callhistorybackup |
The remaining 16 identified variants followed similar naming patterns and package structures, suggesting either a single organized group managing multiple accounts or coordinated operations between affiliated threat actors.
## Technical Details: Exploitation and Data Fabrication
From a technical perspective, CallPhantom represents a relatively unsophisticated but devastatingly effective scheme. The apps contained no actual data-retrieval capabilities, no integration with telecommunications infrastructure, and no legitimate access to private communications. Instead, randomly generated phone numbers and contact names were embedded directly into the application's source code—meaning every user received identical fictional data regardless of which number they queried.
This approach required minimal technical infrastructure: no backend servers processing requests, no exploited vulnerabilities in carrier systems, no sophisticated API integration. The entire operation leveraged:
Payment collection occurred through multiple mechanisms, though details remain limited. Evidence suggests reliance on Google Play's own billing system as the primary payment vector, which ironically created a false sense of legitimacy—users perceived payment through Google's platform as inherently safer than alternative payment methods.
## Implications: Trust Erosion and Vulnerable Populations
The discovery of CallPhantom raises significant questions about Google's Play Store vetting processes, particularly for markets in the Asia-Pacific region. The simultaneous presence of 28 related fraudulent applications, maintained across multiple developer accounts, suggests inadequate review mechanisms or enforcement lag times between initial compromise and removal.
The impact extends beyond financial losses:
The 7.3 million download figure, while partially reflecting installation of legitimate updates before removal, still represents millions of potential victims exposed to subscription fraud. Given average subscription pricing of approximately $10-15 monthly in India and Asia-Pacific markets, the estimated financial impact exceeds tens of millions of dollars across the campaign lifetime.
## Recommendations: Defense, Detection, and Platform Accountability
For Individual Users:
For Organizations and Platform Providers:
For Telecommunications Regulators:
## HackWire Analysis
CallPhantom exposes a structural weakness in how app stores handle coordinated fraud: the assumption that individual app review catches organized campaigns is demonstrably false. Twenty-eight variants operating simultaneously across months suggests either ESET's detection happened after widespread removal had already begun, or Google's internal systems flagged these much earlier than the public disclosure timeline indicates.
The targeting of India and Asia-Pacific markets carries particular significance. This region represents explosive growth in Android adoption, with users increasingly accustomed to trusting the Play Store as a safety-verified ecosystem—precisely the conditions that maximize fraud efficacy. The impersonation of "Indian gov.in" represents a qualitative escalation: instead of mimicking legitimate companies, operators are directly spoofing government institutions, betting that social hierarchies and institutional trust in South Asia create powerful psychological compliance.
What distinguishes CallPhantom from typical subscription fraud is the *scale of distribution before detection*. 7.3 million downloads is not a marginal scam; it's a sustained, successful operation that generated extraordinary returns for minimal technical effort. This demonstrates that fraud doesn't require technical sophistication when social engineering and platform trust suffice.
The real takeaway for defenders: app store fraud will continue accelerating as long as removal happens independently rather than systematically. Google needs coordinated takedowns of entire campaigns, not individual apps. App store identity verification needs to actually verify identity, not simply review applications. And users in emerging markets need explicit education that certain capabilities—accessing anyone's private call history—are technically impossible, regardless of what any application claims.
— *HackWire Editorial*
---
## Related Coverage