# 7.3 Million Android Users Duped by Fraudulent Call History Apps on Google Play Store


ESET uncovers CallPhantom: A sprawling scam campaign impersonating government agencies to steal subscription payments across Asia-Pacific


Cybersecurity researchers have uncovered a massive fraud operation targeting Android users across India and the Asia-Pacific region, where 28 deceptive applications on Google's official Play Store promised users access to private call histories, SMS records, and WhatsApp logs—only to harvest subscription payments in exchange for completely fabricated data.


The campaign, codenamed CallPhantom by Slovakian security firm ESET, accumulated over 7.3 million downloads before removal from the Play Store, with the single most popular variant exceeding 3 million installations. The fraudulent apps exploited a fundamental human vulnerability: the desire to access private communications data for any phone number, a capability that does not exist through legitimate channels.


## The Threat: How the Scam Operated


The CallPhantom apps presented themselves as legitimate utilities offering unprecedented access to telecommunications data. Users downloading these applications encountered interfaces remarkably similar to legitimate productivity apps, with icons and descriptions that suggested functionality related to call logging, contact management, and phone history retrieval.


The deception operated in two distinct variants:


  • Payment-First Model: Apps presented users with a straightforward proposition: pay a subscription fee to unlock access to call histories for any phone number. Upon payment through Google Play's billing system, users received randomly generated phone numbers and names that were hardcoded directly into the application's source code—fabricated data with no relationship to the target phone number.

  • Email-Collection Model: A second cluster of apps employed a more cautious approach, first requesting users' email addresses with promises that detailed call and SMS history would be delivered upon payment. The outcome remained identical: users received entirely fictional data after paying subscription fees.

  • The payment mechanisms deliberately exploited Google Play's billing infrastructure, making recoveries difficult for victims after discovering the fraud. According to ESET researcher Lukáš Štefanko, the activity operated continuously since at least November 2025, suggesting a sustained, organized criminal operation rather than isolated malware incidents.


    ## Background and Context: Geographic Targeting and Impersonation Tactics


    The CallPhantom campaign showed clear operational sophistication in targeting selection and psychological manipulation. The primary victims were Android users in India and broader Asia-Pacific markets, suggesting the operators understood regional demographics most likely to engage with these services—regions where curiosity about surveillance capabilities remains high and app store literacy regarding security risks remains developing.


    Most insidious was the explicit impersonation of government authority. At least one prominent variant was published under the developer name "Indian gov.in"—a brazen attempt to create official legitimacy that would bypass users' normal skepticism. This tactic represents a significant evolution in social engineering: rather than relying solely on authentic-looking interface design, the operators directly falsified publisher identity to create institutional trust.


    Complete list of identified malicious applications:


    | App Name | Package Name |

    |----------|--------------|

    | Call history: any number deta | calldetaila.ndcallhisto.rytogetan.ynumber |

    | Call History of Any Number | com.pixelxinnovation.manager |

    | Call Details of Any Number | com.app.call.detail.history |

    | Call History Any Number Detail | sc.call.ofany.mobiledetail |

    | Call History Any Number Detail | com.cddhaduk.callerid.block.contact |

    | Call History Of Any Number | com.basehistory.historydownloading |

    | Call History of Any Numbers | com.call.of.any.number |

    | Call History Of Any Number | com.rajni.callhistory |

    | Call History Any Number Detail | com.callhistory.calldetails.callerids.callerhistory.callhostoryanynumber.getcall.history.callhistorymanager |

    | Call History Any Number Detail | com.callinformative.instantcallhistory.callhistorybluethem.callinfo |

    | Phone Call History Tracker | com.phone.call.history.tracke |

    | Call History Pro | com.all_historydownload.anynumber.callhistorybackup |


    The remaining 16 identified variants followed similar naming patterns and package structures, suggesting either a single organized group managing multiple accounts or coordinated operations between affiliated threat actors.


    ## Technical Details: Exploitation and Data Fabrication


    From a technical perspective, CallPhantom represents a relatively unsophisticated but devastatingly effective scheme. The apps contained no actual data-retrieval capabilities, no integration with telecommunications infrastructure, and no legitimate access to private communications. Instead, randomly generated phone numbers and contact names were embedded directly into the application's source code—meaning every user received identical fictional data regardless of which number they queried.


    This approach required minimal technical infrastructure: no backend servers processing requests, no exploited vulnerabilities in carrier systems, no sophisticated API integration. The entire operation leveraged:


  • Google Play Store legitimacy as the primary social engineering vector
  • Google Play Billing as the payment processor, creating a perceived safety guarantee that encouraged payment
  • Fabricated source code data requiring only basic app development skills
  • Psychological manipulation through government impersonation and authority appeal

  • Payment collection occurred through multiple mechanisms, though details remain limited. Evidence suggests reliance on Google Play's own billing system as the primary payment vector, which ironically created a false sense of legitimacy—users perceived payment through Google's platform as inherently safer than alternative payment methods.


    ## Implications: Trust Erosion and Vulnerable Populations


    The discovery of CallPhantom raises significant questions about Google's Play Store vetting processes, particularly for markets in the Asia-Pacific region. The simultaneous presence of 28 related fraudulent applications, maintained across multiple developer accounts, suggests inadequate review mechanisms or enforcement lag times between initial compromise and removal.


    The impact extends beyond financial losses:


  • Consumer Trust: Users who believed they were accessing official app ecosystems have experienced direct betrayal, with lasting effects on digital literacy and skepticism
  • Targeted Demographics: The regional focus on India and Asia-Pacific specifically highlights how emerging market users face disproportionate exposure to sophisticated fraud operations
  • Verification Gaps: The successful impersonation of government entities (Indian gov.in) reveals how app store identity verification remains inadequate—government entities lack effective mechanisms to prevent credential spoofing
  • Subscription Abuse: The systematic exploitation of subscription billing models demonstrates how recurring revenue mechanisms can become attack vectors when controls are insufficient

  • The 7.3 million download figure, while partially reflecting installation of legitimate updates before removal, still represents millions of potential victims exposed to subscription fraud. Given average subscription pricing of approximately $10-15 monthly in India and Asia-Pacific markets, the estimated financial impact exceeds tens of millions of dollars across the campaign lifetime.


    ## Recommendations: Defense, Detection, and Platform Accountability


    For Individual Users:


  • Verify app legitimacy through official government channels before trusting apps claiming government affiliation—no legitimate government agency publishes authentication apps on Play Store
  • Check developer credentials carefully, including publication history and user reviews mentioning specific results
  • Reject impossible promises: No legitimate app provides private call histories for arbitrary phone numbers—this capability does not exist
  • Monitor subscriptions regularly through Google Play account settings and immediately dispute fraudulent charges

  • For Organizations and Platform Providers:


  • Implement identity verification for developer accounts claiming government or institutional affiliation—require documented registration verification
  • Establish behavioral detection flagging apps with impossible functionality claims (accessing private telecommunications data without explicit user consent)
  • Create rapid response workflows for coordinated malicious app campaigns, removing related variants simultaneously rather than individually
  • Publish transparency reports detailing fraudulent app removal by region and type, enabling security researchers to identify emerging patterns

  • For Telecommunications Regulators:


  • Establish coordination with app store operators regarding fraudulent apps impersonating regulatory authority
  • Issue public warnings to populations in targeted regions about impossible surveillance claims
  • Develop educational campaigns explaining that private call histories for unknown numbers cannot be legitimately accessed

  • ## HackWire Analysis


    CallPhantom exposes a structural weakness in how app stores handle coordinated fraud: the assumption that individual app review catches organized campaigns is demonstrably false. Twenty-eight variants operating simultaneously across months suggests either ESET's detection happened after widespread removal had already begun, or Google's internal systems flagged these much earlier than the public disclosure timeline indicates.


    The targeting of India and Asia-Pacific markets carries particular significance. This region represents explosive growth in Android adoption, with users increasingly accustomed to trusting the Play Store as a safety-verified ecosystem—precisely the conditions that maximize fraud efficacy. The impersonation of "Indian gov.in" represents a qualitative escalation: instead of mimicking legitimate companies, operators are directly spoofing government institutions, betting that social hierarchies and institutional trust in South Asia create powerful psychological compliance.


    What distinguishes CallPhantom from typical subscription fraud is the *scale of distribution before detection*. 7.3 million downloads is not a marginal scam; it's a sustained, successful operation that generated extraordinary returns for minimal technical effort. This demonstrates that fraud doesn't require technical sophistication when social engineering and platform trust suffice.


    The real takeaway for defenders: app store fraud will continue accelerating as long as removal happens independently rather than systematically. Google needs coordinated takedowns of entire campaigns, not individual apps. App store identity verification needs to actually verify identity, not simply review applications. And users in emerging markets need explicit education that certain capabilities—accessing anyone's private call history—are technically impossible, regardless of what any application claims.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)