ESET CallPhantom report exposes fake call log apps

The latest ESET CallPhantom report reveals how a group of fraudulent Android apps managed to attract more than 7.3 million downloads through a surprisingly simple claim. These apps promised users access to call histories, SMS records and even WhatsApp call logs for “any number”. In reality, the apps generated completely fake data while convincing users to pay for access. ESET researchers identified 28 such apps on Google Play before reporting them to Google, which later removed them from the platform.
What makes the CallPhantom app scam stand out is how little technical sophistication was actually involved. The apps did not rely on intrusive permissions or advanced malware behaviour. Instead, they leaned heavily on user curiosity and social engineering. According to ESET researcher Lukáš Štefanko, the apps simply generated random phone numbers and matched them with pre-written names, call durations and timestamps already embedded in the code. The illusion looked convincing enough for millions of users to trust it.
India became the biggest target
The investigation showed that Android users in India formed the biggest share of victims. Many of the apps came with India’s +91 country code already selected and supported UPI payments, making the experience feel local and familiar. ESET found that 53.7% of all detections worldwide were linked to India, showing how strongly the scam was tailored towards Indian users.
The Google Play UPI refund scam angle adds another layer to the issue. Some apps used Google Play’s official billing system, while others pushed users towards third-party payment methods or direct card payment forms inside the apps themselves. That difference matters because subscriptions purchased through Google Play could be cancelled after the apps were removed. Payments made outside Google Play, however, placed the burden directly on users to contact banks or payment providers for refunds.
The bigger problem behind fake utility apps
One of the more interesting findings in the ESET CallPhantom report is how ordinary these apps appeared on the surface. The apps did not aggressively request sensitive permissions because they did not need actual access to user data. Their entire model depended on creating believable fake outputs rather than stealing information directly. That approach may explain why the apps managed to remain active and attract millions of downloads before being removed.
The Android fake call log apps list uncovered by ESET also points to a broader challenge for app marketplaces. Fraudulent apps are increasingly using simple interfaces, local payment methods and emotionally tempting promises instead of traditional malware tactics. In this case, curiosity itself became the attack vector. For Android users, especially younger audiences who regularly explore utility apps online, the case highlights how easily trust can be manipulated through apps that appear harmless at first glance.
Conclusion
The CallPhantom case is less about technical hacking and more about behavioural manipulation. These apps sold an illusion, and millions paid for it. The larger takeaway from the ESET findings is that app fraud is evolving into something quieter, simpler and often harder for everyday users to recognise before it is too late.
Read More:
Elcom Digital Synergy 2026: Aligning the vendor ecosystem for future growth
What MATLAB EXPO 2026 revealed about future engineering
Zoho Cybersecurity Report exposes hidden AI security gaps
UST Taciti acquisition signals a bigger push Into SAP modernisation






