Skip to content

ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money

  • A new Android scam, CallPhantom, falsely claims to provide access to call logs, SMS records, and WhatsApp call history for any phone number in exchange for payment.
  • We identified and reported 28 separate CallPhantom apps on Google Play, cumulatively downloaded more than 7.3 million times.
  • Some CallPhantom apps sidestep Google Play’s official billing system, complicating victims’ refund efforts.

BRATISLAVA, KOŠICEMay 7, 2026 — ESET researchers have uncovered fraudulent apps on Google Play that claim to provide the call history “for any number.” The offending apps, which ESET named CallPhantom based on their false claims, purport to provide access to call histories, SMS records, and even WhatsApp call logs for any phone number. To unlock this supposed feature, users are asked to pay — but all they get in return is randomly generated data. ESET’s investigation identified 28 such fraudulent apps, cumulatively downloaded more than 7.3 million times. As an App Defense Alliance partner, we reported our findings to Google, which removed all of the apps identified in this report from Google Play. 

The CallPhantom apps mainly targeted Android users in India and the broader Asia Pacific region. Many of the apps came with India’s +91 country code preselected, and support UPI, a payment system used primarily in India.

“In November 2025, we came across a Reddit post discussing an app named Call History of Any Number, found on Google Play. Unsurprisingly, our analysis showed that the ‘call history’ data provided by this app is entirely fabricated — the app generates random phone numbers and matches them with fixed names, call times, and call durations, which were embedded directly in the code,” says ESET researcher Lukáš Štefanko, who uncovered the CallPhantom fraud.

In general, CallPhantom apps have a simple user interface and do not request any intrusive or sensitive permissions — they don’t need to. Coincidentally, they do not contain any functionality capable of retrieving actual call, SMS, or WhatsApp data.
In the CallPhantom apps ESET analyzed, researchers saw three different payment methods used, two of which are in violation of Google Play’s payments policy. Some of the apps relied on subscriptions via Google Play’s official billing system. Others relied on payments via a third party; in some cases, payment card checkout forms were included directly in the CallPhantom apps.

The fees requested for the fake service differ widely across the apps. The apps also appear to offer different subscription packages, such as weekly, monthly, or yearly services, with the highest requested price sitting at US$80. For the lowest “subscription tier,” the average requested price was €5.

In general, subscriptions purchased through the official Google Play billing system can be canceled. For the 28 apps described in this blog post, existing subscriptions were canceled when the apps were removed from Google Play. In some cases, refunds for Google Play purchases are possible.

If the purchase was made outside of Google Play — for example, by entering payment card details inside the app or by paying via third-party services — then Google cannot cancel the subscription or issue a refund, and users have to contact their payment provider.

For a more details about CallPhantom, check out the latest ESET Research blog post, “Fake call logs, real payments: How CallPhantom tricks Android users,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Examples of CallPhantom apps found on Google Play

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

簡化監控架構 | 戰略指南

Windows monitoring with Sysmon requires custom XML configuration for effective security logging. Integrating Sysmon with a SIEM like Pandora SIEM enhances centralized analysis, threat detection, and correlation for robust security management and operational efficiency.

Continue reading

Saily 評測:全球 eSIM 連線的未來

在國際旅行中管理行動數據,傳統上只能在昂貴的漫遊費或繁瑣的當地 SIM 卡之間做選擇。由 Nord Security 推出的新一代 eSIM 方案 Saily 提供了第三條路:負擔得起、安全且即時的數位連線。

 

為什麼 Saily 脫穎而出

  • 全球覆蓋: 在超過 200 個目的地存取高速數據。
  • 安全優先: 內建網頁保護與廣告攔截,守護流量與隱私。
  • 以使用者為中心的方案: 提供從 1GB 入門到完整無限層級的彈性選擇。

Saily Ultra:全方位訂閱服務

針對頻繁出國的旅人,Saily Ultra (每月 29.99 美元) 捆綁了 30GB 數據以及高級旅遊禮遇,例如機場貴賓室使用權,以及完整的 Nord Security Suite(包含 VPN、密碼管理、加密雲端與資安防護)。

 

快速總結

項目詳情
平台支援iOS, Android, 24/7 線上客服
入門價格國家方案 2.99 美元起
特色功能積分與推薦制度、自動儲值、企業管理後台
最終評分4.6 / 5

2026 年 MSP 頂尖 8 大 ITDR 工具

戰略洞察: 基於憑證的攻擊不會留下惡意軟體足跡。若沒有 ITDR,入侵行為往往直到數據外洩或匯款詐騙發生後才會被發現。
 

頂尖 ITDR 平台

1. Guardz

最適合: 尋求統一、MSP 優先偵測與回應的業者。內建 MDR 支援以及 M365 和 Google Workspace 的多租戶管理。

2. Microsoft Defender for Identity

最適合: 標準化採用 Microsoft E5 堆疊與 Entra ID 生態系統的組織。

3. CrowdStrike Falcon Identity Protection

最適合: 透過單一統一代理程式緊密結合端點與身分遙測的環境。

解決方案比較

工具MSP 優勢自動化回應
Guardz原生多租戶 / 統一 MDR停用使用者 / 隔離設備
SentinelOne態勢評估 / 欺敵技術停用帳號 / 重置密碼
Okta ITDR持續性會話監控全球登出 (Universal Logout)
IBM Verify治理與合規性自適應存取控制

 

營運檢查清單

  • 優先選擇 原生多租戶 主控台,而非逐一登入客戶帳戶。
  • 確保能原生覆蓋 M365 收件匣規則OAuth 授權 監控。
  • 驗證自動化動作的 可逆性(例如:停用帳號後的快速恢復)。

關於 Guardz

Guardz 為管理服務提供商 (MSP) 和 IT 專業人士提供一個人工智能驅動的網絡安全平台,專門設計來保護小型企業免受網絡攻擊。我們的統一檢測與響應平台能夠全面保護用戶、電子郵件、設備、雲端目錄和數據。透過簡化網絡安全管理,我們讓企業能夠專注於發展業務,同時減少安全管理的複雜性。Guardz 結合強大的網絡安全技術和豐富的專業知識,確保安全措施持續受到監控、管理和改進,預防未來的攻擊並降低風險。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

Keepit for monday.com | 數據韌性指南

雖然 monday.com 對於日常營運至關重要,但若僅依賴其原生的「資源回收筒」來進行數據治理,將面臨巨大的風險。在勒索軟體橫行與意外刪除頻發的世界中,真正的業務連續性需要一套獨立的還原策略。

責任共擔模型: monday.com 確保平台可用;而負責確保其中的數據免於丟失、失竊或損壞。
自動化每日備份
無需手動干預,每日自動產生存放項目、看板與欄位的快照。
時間點還原
將特定的看板或項目恢復至歷史上任何時間點的精確狀態。
勒索軟體防護
不可竄改且實體隔離的儲存機制,確保備份不受惡意威脅影響。
統一 SaaS 安全性
單一平台即可保護您的所有工具:Jira、Confluence、Miro 與 monday.com。
 

確保營運連續性,萬無一失

不應讓誤點滑鼠或內部惡意行為導致數月的專案數據丟失,成為創意與技術團隊的風險因素。Keepit 確保您的組織知識資產始終可用、符合合規性且安全無虞——無論生產環境發生什麼狀況。

關於 Keepit

Keepit 立足於為雲端時代提供新世代的 SaaS 資料保護。其核心理念是透過獨立於應用程式供應商的雲端儲存,為企業關鍵應用加上一道安全鎖,不僅強化網路韌性,更實現前瞻性的資料保護策略。其獨特、分隔且不可變的資料儲存設計,不涉及任何次級處理器,確保符合各地法規,有效抵禦勒索軟體等威脅,並保證關鍵資料隨時可存取、業務不中斷,以及快速高效的災難復原能力。總部位於丹麥哥本哈根的 Keepit,其辦公室與資料中心遍及全球,已贏得超過 15,000 家企業的深度信賴,客戶普遍讚譽其平台的直覺易用性,以及輕鬆、可靠的雲端資料備份與復原體驗。

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

×

Hello!

Click one of our contacts below to chat on WhatsApp

×