Fake call logs, real payments: How CallPhantom tricks Android users

LowWeLiveSecurity·

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down…

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

At a glance

Severity
Lowfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
Google, Android
Threat actors & malware
Play
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-05-07 08:51 UTC
Priority
19/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. WeLiveSecurityEstablished SourceFirst reported

    2026-05-07 08:51 UTC

Related stories