Android users looking for a way to view someone else’s call history were pulled into a payment scam hiding in plain sight on Google Play, according to research from ESET.
The company said it found 28 Android apps that claimed they could retrieve call histories, SMS records, or WhatsApp call logs for any phone number. Collectively, the apps had more than 7.3 million downloads before Google removed them from the Play Store after ESET reported the findings.
ESET named the cluster CallPhantom, a fitting label for apps that sold access to records they did not actually have. The pitch was simple: enter a phone number, pay for access, and receive a supposed call history. In practice, ESET said the apps returned fabricated data rather than real records.
That makes the case different from many mobile threats. These apps were not notable because they demanded broad device permissions or installed an obvious banking trojan. The risk was more direct and more commercial: users were persuaded to pay for a service that, based on ESET’s analysis, the apps could not deliver.
What the CallPhantom Apps Promised
The apps leaned into a search-friendly promise: call history for any number. Several names were nearly identical, using small wording changes around phrases such as “Call History Any Number,” “Call Details,” and “Phone Call History Tracker.” That repetition matters. It suggests the operators were not building distinct utilities so much as flooding the marketplace with variations of the same offer.
The claimed feature was also the hook. A normal Android app cannot simply retrieve another person’s private call history, SMS records, or WhatsApp call logs by entering a phone number. That kind of access would require data the app should not have. Yet the apps presented the idea as a consumer tool, often wrapping it in a plain interface that looked less risky than traditional malware.
ESET said the apps primarily targeted Android users in India and the broader Asia-Pacific region. Some apps reportedly preselected India’s +91 country code, and several payment flows were built around methods common in India, including UPI-based payments.
One app was published under the developer name “Indian gov.in,” a choice that appeared designed to create a false sense of authority. There is no indication that the app had any legitimate government connection. For a user scanning quickly through app listings, however, a government-looking name can be enough to lower suspicion.
How the Payment Trap Worked
The flow was built around curiosity first and payment second. Users were asked to enter a phone number, then pushed toward a paid step before the supposedly sensitive records could be viewed or delivered.
ESET described two main user paths. In one version, the app claimed it could display call and SMS history after payment. In another, the app asked for an email address and suggested the records would be sent there once the user paid. ESET’s research indicates that the resulting data was not real call history, but generated or preloaded information presented as if it came from a real lookup.
The payment options varied by app. Some used Google Play’s billing system. Others sent users through third-party payment apps or card checkout screens inside the app. ESET said some of those payment approaches sidestepped Google Play’s official billing system, which makes refunds and subscription cancellation harder for victims.
The requested amounts also varied. ESET reported that the fake service used different subscription packages, including weekly, monthly, and yearly options. The highest price identified by ESET was about $80, while lower-tier payments were much smaller. The important point for users is not only the first charge. A subscription scam can keep taking money until the user notices and cancels it.
Malwarebytes Premium Security
A mobile security suite can help scan for known malware, risky links, and unwanted software after a suspicious app is removed. It will not cancel subscriptions or recover payments, so users should still check Google Play, UPI, wallet, or card records separately.
As an Amazon Associate I earn from qualifying purchases.
Why These Apps Were Harder to Spot Than Malware
Many people expect malicious Android apps to ask for suspicious permissions immediately. The CallPhantom apps show why that mental model is incomplete.
ESET said the apps generally had simple interfaces and did not need sensitive permissions to run the scam. That makes sense: if the goal is to sell a fake lookup, the app does not need access to contacts, SMS messages, microphones, or call logs. It only needs a convincing screen, a payment prompt, and enough fake output to make the user believe the service worked.
This is one reason app-store fraud can survive even when classic malware signals are absent. A scanner may flag code that steals credentials or abuses accessibility services. A fake service that charges money for fabricated results can look less technically aggressive while still causing real financial harm.
The scam also exploited a gap between what users want and what is technically realistic. People may search for call records because of family disputes, relationship concerns, debt collection, lost contact information, or suspicion of fraud. The apps turned that demand into a paid product, even though the promised data access was not legitimate.
Apps Identified in the Report
ESET identified 28 apps in the CallPhantom cluster. Many used overlapping names, which can make it difficult for users to remember which one they installed. The package names are more precise than the display names and are useful when checking old receipts, installed-app histories, or device backups.
| App name | Package name |
|---|---|
| Call history : any number deta | calldetaila.ndcallhisto.rytogetan.ynumber |
| Call History of Any Number | com.pixelxinnovation.manager |
| Call Details of Any Number | com.app.call.detail.history |
| Call History Any Number Detail | sc.call.ofany.mobiledetail |
| Call History Any Number Detail | com.cddhaduk.callerid.block.contact |
| Call History Of Any Number | com.basehistory.historydownloading |
| Call History of Any Numbers | com.call.of.any.number |
| Call History Of Any Number | com.rajni.callhistory |
| Call History Any Number Detail | com.callhistory.calldetails.callerids.callerhistory.callhostoryanynumber.getcall.history.callhistorymanager |
| Call History Any Number Detail | com.callinformative.instantcallhistory.callhistorybluethem.callinfo |
| Call History Any Number detail | com.call.detail.caller.history |
| Call History Any Number Detail | com.anycallinformation.datadetailswho.callinfo.numberfinder |
| Call History Any Number Detail | com.callhistory.callhistoryyourgf |
| Call History Any Number | com.calldetails.smshistory.callhistoryofanynumber |
| Call History Any Number Detail | com.callhistory.anynumber.chapfvor.history |
| Call History of Any Number | com.callhistory.callhistoryany.call |
| Call History Any Number Detail | com.name.factor |
| Call History Of Any Number | com.getanynumberofcallhistory.callhistoryofanynumber.findcalldetailsofanynumber |
| Call History Of Any Number | com.chdev.callhistory |
| Phone Call History Tracker | com.phone.call.history.tracke |
| Call History- Any Number Deta | com.pdf.maker.pdfreader.pdfscanner |
| Call History Of Any Number | com.any.numbers.calls.history |
| Call History Any Number Detail | com.callapp.historyero |
| Call History – Any Number Data | all.callhistory.detail |
| Call History For Any Number | com.easyranktools.callhistoryforanynumber |
| Call History of Numbers | com.sbpinfotech.findlocationofanynumber |
| Call History of Any Number | callhistoryeditor.callhistory.numberdetails.calleridlocator |
| Call History Pro | com.all_historydownload.anynumber.callhistorybackup |
Users should not assume that removal from Google Play deletes an app from their phone. If one of these apps was installed, it should be removed manually, and any related subscription or payment history should be checked separately.
What Victims Should Check Now
The right next step depends on how the payment was made. Google Play billing gives users more options than a payment routed outside the Play Store.
- If payment went through Google Play, open Google Play subscriptions and confirm that the subscription is canceled.
- Review Google Play purchase history for charges tied to the app name or developer.
- If payment was made through a UPI app or another third-party wallet, check that app’s transaction history and dispute process.
- If card details were entered directly inside an app, contact the card issuer and watch for recurring charges.
- Remove the app from the device and restart the phone after uninstalling it.
- Keep screenshots or receipts if a refund, chargeback, or support request is needed.
ESET said subscriptions bought through official Google Play billing may be eligible for refunds under Google’s policies. For purchases made outside Google Play, Google generally cannot cancel the payment or refund it, leaving users dependent on the payment provider, bank, card issuer, or app operator.
Users should also treat any promise of “call history for any number” as a warning sign. The safest answer is simple: if an app claims it can retrieve private communications records for someone else’s number, assume the offer is deceptive unless it comes from a legitimate telecom provider and applies to your own authorized account.
Why App Store Trust Is Not Enough
The CallPhantom case is a reminder that official app stores reduce risk but do not remove it. Google Play has review systems, policy enforcement, and malware scanning, yet fraudulent commercial behavior can still slip through long enough to reach millions of downloads.
For buyers, the better question is not only “Is this app in the official store?” It is also “Does this app’s promise make sense?” In this case, the promise did not. A third-party utility should not be able to access arbitrary call logs, SMS records, or WhatsApp call history just because a user typed in a number.
Reviews can help, but they are not decisive. Scam apps often use generic review patterns, rating manipulation, or misleading screenshots. The app name itself can also be engineered for search rather than trust. Repeated keywords, awkward phrasing, and multiple near-identical apps from unrelated developers are all reasons to slow down.
A practical review checklist helps before paying for a mobile utility:
- Check whether the promised feature is technically and legally plausible.
- Look at the developer name, website, and support contact.
- Read negative reviews first, especially recent ones.
- Be cautious with apps that require payment before showing whether the core feature works.
- Avoid entering card details directly into small utility apps unless the developer is well known and the payment flow is clearly legitimate.
- Prefer subscriptions that are managed through the official app store billing system, because they are easier to cancel and dispute.
Yubico Security Key C NFC
A hardware security key can add phishing-resistant two-factor protection to supported accounts such as Google, Microsoft, password managers, and other services. It is most useful as account hardening, not as a replacement for checking app subscriptions and payment history.
As an Amazon Associate I earn from qualifying purchases.
A Related Pattern: Brand Impersonation and Mobile Payment Fraud
The CallPhantom findings also fit a broader pattern in mobile fraud: attackers and scammers increasingly use familiar platforms, trusted brands, and everyday payment flows instead of relying only on advanced technical exploits.
In a separate campaign affecting Indonesian users, Group-IB reported fraud activity involving fake apps and impersonation of trusted services, including Indonesia’s CoreTax platform. Group-IB associated that activity with the financially motivated GoldFactory threat cluster, though the details should be read as vendor-attributed findings rather than independently confirmed public facts.
That campaign, as described by Group-IB, used a heavier attack chain than CallPhantom. It involved phishing sites, WhatsApp-based social engineering, malicious Android package installation outside official app stores, and voice phishing. Group-IB said malware families such as Gigabud RAT, MMRat, and Taotie were involved in parts of the activity it tracked.
The useful comparison is not that every fake app behaves the same way. They do not. CallPhantom appears to have focused on charging users for fabricated records, while the Indonesian brand-abuse activity described by Group-IB involved deeper device compromise and attempted financial theft. The shared lesson is that mobile users are being pushed into payment or installation decisions through familiar-looking brands, urgent claims, and services that appear useful at first glance.
What Businesses Should Take From This
For businesses, especially those operating in India, Southeast Asia, or other high-volume mobile-payment markets, the CallPhantom case is not just a consumer warning. It is a marketplace and brand-trust problem.
Fraudulent apps can borrow government language, payment familiarity, and app-store legitimacy to create a convincing funnel. If a scammer can persuade millions of users to pay for fake call records, the same playbook can be adapted to fake loan apps, tax tools, HR portals, delivery services, utility payments, crypto wallets, and customer-support apps.
Companies should monitor app stores for lookalike apps using their names, logos, product language, or customer workflows. They should also give customers a clear place to verify official apps and payment channels. Silence creates space for impersonators.
Security teams should treat mobile app impersonation as part of the fraud surface, not only as a malware problem. A fake app may not need to steal credentials to damage customers. It can collect payments, harvest contact details, gather email addresses, or train users to trust unsafe payment flows.
The Bottom Line for Android Users
The CallPhantom apps succeeded because they sold something people wanted to believe existed. The apps did not need a sophisticated permission request or a complex exploit. They needed a plausible name, a payment page, and a promise that sounded powerful.
The safest rule is blunt: do not pay an app that claims it can reveal private call, SMS, or WhatsApp records for any phone number. That is not a normal consumer service. If an app makes that claim, the risk is not just that it may fail. The risk is that the entire product is built around getting money before the user realizes the records are fake.
Anyone who installed one of the listed apps should remove it, check subscription and payment records, and dispute suspicious charges through the channel used to pay. Future protection comes from a more skeptical buying habit: official app store placement is helpful, but it is not proof that an app’s business model is honest.


