A new Android scam called CallPhantom falsely promises access to call, SMS and WhatsApp logs for any number in exchange for payment. 28 apps identified on Google Play with over 7.3 million downloads. Some apps bypass the official payment system, making refunds difficult
ESET Research has identified some fraudulent apps on Google Play that promise to provide call history "for any number". The apps in question, which ESET has named CallPhantom based on the false information provided, pretend to allow access to call history, SMS messages and even WhatsApp call logs for any phone number. To unlock this supposed feature, users are asked to deposit an amount, but in return they only receive randomly generated data. An ESET investigation revealed 28 fraudulent apps of this type, downloaded more than 7.3 million times overall. As a partner of the App Defense Alliance, ESET reported the findings to Google, which removed the apps identified in the report from Google Play.
CallPhantom apps primarily targeted Android users in India and the Asia-Pacific region. Many of these apps had the country code of India (+91) pre-selected and supported the UPI payment system, which is mainly used in India.
"In November 2025, we came across a post on Reddit talking about an app called Call History of Any Number, found on Google Play. Not surprisingly, the analysis showed that the 'call history' data provided by this app is entirely fabricated: the app generates random phone numbers and matches them with fixed names, times and call durations, which were inserted directly into the code," says Lukáš Štefanko, researcher at ESET, who discovered the fraud CallPhantom.
Generally speaking, CallPhantom apps have a simple user interface and do not require invasive or sensitive data permissions - they don't need them. As a result, they do not contain any features that can recover actual data related to calls, SMS or WhatsApp.
In the CallPhantom apps analyzed by ESET, researchers identified three different payment methods, two of which violate Google Play's payment policy. Some apps relied on subscriptions through Google Play's official billing system. Others relied on third-party payments; in some cases, credit card payment forms were included directly in the CallPhantom apps.
The fees charged for the fake service vary greatly from one app to another. The apps also appear to offer different subscription plans, such as weekly, monthly or annual services, with the maximum asking price standing at $80. For the cheapest “subscription level”, the average asking price was 5 euros.
As a rule, subscriptions purchased through Google Play's official billing system can be canceled. For the 28 apps described in this blog post, existing subscriptions were canceled when the apps were removed from Google Play. In some cases, you may be able to get a refund for purchases made on Google Play.
If the purchase was made outside of Google Play — for example, by entering payment card information within the app or paying through third-party services — Google cannot cancel the subscription or issue a refund and users must contact their payment provider.
For more details on CallPhantom, see the latest ESET Research blog post”Fake Call Logs, Real Payments: How CallPhantom Tricks Android Users,” on WeLiveSecurity.com. Be sure to follow ESET Research on Twitter (now known as X), BlueSky, e Mastodon for the latest news from ESET Research.






