A staggering 7.3 million Android users downloaded fake stalking applications that falsely promised access to others’ private communications, revealing serious gaps in both app store security and consumer judgment.
These deceptive apps, collectively known as CallPhantom, claimed to provide call logs, SMS histories, and even WhatsApp conversations for any phone number – despite the technical impossibility of such access due to carrier restrictions and platform security measures. Instead of delivering on their promises, the apps generated fake data consisting of random phone numbers paired with fabricated names and timestamps, designed to appear convincing only after payment had been made.
Security researchers at ESET investigated this extensive scam operation, identifying 28 separate variants of the fraudulent application that remained available on the Google Play Store for months despite numerous user complaints. The apps maintained seemingly legitimate ratings through a combination of genuine one-star reviews from victims and suspicious clusters of five-star ratings that appeared designed to offset the negative feedback.
Most troubling was Google’s delayed response to the threat. Although ESET reported the applications in December 2025, their removal came only after external pressure rather than through Google’s automated detection systems. This failure is particularly significant given Google’s investments in threat detection frameworks and the App Protection Alliance.
Some variants exacerbated the problem by bypassing Google Play’s official billing system entirely, directing users to third-party payment methods like UPI or embedded credit card fields. This violation of Play Store policies not only prevented automatic refunds but also left victims needing to pursue reimbursement through complicated channels with unresponsive developers.
The apps’ success stemmed from their effective exploitation of a universal human desire: the temptation to monitor others’ communications. By offering access to partners’ calls, exes’ messages, or children’s activity at subscription prices ranging from a few euros weekly to $80 annually, they tapped into powerful emotional drivers despite delivering nothing functional.
For those who processed payments through Google Play’s legitimate system, subscription cancellations and potential refunds remain available through the store’s payment settings. However, users who paid through alternative methods face significantly more challenging recovery processes.
This incident serves as a stark reminder that even obvious technological impossibilities can’t deter determined scammers when they effectively manipulate human psychology, and that platform security requires constant vigilance to protect users from increasingly sophisticated deception attempts.


