Fake stalking apps racked million of downloads. It says a lot about Google’s security and us

A staggering 7.3 million Android users downloaded fake stalking applications that falsely promised access to others’ private communications, revealing serious gaps in both app store security and consumer judgment.

These deceptive apps, collectively known as CallPhantom, claimed to provide call logs, SMS histories, and even WhatsApp conversations for any phone number – despite the technical impossibility of such access due to carrier restrictions and platform security measures. Instead of delivering on their promises, the apps generated fake data consisting of random phone numbers paired with fabricated names and timestamps, designed to appear convincing only after payment had been made.

Security researchers at ESET investigated this extensive scam operation, identifying 28 separate variants of the fraudulent application that remained available on the Google Play Store for months despite numerous user complaints. The apps maintained seemingly legitimate ratings through a combination of genuine one-star reviews from victims and suspicious clusters of five-star ratings that appeared designed to offset the negative feedback.

Most troubling was Google’s delayed response to the threat. Although ESET reported the applications in December 2025, their removal came only after external pressure rather than through Google’s automated detection systems. This failure is particularly significant given Google’s investments in threat detection frameworks and the App Protection Alliance.

Some variants exacerbated the problem by bypassing Google Play’s official billing system entirely, directing users to third-party payment methods like UPI or embedded credit card fields. This violation of Play Store policies not only prevented automatic refunds but also left victims needing to pursue reimbursement through complicated channels with unresponsive developers.

The apps’ success stemmed from their effective exploitation of a universal human desire: the temptation to monitor others’ communications. By offering access to partners’ calls, exes’ messages, or children’s activity at subscription prices ranging from a few euros weekly to $80 annually, they tapped into powerful emotional drivers despite delivering nothing functional.

For those who processed payments through Google Play’s legitimate system, subscription cancellations and potential refunds remain available through the store’s payment settings. However, users who paid through alternative methods face significantly more challenging recovery processes.

This incident serves as a stark reminder that even obvious technological impossibilities can’t deter determined scammers when they effectively manipulate human psychology, and that platform security requires constant vigilance to protect users from increasingly sophisticated deception attempts.

spot_imgspot_img

Subscribe

Related articles

Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison

Latvian national sentenced to 8.5 years for Karakurt ransomware negotiator role in $56M+ extortion scheme.

Google now offers up to $1.5 million for some Android exploits

Google overhauls Android and Chrome vulnerability rewards, offering up to $1.5 million for complex exploits while adjusting AI-discoverable flaw payouts.

Test Post Updated

This test post has been updated.

Weekly Deals: iPhone Air and iPhone 17 Price Cuts, Galaxy S26 and Pixel 10 Series on Sale

This Week's Best Smartphone DealsThe flagship smartphone market is...

Apple Unveils 2026 Pride Edition Sport Loop — A Rainbow Woven for Every Identity

A Band That Celebrates the Full SpectrumApple has launched...
spot_imgspot_img