Skip to main content
  1. Home
  2. Phones
  3. Features

Fake stalking apps racked million of downloads. It says a lot about Google’s security and us

Add as a preferred source on Google
I Spy Podcast
Spy

There is no app that lets you pull up someone else’s call history. There never has been, and there almost certainly never will be — carriers don’t expose that data, and no third-party developer has the access required to retrieve it. This is not a grey area; it is simply not possible. And yet, 7.3 million people, according to welivesecurity have downloaded apps that claimed to do exactly that.

Security researchers at ESET spent months untangling a sprawling family of 28 fraudulent Android apps they collectively dubbed CallPhantom — apps that promised users a window into anyone’s phone activity: call logs, SMS records, even WhatsApp history. Enter a number, pay a small fee, and the secrets of whoever you were looking up would supposedly come spilling out. What actually came out was fiction — random phone numbers dressed up with hardcoded names and timestamps, generated by the app itself, designed to look just convincing enough to seem real. The payoff is that users only saw this fake data after they’d already paid. That sequencing wasn’t accidental.

Google Play Store had a serious blind spot here

All 28 apps sat on the Google Play Store long enough to accumulate millions of downloads. One of them was published under the name “Indian gov.in,” a developer handle implying government legitimacy it had no right to claim. Several had review sections full of users explicitly writing that they’d been scammed, and those warnings coexisted with clusters of suspiciously enthusiastic five-star reviews that kept the ratings looking respectable.

ESET flagged the full set to Google in December 2025, and the apps were removed. But the removal came from an external report, not from Google catching something itself. For a platform that has invested heavily in automated threat detection and the App Defense Alliance framework, letting 28 variants of the same scam — all promising the same technically impossible feature — accumulate millions of downloads is a significant gap.

Recommended Videos

Some apps made things worse by bypassing Google’s payment infrastructure entirely, routing users to third-party UPI transactions or to direct card entry fields embedded in the app. That’s a violation of Play Store policy, but it also means Google can’t issue refunds to those users. Anyone who paid outside the official billing system has to chase down the payment provider themselves, or the developers, who, it goes without saying, are not particularly motivated to help.

The apps worked because the pitch was irresistible

The more uncomfortable part of this story is what drove 7.3 million downloads in the first place. These apps didn’t offer cloud storage or a new way to edit photos. They offered something people actually wanted badly enough to pay for: the ability to spy on someone — a partner, an ex, a teenager, or a business contact. Whatever the reason, there was clearly a large and willing audience for the idea.

The apps leaned into that desire with ruthless precision. They preselected India’s +91 country code by default and supported UPI payments, which signals that the scammers understood their target demographic well. Subscription tiers ranged from a few euros per week to $80 a year, giving users options that felt like a legitimate service and catered to different needs. One app, when a user tried to exit without paying, sent a fake push notification styled to look like an email had just arrived with the results — a last-ditch nudge that led straight back to the paywall.

It worked because curiosity is a powerful thing, and the apps were designed by people who understood that. Strip away the technical scaffolding and what you have is a very old scam: charge someone for something they desperately want, give them a plausible-looking nothing, and count on embarrassment to keep them from complaining too loudly.

For anyone caught up in this, subscriptions processed through Google Play’s official system can be canceled — and potentially refunded — through the Play Store’s payment settings. Everything else is a harder conversation with whoever processed the payment.

Shimul Sood
Shimul is a contributor at Digital Trends, with over five years of experience in the tech space.
I tried a hidden video trick in iOS 27, and it saved me a ton of frustration
Better quality, smaller file size, and no status bar. iOS 27's video frame feature beats screenshots on every count.
Electronics, Mobile Phone, Phone

If you've ever been on vacation and chose to record video instead of taking photos only to avoid missing the fun moments, thinking you’d pause and take screenshots later, you might have ended up questioning your decision later. 

You see, the process involves multiple steps, starting from hunting for the right frame, pausing, and taking a screenshot. If it doesn’t look good, you go back to the video, pause somewhere else, and try taking another screenshot. You see where I’m going with this?

Read more
iPhone 18 Pro images are already floating on the dark web with a whole bunch of other Apple secrets
A ransomware attack on Tata Electronics reportedly exposed confidential documents tied to Apple's next flagship.
Apple iPhone 17 Pro White

Apple is famous for keeping future iPhones under lock and key. This time, however, the leak didn't come from a case maker or an overenthusiastic tipster. According to Reuters, confidential files linked to the iPhone 18 Pro have surfaced on the dark web following a cyberattack on Tata Electronics, one of Apple's most important manufacturing partners in India.

The leak goes far beyond a few blurry photos

Read more
Apple has six new iPhones lined up for 2027 with some serious upgrade muscle
The 2027 iPhone lineup looks stacked
Electronics, Phone, Mobile Phone

Apple's iPhone launch calendar may get a lot busier in 2027. A new leak claims the company has six new iPhone models lined up across the year, and if most of it is accurate, we could be looking at the biggest iPhone roadmap in years.

According to known tipster, Digital Chat Station, Apple’s early 2027 lineup could include the iPhone Air 2, iPhone 18, and iPhone 18e. The fall lineup is expected to bring next-generation Pro models and a second foldable iPhone, reportedly referred to as iPhone Ultra 2.

Read more