CallPhantom scam spreads across 28 Google Play apps with 7 million downloads

A scam campaign called CallPhantom has appeared in 28 applications available on the Google Play store. The apps, which have been downloaded more than 7 million times combined, promised users access to their call logs.

The malicious software was distributed through legitimate-looking apps on the official Android marketplace. Once installed, the apps collected call data without proper user consent, according to reports of the scheme.

Articoli correlati

IT expert Supangat warns of Lebaran digital scams via WhatsApp and SMS in a press conference illustration.
Immagine generata dall'IA

IT expert warns of digital scams ahead of Lebaran

Riportato dall'IA Immagine generata dall'IA

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

A dangerous Android malware called Massiv is disguising itself as an IPTV app to infect devices and steal banking information. The threat primarily targets users in Portugal through this deceptive application. Security researchers have highlighted the risks posed by this fake app.

Riportato dall'IA

Security researchers have flagged a new risk to users of Microsoft's Phone Link application. An unidentified threat actor is using the tool to steal SMS messages and one-time passwords.

In Colombia, fraudulent SMS messages mimicking insurance notifications and bank transfers are spreading during Semana Santa 2026. Authorities including the Fiscalía and National Police warn against clicking suspicious links to prevent data theft and account draining. They urge verifying information through official channels.

Riportato dall'IA

Swedish police report more than 300 cases of fake SMS messages nationwide over the past two days, following initial warnings about scams urging payment of traffic fines via links. Authorities continue to advise deleting the messages and reporting them.

Google is introducing a developer verification program for Android apps starting September 2026 in select regions, requiring developers to register personal details regardless of app source. The measure aims to enhance security by increasing accountability, but critics argue it threatens open source projects and user choice. An open letter opposing the program has garnered support from numerous organizations.

Riportato dall'IA

Journalists reported mysterious phishing attempts by unknowns a few weeks ago. The Dutch secret service now holds Russia responsible for attacks on the messaging apps WhatsApp and Signal. The report explains how the attacks work and how users can protect themselves.

 

 

 

Questo sito web utilizza i cookie

Utilizziamo i cookie per l'analisi per migliorare il nostro sito. Leggi la nostra politica sulla privacy per ulteriori informazioni.
Rifiuta