Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Secure Boot state off in System Information, but on in BIOS

    June 12, 2026

    Samsung Galaxy A27 listed on official site

    June 12, 2026

    Ivanti Sentry Exploitation Attempts Hitting Honeypots

    June 12, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Reviews»Fake stalking apps racked million of downloads. It says a lot about Google’s security and us
    Fake stalking apps racked million of downloads. It says a lot about Google’s security and us
    Reviews

    Fake stalking apps racked million of downloads. It says a lot about Google’s security and us

    The Tech GuyBy The Tech GuyMay 9, 2026No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    There is no app that lets you pull up someone else’s call history. There never has been, and there almost certainly never will be — carriers don’t expose that data, and no third-party developer has the access required to retrieve it. This is not a grey area; it is simply not possible. And yet, 7.3 million people, according to welivesecurity have downloaded apps that claimed to do exactly that.

    Advertisement

    Security researchers at ESET spent months untangling a sprawling family of 28 fraudulent Android apps they collectively dubbed CallPhantom — apps that promised users a window into anyone’s phone activity: call logs, SMS records, even WhatsApp history. Enter a number, pay a small fee, and the secrets of whoever you were looking up would supposedly come spilling out. What actually came out was fiction — random phone numbers dressed up with hardcoded names and timestamps, generated by the app itself, designed to look just convincing enough to seem real. The payoff is that users only saw this fake data after they’d already paid. That sequencing wasn’t accidental.

    Google Play Store had a serious blind spot here

    All 28 apps sat on the Google Play Store long enough to accumulate millions of downloads. One of them was published under the name “Indian gov.in,” a developer handle implying government legitimacy it had no right to claim. Several had review sections full of users explicitly writing that they’d been scammed, and those warnings coexisted with clusters of suspiciously enthusiastic five-star reviews that kept the ratings looking respectable.

    Page, Text, Electronics
    WeLiveSecurity

    ESET flagged the full set to Google in December 2025, and the apps were removed. But the removal came from an external report, not from Google catching something itself. For a platform that has invested heavily in automated threat detection and the App Defense Alliance framework, letting 28 variants of the same scam — all promising the same technically impossible feature — accumulate millions of downloads is a significant gap.

    Some apps made things worse by bypassing Google’s payment infrastructure entirely, routing users to third-party UPI transactions or to direct card entry fields embedded in the app. That’s a violation of Play Store policy, but it also means Google can’t issue refunds to those users. Anyone who paid outside the official billing system has to chase down the payment provider themselves, or the developers, who, it goes without saying, are not particularly motivated to help.

    The apps worked because the pitch was irresistible

    The more uncomfortable part of this story is what drove 7.3 million downloads in the first place. These apps didn’t offer cloud storage or a new way to edit photos. They offered something people actually wanted badly enough to pay for: the ability to spy on someone — a partner, an ex, a teenager, or a business contact. Whatever the reason, there was clearly a large and willing audience for the idea.

    The apps leaned into that desire with ruthless precision. They preselected India’s +91 country code by default and supported UPI payments, which signals that the scammers understood their target demographic well. Subscription tiers ranged from a few euros per week to $80 a year, giving users options that felt like a legitimate service and catered to different needs. One app, when a user tried to exit without paying, sent a fake push notification styled to look like an email had just arrived with the results — a last-ditch nudge that led straight back to the paywall.

    File, Text
    WeLiveSecurity

    It worked because curiosity is a powerful thing, and the apps were designed by people who understood that. Strip away the technical scaffolding and what you have is a very old scam: charge someone for something they desperately want, give them a plausible-looking nothing, and count on embarrassment to keep them from complaining too loudly.

    For anyone caught up in this, subscriptions processed through Google Play’s official system can be canceled — and potentially refunded — through the Play Store’s payment settings. Everything else is a harder conversation with whoever processed the payment.

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    vivo X Fold6 confirmed to feature a special edition Dimensity 9500 SoC

    June 12, 2026

    Corsair Galleon 100 SD review: Stream Deck meets K70, complete with all the bells and whistles

    June 12, 2026

    The Galaxy Watch Ultra 2 could be a battery champion

    June 11, 2026

    OpenAI teams up with Visa to enable secure payments through AI agents

    June 11, 2026

    The new Tecno Pova 8 boasts an 8,000mAh battery, Alive Matrix Display on its back

    June 11, 2026

    HyperX Origins 2 1800 review: a satisfying mechanical board with versatile hardware but limited software

    June 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202625 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Secure Boot state off in System Information, but on in BIOS

    June 12, 2026

    Samsung Galaxy A27 listed on official site

    June 12, 2026

    Ivanti Sentry Exploitation Attempts Hitting Honeypots

    June 12, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.