Fake call logs, real payments: How CallPhantom tricks Android users

2026-05-08T08:51:48Z1c5f30632d54db2692e43a8ec3b7f19fdf1213edcde95eef1d84dd273ffa1f53
android-malwarecallphantomdynowiperedr-killersgenai-abusegoogle-playgopherwhispermobile-fraudngatepromptspyransomwarescamsscarcruftsupply-chain-attacktrojanized-nfc-app

What happened

ESET’s recent research collection highlights a wave of mobile- and supply-chain-focused threats plus high-impact intrusions and fraud. Key findings: CallPhantom — fraudulent Android apps on Google Play that fabricate call-history records to trick users into real payments (removed after ~7M+ installs); PromptSpy — the first known Android malware observed abusing generative AI in its execution flow; a new NGate variant hidden in a trojanized NFC payment app; ScarCruft supply‑chain compromises via backdoor-laced Windows and Android games; GopherWhisper — a China-aligned APT targeting Mongolian 정부

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
1c5f30632d54db2692e43a8ec3b7f19fdf1213edcde95eef1d84dd273ffa1f53
Enrichment time
2026-05-08T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.