Fake call logs, real payments: How CallPhantom tricks Android users
2026-05-08T08:51:48Z•1c5f30632d54db2692e43a8ec3b7f19fdf1213edcde95eef1d84dd273ffa1f53
android-malwarecallphantomdynowiperedr-killersgenai-abusegoogle-playgopherwhispermobile-fraudngatepromptspyransomwarescamsscarcruftsupply-chain-attacktrojanized-nfc-app
What happened
ESET’s recent research collection highlights a wave of mobile- and supply-chain-focused threats plus high-impact intrusions and fraud. Key findings: CallPhantom — fraudulent Android apps on Google Play that fabricate call-history records to trick users into real payments (removed after ~7M+ installs); PromptSpy — the first known Android malware observed abusing generative AI in its execution flow; a new NGate variant hidden in a trojanized NFC payment app; ScarCruft supply‑chain compromises via backdoor-laced Windows and Android games; GopherWhisper — a China-aligned APT targeting Mongolian 정부
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 1c5f30632d54db2692e43a8ec3b7f19fdf1213edcde95eef1d84dd273ffa1f53
- Enrichment time
- 2026-05-08T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.