‏إظهار الرسائل ذات التسميات Internet Frauds. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Internet Frauds. إظهار كافة الرسائل

ESET Exposes CallPhantom Scam: 28 Fake Call‑History Apps With 7.3M Downloads Removed From Google Play

ESET Exposes CallPhantom Scam: 28 Fake Call‑History Apps With 7.3M Downloads Removed From Google Play
  • ESET identified and reported 28 separate CallPhantom apps on Google Play, cumulatively downloaded more than 7.3 million times.
  • 53.7% of all CallPhantom detections worldwide were found in India.Some CallPhantom apps sidestep Google Play’s official billing system, complicating victims’ refund efforts.
ESET researchers have uncovered fraudulent apps on Google Play that claim to provide the call history “for any number.” The offending apps, which ESET named CallPhantom based on their false claims, purport to provide access to call histories, SMS records, and even WhatsApp call logs for any phone number. To unlock this supposed feature, users are asked to pay — but all they get in return is randomly generated data. ESET’s investigation identified 28 such fraudulent apps, cumulatively downloaded more than 7.3 million times. As an App Defense Alliance partner, we reported our findings to Google, which removed all of the apps identified in this report from Google Play.

The CallPhantom apps mainly targeted Android users in India. Many of the apps came with India’s +91 country code preselected, and support UPI, a payment system used primarily in India. 53.7% of all CallPhantom detections worldwide were found in India.

In November 2025, we came across a Reddit post discussing an app named Call History of Any Number, found on Google Play. Unsurprisingly, our analysis showed that the ‘call history’ data provided by this app is entirely fabricated — the app generates random phone numbers and matches them with fixed names, call times, and call durations, which were embedded directly in the code, says ESET researcher Lukáš Štefanko, who uncovered the CallPhantom fraud.


In general, CallPhantom apps have a simple user interface and do not request any intrusive or sensitive permissions — they don’t need to. Coincidentally, they do not contain any functionality capable of retrieving actual call, SMS, or WhatsApp data.

In the CallPhantom apps ESET analyzed, researchers saw three different payment methods used, two of which are in violation of Google Play’s payments policy. Some of the apps relied on subscriptions via Google Play’s official billing system. Others relied on payments via a third party; in some cases, payment card checkout forms were included directly in the CallPhantom apps.

The fees requested for the fake service differ widely across the apps. The apps also appear to offer different subscription packages, such as weekly, monthly, or yearly services, with the highest requested price sitting at US$80. For the lowest “subscription tier,” the average requested price was €5.

In general, subscriptions purchased through the official Google Play billing system can be canceled. For the 28 apps described in this blog post, existing subscriptions were canceled when the apps were removed from Google Play. In some cases, refunds for Google Play purchases are possible.

If the purchase was made outside of Google Play — for example, by entering payment card details inside the app or by paying via third-party services — then Google cannot cancel the subscription or issue a refund, and users have to contact their payment provider.

For more details about CallPhantom, check out the latest ESET Research blog post, “Fake call logs, real payments: How CallPhantom tricks Android users,” on WeLiveSecurity.com. Make sure to follow ESET Research on BlueSky, and Mastodon for the latest news from ESET Research.

Think Before You Click: SEBI’s #SEBIvsSCAM Campaign Targets Fake Apps, Deepfakes, and Dubious Tips

Think Before You Click: SEBI’s #SEBIvsSCAM Campaign Targets Fake Apps, Deepfakes, and Dubious Tips

Securities and Exchange Board of India (SEBI) has launched a nationwide investor awareness campaign titled #SEBIvsSCAM, aimed at educating investors about various types of financial scams and how to safeguard themselves. This initiative is part of SEBI’s ongoing commitment to protect the retail investors from such scams in the securities market. Under SEBI’s guidance and regulatory oversight, the National Stock Exchange of India Ltd. (NSE) has rolled out a comprehensive investor protection drive to support this campaign.

The campaign comes at a critical time when digital financial frauds are on the rise, with fraudsters using increasingly sophisticated and deceptive methods to target investors. From fake trading apps and deepfake videos to unregistered investment advisors and misleading stock tips on social media, scammers are exploiting technology and denting investor’s trust. Many individuals fall prey to schemes promising guaranteed returns/unusually high returns, pump-and-dump tactics, dabba trading, fraudulent foreign portfolio investment offers, etc—often resulting in significant financial losses.

#SEBIvsSCAM seeks to raise public awareness, promote safe investing habits and empower investors to make informed decisions. By spotlighting common scams and offering guidance, the campaign aims to help investors recognize warning signs, verify sources and report suspicious activities—ultimately contributing to a more secure and transparent financial ecosystem.

To ensure maximum outreach, NSE, under the aegis of SEBI will leverage a mix of media platforms including television, radio, print, digital and social media. We will also spread the Investor Awareness messages through Investor Awareness Programs which are done through physical, digital and hybrid modes. This multi-channel approach is designed to reach investors across urban and rural areas, in multiple languages and through formats that are accessible and engaging to diverse audiences.

Investor Advisory: Stay Alert, Stay Protected


Issued in public interest by the National Stock Exchange of India Ltd under the aegis of Securities and Exchange Board of India.

Indian Govt Issues Advisory Warning on AI Generated Deepfake Threats

Indian Govt Issues Advisory Warning on AI Generated Deepfake Threats

India's national nodal agency for responding to computer security incidents in the country, the Indian Computer Emergency Response Team (CERT-In), has recently issued an advisory warning about the rising threats posed by Al-generated deepfakes.

Deepfake technology, which involves the use of artificial intelligence (AI) to create highly realistic and convincing fake videos, images, and audio, is becoming increasingly sophisticated. This technology poses significant risks, including the potential for disinformation, fraud, and social engineering attacks.

The advisory highlights risks such as misinformation, financial fraud, and privacy violations, and provides guidance for individuals and organizations to detect and counter these threats.

Here are some key points from the advisory:

1. Verify Sources: Ensure digital content is from reliable sources before sharing or acting on it.

2. Look for Anomalies: Identify signs such as unnatural blinking, mismatched lip-sync, inconsistent lighting, or distorted visuals.

3. Cross-Reference Information: Confirm the accuracy of content through multiple trusted sources

4. Limit Personal Data: Avoid sharing high-resolution images or videos online.

5. Use Multi-Factor Authentication (MFA): Secure accounts with MFA to reduce risks of hacking.

6. Monitor Public Channels: Keep track of potential deepfake content targeting your Organization.

7. Adopt Secure Communication: Use encrypted channels for sensitive discussions to prevent interception.

The advisory also urges organizations to strengthen detection tools, monitor public channels, and enhance digital forensics capabilities.

The advisory, with original issued date of 27 November 2024, serves as a critical resource for identifying, assessing, and mitigating the threats posed by synthetic media.

It's crucial to stay informed and vigilant about these threats.

Deepfake Videos of Narayana Murthy and Mukesh Ambani Scammed Two to Lose ~₹ 90 Lakh

Deepfake Videos of Narayana Murthy and Mukesh Ambani Scammed Two to Lose ~₹ 90 Lakh

Two residents of Bengaluru fell victim to deepfake videos featuring Infosys co-founder Narayana Murthy and Reliance Industries Chairman Mukesh Ambani, collectively losing around ₹95 lakh.

These deepfake videos promoted trading platforms and promised high returns, leading the victims to invest large sums of money. One victim lost ₹67 lakh, while another lost ₹19 lakh.

First Victim:

A woman from Banashankari came across a video on social media promoting a trading platform with high returns. She clicked on a suspicious link, shared her details, and was contacted by someone claiming to be an agent. Initially, she invested ₹1.4 lakh and received ₹8,000 in returns. Encouraged by this, she invested ₹6.7 lakh but didn't receive any returns. She also lost ₹67 lakh to another platform promising work-from-home opportunities.

Second Victim:

A retired employee saw a similar video on Facebook promoting a trading platform. He transferred ₹19 lakh to two different bank accounts provided by the fraudsters but didn't receive any response after the transfer.

Both victims didn't verify the authenticity of the videos and ended up clicking on links that led to fake websites created by fraudsters. Separate cases have been registered at the CEN (Cyber Economic and Narcotics) South police station, and investigations are ongoing to track down the culprits.

Deepfake technology played a crucial role in this scam by creating highly realistic videos of Narayana Murthy and Mukesh Ambani. These videos were used to promote fraudulent trading platforms, convincing victims that the endorsements were genuine. The deepfakes were so convincing that the victims didn't question their authenticity and ended up investing large sums of money.

It's a stark reminder to always verify the authenticity of online content, especially when it involves financial investments.

It must be recalled that last year, Narayana Murthy had alerted people that many trading platforms are using his identity for promotions and said that he does not endorse any of them.

In an X post, Murthy said, “In recent months, there have been several fake news items propagated via social media apps and on various web pages available on the Internet claiming that I have endorsed or invested in automated trading applications named BTC AI Evex, British Bitcoin Profit, Bit Lyte Sync, Immediate Momentum, Capitalix Ventures etc. The news items appear on fraudulent websites that masquerade as popular newspaper websites and some of them even publish fake interviews using deepfake pictures and videos. I categorically deny any endorsement, relation or association with these applications or websites.”

In response to the deepfake scam, the Bengaluru police have taken several actions. Separate cases have been registered at the CEN (Cyber Economic and Narcotics) South police station. The police are actively investigating to track down the culprits behind the scam.

Public Awareness: Authorities have urged the public to be cautious of deepfake videos and to verify the authenticity of any suspicious content before taking any action. They have also advised people to report any such incidents to the police immediately.

Helpline: The Bengaluru City Police have launched a helpline (1930) for victims of deepfake scams to register complaints and seek assistance.

It's crucial to stay vigilant and report any suspicious activity to the authorities to help prevent such scams in the future. If you or someone you know has been affected, don't hesitate to reach out to the police for help.

Amazon Opens its Fraud Detector Services that Helps Businesses Identify Online Identity, Payment Frauds in Real Time using Machine Learning


Amazon Web Services Inc. (AWS), an Amazon.com company, announced the general availability of Amazon Fraud Detector, a fully managed service that makes it easy to quickly identify potentially fraudulent online activities like online payment and identity fraud.





Using machine learning under the hood and based on over 20 years of fraud detection expertise from Amazon, Amazon Fraud Detector automatically identifies potentially fraudulent activity in milliseconds—with no machine learning expertise required.





Essentially, Amazon Fraud Detector automates the complicated steps of creating machine learning models for fraud detection. Everything from data validation to model deployment can be done with no machine learning or coding experience required. The result is machine learning based fraud detection models that can be deployed in minutes instead of months.





Amazon Fraud Detector provides a fully managed service that uses machine learning for detecting potential fraud in real time (e.g. online payment and identity fraud, the creation of fake accounts, loyalty account and promotion code abuse, etc.), based on the same technology used by Amazon.com—with no machine learning experience required.





Amazon Fraud Detector is now available in parts of the US and other countries -- Ireland, Singapore, Sydney, with availability in additional regions -- expectedly India -- in the coming months.





With Amazon Fraud Detector, customers use their historical data of both fraudulent and legitimate transactions to build, train, and deploy machine learning models that provide real-time, low-latency fraud risk predictions. To get started, customers upload historical event data (e.g. transactions, account registrations, loyalty points redemptions, etc.) to Amazon Simple Storage Service (Amazon S3), where it is encrypted in transit and at rest and used to customize the model’s training. Customers only need to provide any two attributes associated with an event (e.g. logins, new account creation, etc.) and can optionally add other data (e.g. billing address or phone number). Based upon the type of fraud customers want to predict, Amazon Fraud Detector will pre-process the data, select an algorithm, and train a model.






https://youtu.be/MNSq2G3V8wM

Online Broker OctaFX Fights Fraud on the Forex Market



OctaFX is an international online broker who has been providing trading services worldwide over the last nine years. They have noticed a recent rise in the number of scammers who try to associate themselves with the company and defraud traders of their funds.

The fake websites are not that easy to pinpoint at a glance. Some of the fraudsters started acquiring security certificates and using .com as their top-level domain so that the potential traders would not notice anything suspicious when looking at the address bar.

One way traders can avoid being defrauded by OctaFX impersonators is by paying attention to the domain name itself. The broker regularly warns its clients about fake websites and social media accounts that use different variations of the OctaFX brand name. The company stresses that it only works under its official brand name.

The OctaFX clients should also pay attention to the payment processing. The broker only processes payments through the client's profile on the official website or the OctaFX Trading App and the OctaFX Copytrading App.

Fighting fraudsters on the Forex market is a complex task that requires effort from all parties involved. OctaFX is doing its best to take down fake websites and social media accounts. The team told us that it would be much harder without the trader community help. OctaFX is thankful to traders who diligently report fake websites and accounts that try to pass themselves off as the broker.

About OctaFX

OctaFX is a Forex broker providing online trading services worldwide since 2011. It offers a state-of-the-art trading experience to more than two million trading accounts. OctaFX has won more than 20 awards since its foundation, including the Best ECN Broker 2020 award from World Finance. The company is well-known for its social and charity activity. It also regularly conducts global and local promotion campaigns with valuable money and product prizes.

Nigeria's SEC Warns Against Blockchain Firm that Claims to End Poverty in Any Country in Less than 9 Mths




Securities and Exchange Commission (SEC), Nigeria has warned stakeholders and the investing public about the activities of an illegal blockchain operator - iBSmartify Nigeria, which is the promoters of a Blockchain known as iBledger (iBcashcryptocurrency) and InksNation.

In an announcement, SEC, said 0

The general public is hereby advised that neither the promoters of iBSmartify Nigeria nor the illegal products they offer are registered or regulated by the Commission." In view of the above, the general public is hereby WARNED that any person dealing with the said entity and others in the same business in any manner whatsoever, does so at his/her own risk.


Based out of Badagry, Nigeria, iBSmartify (InksNation) claims to use Blockchain , Artificial Intelligence, Extended Reality and Quantum Computing for Humanitarian Good towards building a better world where humans live like Kings and Queen in an autonomously driven ecosystem of abundance.

On its website 'inksnation.io', the company also claims to have invented the World's First Philanthropic Blockchain (InksLedger) and the World's First Charitable Trust DAO (InksNation), which the company in questions claims to end poverty in any country in less than 9 months incentivising goodness, promoting love, unity, oneness, peace and equitable distribution of wealth.

Further the Nigenrian company claims that its native Reserve Coin called 'PinKoin' will pay every single Nigerian, African and Human being on earth including babies born everyday a minimum of N120,000 ($330) monthly for life as UCBI (Universal Child Basic Income).

In a circular dated June 26, 2020, the SEC pointed out that neither the promoters of iBSmartify Nigeria nor the illegal products they offer are registered or regulated by the commission.

The SEC keeps warning the investing public against dealing with fraudulent and unregistered investment schemes and capital market operators, especially those with bogus investment and unjustifiable return claims.

The commission, in 2019, clamped down on some Ponzi scheme operators by blocking their bank accounts and taking over the real estate properties linked to them.

RBI Announces Creation of Central Payments Fraud Information Registry

The Reserve Bank of India (RBI) Wednesday announced creation of a central payments fraud information registry, which could ensure a quick and systemic responses in cases of financial frauds.

At present, there is a mechanism in place for banks to report all banking frauds to the Central Fraud Monitoring Cell of the Reserve Bank and the proposed dedicated registry will further enable this process.

The central bank said with the digital payment ecosystem making substantial progress in terms of growth of the payment infrastructure as well as volume and value of digital payment transactions, fraud risk monitoring and management by the stakeholders have assumed added importance.

"It has always been the endeavour of the RBI to improve the confidence of customers in the payment systems. To carry forward these efforts and ensure quick and systemic responses, it is proposed to facilitate the creation of a central payment fraud registry that will track these frauds,"
RBI said.

It also said payment system participants will be provided access to this registry for near-real time fraud monitoring.

The aggregated fraud data will be published to educate customers on emerging risks. The central bank will issue a detailed framework in this regard by end-October. PTI HV EN

iFraudAlert.org: To Help Protect Consumers from Internet Frauds

iFraudAlert.org: To Help Protect Consumers from Internet FraudsiFraudAlerts.org is a new initiative by National Cyber-Forensics & Training Alliance (NCFTA) and powered by Microsoft in alliance with leading public and private organizations such as Federal Trade Commission (FTC), Anti-Phishing Working Group (APWG), eBay/Paypal, American Bankers Association, Accuity and Citizens Bank.

Internet Fraud Alert (iFraudAlerts.org) will be providing an effective mechanism of a centralized alerting system which on one side will have participating experts/ researchers to report consumer identity theft, stolen account information discovered online such as username & password , login information for online services or compromised credit card numbers to the appropriate institution responsible for that account. Now this centralized alerting system (iFraudAlert) will quickly inform companies about compromised credentials which in turn help them to take the appropriate action to protect their customers stolen credentials or important private data.

As per APWG an Anti-Phishing Working Group phishing and malicious attack is all time high with more than 4,10,000 uniqiue phishing email reports. The iFraudAlert program will go into effect immediately today making a step forward in fighting online fraud and cybercrime.



Moreover in the shared interest of reducing online fraud and protecting consumers - any retailers, financial institutions, service providers, technology companies, academic researchers, consumer advocates and government agencies can become a partner of Internet Fraud Alert widen the group/ alliance of first of its kind centralized system to fight cybercribe and online ID theft.

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved