payment apps

AppWizard
May 9, 2026
Cybersecurity researchers from ESET have discovered 28 fraudulent applications on the Google Play Store that falsely claimed to provide access to call histories for any phone number. These apps have been downloaded over 7.3 million times, with one app alone accounting for over 3 million downloads. The operation, named CallPhantom, primarily targeted Android users in India and the Asia-Pacific region. Users were lured into subscription services, paying for access to fictitious data, including call histories and SMS records, but received only randomly generated information. Some apps were published under the developer name "Indian gov.in" to create a false sense of trust. Payments were processed through the Google Play Store or third-party applications like Google Pay and Paytm. Users who subscribed via Google Play may be eligible for refunds, while those who used third-party payment methods may not be able to recover their funds. The fraudulent activity may have been ongoing since at least November 2025.
AppWizard
September 24, 2025
A financially motivated cybercrime group has been targeting Android users in Indonesia and Vietnam by deploying banking trojans disguised as legitimate government applications. They spoof Google Play Store and App Store interfaces to deliver malicious APKs through obfuscated WebSocket connections, evading traditional security measures. Analysis of over 100 malicious domains shows they use Alibaba ISP, Gname.com for domain registration, and share-dns.net nameservers, with rapid DNS resolutions occurring within about 10.5 hours during peak daytime hours in Eastern Asia. The group's delivery mechanism utilizes the Socket.IO library for real-time WebSocket connections, allowing them to stream malicious APKs in small chunks. The downloaded file, often named IdentitasKependudukanDigital.apk, installs a variant of the BankBot trojan family. Some simpler spoofed sites offer direct download links with mixed language code strings, indicating the use of multilingual templates. Domain registration data from August 2024 to September 2025 shows these threat actors frequently reuse TLS certificates and cluster spoofed sites on identical IP addresses, primarily hosted via Alibaba and Scloud. These domains share server titles and operate on Nginx, with first-seen DNS queries typically lagging 10.5 hours behind registration times. Infections communicate with command and control domains, highlighting a coordinated infrastructure. The campaign emphasizes the need for behavioral detection and real-time traffic inspection to identify anomalous WebSocket file transfers.
AppWizard
July 29, 2025
Cash App has introduced a new feature called Pools, designed to facilitate group payments for shared expenses. Users can invite others, including those using Google Pay or Apple Pay, to contribute to a pool for expenses like vacations or gifts. Organizers can name the pool, set a target amount, and once the goal is reached, they can close the pool and transfer the funds. The feature is currently being rolled out to a select group of users, with plans for wider availability soon.
Search