Ms. Aayushi Pardeshi, Ms. Rucha R. Galgali, Mr. Akshatsingh Pardeshi
Voice phishing (vishing) has evolved from social-engineering phone scams into technically assisted attacks, where victims install malicious Android apps that intercept calls, harvest contacts/messages, and redirect victims into fraudulent conversations. Since such malware needs a cluster of dangerous permissions, install-time and runtime permission patterns offer a behavioural signature for early detection—before call interception begins. This paper studies early-stage vishing detection via Android permission and API-call analysis, using a general Android malware/benign dataset (4,464 apps: 2,533 malware, 1,931 benign; 327 binary features) instead of a vishing-specific corpus. Point-biserial correlation identifies 157 significant features (p < 0.1), including vishing-relevant permissions like SYSTEM_ALERT_WINDOW, READ_PHONE_STATE, SEND_SMS, and RECEIVE_SMS. Among five classifiers tested, Logistic Regression performs best (96.75% accuracy, 97.13% F1), followed by linear SVM (95.97%, 96.42%) and Random Forest (95.86%, 96.35%). A model using only 15 vishing-relevant permissions still achieves 89.25% accuracy and 90.91% F1, showing strong discriminative power even without vishing-specific labels—supporting a lightweight, on-device early-warning approach and motivating future work with vishing-specific data.