Have you noticed that your phone battery has begun to discharge suspiciously quickly, and Internet traffic is โleakingโ even when you are not using the gadget? Or maybe the smartphone spontaneously turns on the microphone, camera, and unknown device administrators appear in the settings? These symptoms are a reason to be wary. Modern Android devices are vulnerable to spying attacks, and attackers can track your calls, messages, location and even control your phone remotely.
In this article we will analyze 15 key signs of surveillance via Android, learn how to identify hidden threats using built-in and third-party tools applications, and also tell you how completely wipe the device from spyware. We will pay special attention methods of disguising surveillance as legitimate processes โeven experienced users often miss them. If you suspect that you are being followed, act systematically: from analyzing network activity to checking physical access to the phone.
1. The main signs of surveillance via Android
Spyware rarely gives out its presence with obvious signals, but there are indirect signsthat should alert you. They can be divided into three categories: hardware (phone behavior), software (changes in the system) and network (suspicious activity). Let's look at the most common ones.
- ๐ Rapid battery drain - spyware works in the background, constantly transmitting data (location, call recordings, screenshots). If the phone discharges after 4-5 hours without active use, this is an alarming sign.
- ๐ก Increased traffic consumption - check the statistics in
Settings โ Network and Internet โ Data usage. Unknown applications that consume gigabytes per month can be spies. - ๐ค Spontaneous activation of the microphone/camera โ if the camera indicator lights up without your participation or appears in the list of active processes
android.media.MediaRecorder, this may indicate wiretapping. - ๐ฑ Unusual behavior of the phone โrandom reboots, screen backlighting in sleep mode, slow operation for no reason. Viruses are often disguised as system processes, for example
com.android.system.
It is especially dangerous if these symptoms appear after physical access to the phone of third parties (for example, repairs at a service center, temporary transfer of the device to a colleague). Spyware like FlexiSPY or mSpy is installed in 5-10 minutes and can remain undetected for years.
2. How to check your phone for spyware
If you have found at least 2-3 signs from the previous section, proceed to deep diagnostics. Let's start with the built-in Android tools, then move on to third-party utilities. Important: do not delete suspicious files immediately โfirst make a backup copy of your data (for example, via adb backup) so as not to lose evidence of surveillance.
2.1. Checking through Android settings
- ๐ List of applications: Go to
Settings โ Applications โ All applicationsand sort by installation date. Pay attention to apps with names like System Update, Device Test or Service โthese are common โmasksโ for spies. - ๐ก๏ธ Device Administrators: There should be no unknown services. If you see
Settings โ Security โ Device Administratorsthere should be no unknown services. If you saw Device Admin or Enterprise Policy โdisable them! - ๐ก Application permissions: B
Settings โ Applications โ PermissionsCheck which apps have access to microphone, camera, geolocation i SMS. For example, the messenger should not request access to your contacts after installation.
Pay attention to applications with empty icons or names in Chinese/Korean - these may be APK spiesinstalled manually. Also check the folder /system/app through the file manager (for example, Solid Explorer): there should be no files with the modification date after purchase telephone.
2.2. Specialized anti-spyware utilities
The built-in Android tools do not always detect advanced spyware. For a deep scan, use:
| Application | What you are looking for | Free version | Link (Play Market) |
|---|---|---|---|
| Malwarebytes | Spyware, keyloggers, Trojans | Yes (with restrictions) | Available in the official store |
| CertiK OS | Hidden administrators, kernel vulnerabilities | No (paid) | Requires root access |
| Kaspersky Mobile | Network attacks, phishing, spyware | Yes (basic scan) | Supports real-time scanning |
| Hidden Device Admin Detector | Hidden device administrators | Yes | Does not require root |
Before scanning turn off the Internet โsome spyware can masquerade as legitimate processes if they see antivirus activity. Also check your phone in safe mode (press the power button โ โSafe Modeโ). If the phone works fine in this mode, the problem is definitely in third-party software.
โ๏ธ Checklist for checking for spyware
3. Analysis of network activity: who is connecting to your phone
Spyware often transfers data to remote servers. To identify such connections, use traffic analyzers i firewalls. Let's start with simple methods:
- ๐ Checking active connections: Install NetGuard or PCAPdroid (requires root for full access). These applications show which apps are transferring data and where.
- ๐ DNS query analysis: Use DNS66 or Blokadato block suspicious domains. Spies often contact servers like
spyserver[.]netortrack[.]me. - ๐ Checking ports: Enter in the terminal (via Termux):
netstat -tulnIf you see open ports
4444,5555or7777- this is a sign of remote access (for example, through Metasploit).
Pay special attention SMS commands. Some spies are activated via SMS with a certain text (for example, *123#ON). Check your message history on presence of unknown short numbers or commands. Also study the call log: if there are outgoing calls to numbers with prefixes +375, +380 or +1 (without your knowledge), this may be a tracker signal.
If you have detected a suspicious IP address in traffic logs, check it through the service VirusTotal or AbuseIPDB. Enter the IP in the browser search bar adding the word "scam" or "spyware".
4. Physical check of the phone: what to look for.
Not all surveillance methods are software based. Attackers can use hardware bookmarkswhich are difficult to detect without disassembling the device. Here's what to pay attention to:
- ๐ Suspicious cables and chargers โsome devices (for example, O.MG Cable) look like a regular USB cable, but transmit data to the attacker's server when connected. Check the cable for additional chips.
- ๐ฑ External stickers or damage to the case - spy modules can be hidden under the battery or in the SIM card slot. Inspect the phone for extraneous wires or non-standard holes.
- ๐ง Non-original headphones or cases โsome accessories contain built-in microphones or GPS trackers. For example, cases with an additional battery can hide the tracking module.
If you suspect hardware bookmark, the most reliable way is complete disassembly of the phone at a service center. However, even this does not provide a 100% guarantee: modern spy chips (for example NSAโs COTTONMOUTH) can be the size of a grain of sand and soldered into the motherboard. In such cases, the only way out is replacement of the device.
How to check the charger for the presence of a spy chip?
Connect the charger to another phone and check network activity via Fing or Wireshark. If the charger transmits data (for example, MAC address or IMEI), this is a sign of a bookmark. Also inspect the USB plug: in spy devices you can often see additional contacts or microcircuits.
5. How to remove spyware from Android
If you find surveillance, act immediately. Removing spyware depends on its type:
5.1. Removing spyware
- Disable the Internet (airplane mode) - this will prevent the transfer of data to the attacker.
- Remove suspicious applications via
Settings โ Applications. If the โDeleteโ button is inactive, first remove administrator rights inSettings โ Security. - Clear the cache and data for all browsers and instant messengers - spyware is common hide in the cache Chrome or Telegram.
- Reset to factory settings (
Settings โ System โ Reset settings). This will remove all data, including spyware, but will not helpif malware is embedded in the firmware.
5.2. Treatment of infected firmware
If the spy is built into system files (for example, via custom ROM), a normal reset will not help. In this case:
- ๐ Reflash the phone official firmware via Odin (for Samsung), Fastboot (for Google Pixel) or SP Flash Tool (for MediaTek). Download firmware only from the official website manufacturer!
- ๐ Install custom software like LineageOS or GrapheneOS - they are devoid of backdoors and have enhanced protection.
- ๐ก๏ธ Disable USB debugging (
Settings โ For developers) and enable lock bootloader (bootloader lock).
After flashing do not restore data from a backup copy - the spyware could have been saved in the backup. Set up your phone as new and install applications only from Google Play (checking reviews and permissions).
If spyware appears again after resetting the settings, this is a sign hardware bookmark or hacking at the bootloader level. In this case, the only way out is to replace the phone.
6. How to protect Android from surveillance in the future
Even after wiping your phone, the risk of repeated surveillance remains. To minimize threats, follow these rules:
- ๐ Use strong passwords โat least 12 characters with letters, numbers and special characters. To unlock your phone, set up biometrics + PIN (not just a fingerprint!).
- ๐ฒ Disable unnecessary permissions โ in
Settings โ Applications โ Permissionsdeny access k geolocation, microphone i camera for all applications except instant messengers and navigator. - ๐ Use VPN โ ProtonVPN or Mullvad encrypt traffic and hide your IP. Configure VPN at the system level, and not just in the browser.
- ๐ Update the software regularly โmanufacturers are closing vulnerabilities in new versions of Android. Enable automatic updating in
Settings โ System โ System update. - ๐ซ Do not install APKs from unknown sources โeven if the file was sent by a friend. Check the hash sums (SHA-256) of downloaded files.
For additional protection, install Firewall application (for example, AFWall+) and configure the rules blocking for all applications except system ones. Also consider using of a second phone for sensitive operations (banking, correspondence) - this will complicate the task for attackers.
If you often connect to public Wi-Fi, disable the function Auto-connect to networks in the settings. Attackers can create a fake network with the name Free_WiFi or Starbucks and intercept your traffic.
7. What to do if surveillance was organized by a loved one
The situation becomes more complicated if you are being watched spouse, employer or relative. In this case, it is important to act carefully so as not to provoke a conflict. Here is the algorithm:
- Gather evidence โtake screenshots of suspicious applications, traffic logs and permissions. This will come in handy if the case comes to court or proceedings.
- Donโt accuse directly โinstead of the phrase โI know youโre following me,โ use a neutral wording: โMy phone is acting strange, letโs check it together.โ
- Contact a mediator โif the surveillance was organized by a partner, offer to discuss the problem with a psychologist or lawyer. In some countries (for example, in the EU), unauthorized surveillance is punishable by law.
- Change device - if a conflict is inevitable, switch to a new phone with enhanced protection (for example, Google Pixel c Titan M or Fairphone with open software).
Remember: even if surveillance is organized โwith the best intentionsโ (for example, parents are watching their child), it is violation of personal boundaries. An adult has the right to privacy, and any surveillance must be carried out with his consent.
โ ๏ธ Attention! In some countries (Russia, China, UAE), the use of spyware may be legal under certain conditions (for example, employer spying on a corporate phone). Check local laws before taking action.
FAQ: Frequently asked questions about tracking via Android
Can a phone be tracked if it is turned off?
Yes, but only if:
- Phone is not completely turned off, but is in deep sleep mode (for example, in some models Xiaomi or Samsung background processes continue to run).
- Into the device built-in hardware tracker (for example, a chip in the battery or SIM card).
- The attacker uses vulnerability in the bootloader, which allows you to turn on the phone remotely (rarely, but possible on older models).
To completely eliminate surveillance, remove the SIM card and battery (if possible) or place the phone in Faraday bag.
How to check if my calls are being monitored?
Signs of calls being monitored:
- ๐ Interference or echo during a call.
- ๐ Calls are interrupted or redirected to unknown numbers.
- ๐ The battery runs out during calls (wiretapping consumes additional energy).
To check:
- Dial during a call
*#21#โthis will show whether forwarding is enabled. - Use the app Call Recorder to record calls and listen to background noise.
- Check your call log for unknown short calls (for example, 1-2 seconds long).
Can a virus track me through WhatsApp or Telegram?
Yes, but not directly. Spyware can:
- ๐ฅ Intercept messages via Accessibility Service (if you have given permission to an unknown application).
- ๐ Read notifications โmany spies read the text of notifications, even if the messenger is blocked.
- ๐ Steal media files โphotos and videos from chats can be automatically uploaded to the attacker's server.
Protection:
- Disable preview notifications in messenger settings.
- Use secret chats in Telegram (they are not saved in the cloud).
- Enable two-factor authentication in WhatsApp (
Settings โ Account โ Two-step verification).
How to find out who is following me phone?
It is difficult to identify a specific person, but you can narrow down the circle of suspects:
- Check physical access โ who took your phone in their hands over the last 2-3 weeks?
- Analyze network activity โ if traffic flows to an IP address belonging to a friend (can be checked via WHOIS), this is suspicious.
- Look for "digital footprints" โsome spyware (for example, Cerberus) are tied to the installerโs email or phone number. Check the authorization logs in
Settings โ Google โ Account Management โ Security.
If you suspect a specific person, don't deal with him directly gather evidence and contact a cybersecurity specialist.
Does changing the SIM card help against surveillance?
Partially. Changing the SIM card:
- โ Interrupts surveillance via a mobile network (if the spy was tracking your number).
- โ Does not helpif:
- Spyware is installed on the phone (it will use Wi-Fi or new SIM data).
- Spying is carried out via IMEI or MAC address (they cannot be changed without flashing).
- Used hardware tab (for example, in the battery).
For complete protection after changing SIM:
- Reset the phone to factory settings.
- Use virtual number (for example, via Google Voice) to register in instant messengers.
- Disable automatic registration in networks (
Settings โ Mobile network โ Auto search).