Modern smartphones store a colossal amount of personal information, from correspondence in instant messengers to banking data, which makes them an attractive target for attackers or ill-wishers. Many users wonder how to find out that you are being tapped on a phone using Android combinations, but the reality is often more complex than myths about magic codes. Technical expertise shows that classic USSD commands can only partially shed light on the status of call forwarding, but are not capable of detecting complex spyware running in the background of the operating system.
The true threat of wiretapping most often does not come from intelligence services using access to towers cellular communications, but from malicious software installed on the device itself. Such software can silently activate the microphone, take screenshots of the screen, or forward call history to third parties without the owner’s knowledge. Understanding the difference between intercepting a signal at the operator level and installing Trojan on a gadget is the first step to the real security of your digital space.
In this article we will analyze in detail legal methods of device self-diagnosis, analyze the operation of system codes and consider behavioral signs indicating the presence of hidden surveillance. It is important to approach the issue comprehensively, without relying solely on mythical combinations of numbers that supposedly instantly clear the phone of viruses.
Myths and reality of USSD combinations for security checks
There is a widespread belief on the Internet that there is a universal secret code, entering which into the dialer will immediately show a list of all listening devices or will remove viruses. This is a dangerous misconception, since Android is an open system with thousands of different modifications from manufacturers, and there is no single standard for such checks. Most of the so-called “wiretapping codes” are actually standard commands for requesting call forwarding status, incorporated into the GSM standard decades ago.
However, checking the forwarding settings remains an important step in the initial diagnosis, since attackers often use legitimate network functions to redirect your calls to their number. The combination *#21# allows you to display the status of conditional and unconditional forwarding for voice calls, SMS and data. If you see an unknown number in the forwarding field, this is a clear signal that someone is receiving copies of your incoming events.
Another useful combination ##002# serves to completely cancel all types of forwarding set at the telecom operator level. Entering this code and pressing the call button resets the call forwarding settings to their original state, which can be an effective countermeasure against simple interception methods. However, it is worth understanding that this command does not affect the software already installed inside your smartphone.
⚠️ Warning: Do not enter random combinations of characters into the dialer found on dubious forums. Some codes can trigger a network reset or, in rare cases on older devices, a factory reset without warning.
There is also a code *#62#that shows the number to which calls are forwarded when your phone is turned off or out of network coverage. Often your operator's voicemail number is indicated there, which is the norm, but the appearance of an unfamiliar mobile number should alert you. Regularly checking these parameters helps control the routing of your voice traffic.
Hidden menus and Android engineering mode
For deeper diagnostics, specialists use hidden service menus, which are accessed through special codes that depend on the processor and device model. On smartphones with processors MediaTek the combination ##3646633##often works, which opens the engineering menu with advanced settings for the radio module. In this section, you can check signal levels, antenna status and connection logs, which can indirectly indicate anomalies in the network.
For processor-based devices Qualcomm there is a specific set of commands, for example ##4636##that opens the testing menu. The "Phone Information" section is available here, where details about the network, connection type and packet statistics are displayed. An experienced user may notice uncharacteristic data transfer activity, even when the screen is turned off and you are not using the Internet, which often indicates the work of background spyware.
It is important to note that on modern versions Android (starting from version 10 and higher), access to many engineering functions is limited by manufacturers for security reasons. An attempt to enter such menus on new flagships may not yield results or require special access rights that are difficult for an ordinary user to obtain. However, checking basic statistics in the available menus remains a useful practice.
Danger of the engineering mode
Changing settings in the engineering menu without understanding their purpose can lead to loss of communication, inoperability of Wi-Fi or Bluetooth modules, and in the worst case, to the need to reflash the device in a service center.
If you find that Connection logs show suspicious IP addresses or constant data transfer activity at a time when the phone should be “sleeping”, this is a reason for a more thorough check of installed applications. The engineering menu will not directly say “you are being wiretapped,” but will provide technical data that will indirectly indicate the problem.
Behavioral signs of the presence of spyware
Often the most reliable indicator of the presence of wiretapping is not the code in the dialer, but a change in the behavior of the smartphone itself. Malicious apps designed to intercept audio or data consume device resources, which inevitably affects its performance. If your phone, which previously worked reliably, suddenly began to discharge quickly, overheat in standby mode, or reboot on its own, these are alarming symptoms.
Pay attention to the consumption of mobile traffic: spyware must transfer recorded conversations or screenshots to a remote server, which creates an abnormal surge in Internet consumption. You can check this in the settings by going to the Settings → Connections → Data usagesection, where sorting applications by traffic volume will help identify suspicious processes. Often such apps are disguised as system services or have names similar to legitimate processes, for example System Update or Wi-Fi Service.
The next sign may be strange behavior of the interface: spontaneous turning on of the screen, delay when typing, appearance of unknown icons in the panel notifications or pop-up advertisements. Some advanced Trojans can turn off the camera shutter sound or the recording indicator, but cannot completely hide the load on the processor and battery.
- 🔋 Rapid battery drain even with minimal screen use and no heavy games.
- 📶 Interference, clicks or echoes during normal phone calls that are not related to call quality operator.
- 📲 Long shutdown of the phone or heating of the case in the upper part (where the processor is located) in rest mode.
- 💾 The appearance of unknown files in download folders or strange activity of the drive operation indicator.
⚠️ Attention: A single manifestation of one of these Symptoms may be due to battery wear or a specific application malfunction. The alarm should only be sounded if several signs are combined.
It is also worth analyzing the list of installed applications for apps with excessive access rights. If a simple flashlight or calculator asks for permission to access your microphone, contacts and geolocation, this is a clear sign of the malicious nature of the software. In modern versions Android the system notifies you of access to the microphone or camera with a green indicator in the corner of the screen, the appearance of which without your knowledge requires an immediate response.
☑️ Diagnosis of suspicious activity
Analysis of access rights and device manager
One of the most effective ways to detect hidden wiretapping is a thorough audit of the access rights granted to installed applications. Go to the menu Settings → Privacy → Permission Manager and sequentially check the categories “Microphone”, “Camera” and “Access to phone calls”. Any application that is not a voice recorder, messenger or dialer, but has access to these functions, should be removed immediately.
Particular attention should be paid to the "Accessibility" section, which is often used by malware to gain complete control over the device. This menu lists services that can read screen content, track keystrokes, and simulate user actions. If you see an unknown application or service with a suspicious name here, disable it and uninstall the corresponding app.
Also check the list of device administrators in the section Settings → Security → Device administrator applications. Spyware often requests these rights to prevent the user from removing them easily. The presence of an unknown element in this list is a sure sign of security compromise, requiring immediate revocation of rights and uninstallation.
| Permission type | Legitimate use | Suspicious sign | Action |
|---|---|---|---|
| Microphone | Messengers, voice recorder, voice search | Flashlight, calculator, wallpaper | Disable and delete |
| Accessibility features | Screen readers, password managers | Any other utilities | Disable service |
| Device administrator | Antiviruses, corporate profiles | Unknown services | Revoke rights |
| Installing applications | Browsers, stores applications | Games, players | Deny access |
Modern versions Android allow you to view the permission usage log for the last 24 hours. This feature helps you identify apps that were accessing your microphone or camera when you weren't using them. Regularly auditing this log becomes an important habit for maintaining digital hygiene.
Use the Privacy Dashboard feature in Android 12 and above: it collects all the important privacy switches in one place and shows a timeline of sensor activity.
Pro protections and scanning
When Manual checks are not enough; specialized antivirus solutions and malware scanners come to the rescue. Unlike the standard one, which works at a basic level, third-party products from companies like Google Play Protect, which works at a basic level, third party products from companies like Kaspersky, ESET or Dr.Web use more aggressive heuristic algorithms to search for spyware Trojans. Installing such software and running a full system scan can reveal hidden threats masquerading as legitimate processes.
There are also highly specialized anti-spyware detection utilities that focus specifically on finding surveillance apps rather than classic viruses. These applications check for known spyware signatures, such as Pegasus, FlexiSPY or their cheaper analogues, often distributed bypassing official application stores.
In such cases, the only reliable method is a complete reset of the device to factory settings with preliminary formatting of the internal drive. This is guaranteed to delete any app bookmarks, but will require restoring data from a backup.
⚠️ Attention: Settings interfaces and menu item names may differ depending on the version of Android and the manufacturer’s shell (Samsung One UI, Xiaomi MIUI, etc.). Always check the official reference materials for your specific model.
Comprehensive protection is not built on one magic code, but on a combination of checking access rights, analyzing system behavior and using specialized anti-virus software.
Radical measures: resetting and protecting data
If you find irrefutable evidence wiretapping or simply have serious suspicions that cannot be confirmed or refuted, the most reasonable step would be a complete data reset. Before this procedure, you need to create a backup copy of only the most important files (photos, contacts, documents), but under no circumstances save a backup copy of the applications themselves, as you can also restore infected files.
The procedure is performed through the menu Settings → System → Reset settings → Delete all data. Make sure that you choose to format the internal storage to eliminate all traces of intruders. After the reset, the phone will return to its “out of the box” state, and you will have to re-configure accounts and install applications from trusted sources.
To prevent future attacks, it is recommended to change all passwords for important services (mail, social networks, banks) from another, known clean device. Enabling two-factor authentication wherever possible will create an additional barrier to unauthorized access, even if attackers somehow obtain your credentials.
Be careful when installing applications from unknown sources and do not click on suspicious links in SMS or instant messengers. Most cases of spyware installation occur precisely because of the carelessness of users who download hacked versions of games or apps under the guise of useful utilities. The only guaranteed way to avoid wiretapping through an application is to install software exclusively from the official Google Play store.
What to do after the reset?
After returning to factory settings immediately Install a reliable antivirus and update the operating system to the latest available version to close security vulnerabilities.
Frequently asked questions (FAQ)
Does the *#21# code really show whether the phone is being tapped?
No, this code only shows the settings for call forwarding, SMS and data. It cannot detect spyware that records conversations or ambient sound directly from the device. If forwarding is disabled, this does not guarantee the absence of wiretapping through malware.
Can a phone be wiretapped without the Internet?
Technically, audio recording is possible without the Internet, but transferring data to an attacker is impossible. Entries will be accumulated on the device and sent as soon as a network connection is available. However, intercepting a cellular signal (GSM) is possible without the participation of the phone itself, but this requires expensive equipment and access from special services.
How to remove a virus if it is not removed in the usual way?
If the application is not removed, most likely it has received device administrator rights. Go to the security settings, find the "Device Administrator Applications" section, uncheck the suspicious app, and only then try to remove it again. In difficult cases, only resetting to factory settings will help.
Is it safe to enter secret codes on your phone?
Most standard USSD codes (for example, for checking a balance or forwarding) are safe. However, entering little-known engineering codes found on the Internet can cause network settings to fail or data loss to occur. Use only proven combinations described in the official documentation.
Does the green indicator in the corner of the screen show wiretapping?
The green indicator (dot) in Android 12 and newer lights up when any application uses the microphone or camera. If you see it when you're not using these features, it means an app is actively recording audio or video. This is a reason to check the permission usage log and identify the violator.