The modern smartphone has become a digital extension of the individual, storing correspondence, banking data and confidential conversations. The question of how to find out whether a phone is tapped with an Android combination is becoming increasingly relevant for users who suspect an information leak. There are many myths about “magic codes”, but real verification requires a comprehensive approach to analyzing the system and network settings.
In this article we will look at technical methods for identifying hidden monitoring, including using USSD commands to check redirects, traffic analysis and searching for presence signs. spyware. It is important to understand that standard service codes do not always give the full picture, but are the first step in diagnosing the security of your device.
Many users confuse the legitimate functions of the operator with the actions of attackers. For example, a standard forward to voicemail may be mistaken for eavesdropping. We will look in detail at the differences between normal network operation and suspicious activity so that you can objectively assess the risks.
Using USSD codes to check redirects
The most accessible method of primary diagnosis is the use of special USSD requests. These codes let you know where your incoming calls, SMS, and data are routed when you're not picking up or are busy. If the settings contain a number different from the operator's voicemail number, this is a serious cause for concern.
To check, enter the command *#21# and press the call button. A table of forwarding statuses for various types of communication will appear on the screen. You need to carefully check the numbers provided with your operator's official voicemail number. Any discrepancy requires an immediate reset.
It is also useful to use the code ##002#. This command forces a reset of all forwarding on the device. After completing it, the system must confirm that all forwarding services are disabled. This action is safe and does not lead to the loss of personal data or contacts.
There is another diagnostic request - *#62#. It shows you where calls are routed when your phone is turned off or out of network coverage. Often, attackers or scammers set up forwarding to this particular trigger so as not to miss an important call while the owner of the device is unavailable.
⚠️ Attention: The interface for displaying the results of USSD requests may differ in depending on the smartphone model and manufacturer’s shell version (for example, MIUI, OneUI or EMUI). On some devices, the information may appear as a text message rather than a pop-up window.
Signs of spyware on Android
Secret tracking apps, known as stalkerware, often run in the background, consuming system resources. One of the first symptoms of infection is abnormally rapid battery drain. If your previously stable smartphone begins to discharge within half a day with moderate use, it is worth conducting a deep check.
Pay attention to the heating of the case. Even when the phone is idle, the active process of recording sound or transmitting data through the microphone and communication module causes the processor to heat up. This is a physical manifestation of the work of hidden algorithms that cannot be completely disguised.
The third sign is the strange behavior of the interface and system. Spontaneous screen turning on, delays when typing, unexpected reboots or the appearance of unknown icons in the tray may indicate a conflict between system processes and malware.
- 🔋 A sharp decrease in autonomy without changing usage habits.
- 🔥 Heating of the rear panel in standby mode.
- 📉 A noticeable drop in Internet connection speed.
- 📲 The appearance of advertising in system notifications.
Analysis of the list of applications and access rights
Spyware is often disguised as system processes or harmless utilities, such as “Flashlight”, “Calculator” or “System Update”. To identify the threat, you need to go to section Settings → Applications → All applications. Carefully study the full list, paying attention to applications without an icon or with a name consisting of a set of characters.
Pay special attention to access rights. Go to Settings → Privacy → Rights Manager (the path may differ on different versions of Android). Check which apps have access to your microphone, camera, and location. If a simple flashlight requires permission to record sound and access contacts, this is a clear sign of malware.
In some cases, malware is hidden in the “Accessibility” section. Attackers use these rights to intercept keyboard input and read screen content. Make sure that there are no suspicious services with enabled rights in this list.
☑️ Checking application security
It is important to note that some modern versions of Android, for example Android 12 and newer, have a built-in activity indicator. A green dot may light up in the top right corner of the screen when the microphone is in use, or an orange dot when the camera is being accessed. If you see these indicators when you are not using the corresponding functions, the system is clearly not working as it should.
Checking through the engineering menu and debugging
For more advanced users, access to the engineering menu is available through code ##4636##. This interface provides detailed phone usage statistics. Here you can see information about the latest activity and network status. However, be careful: changing settings in this menu without knowledge may result in loss of connection.
Another method is to check through USB debugging mode. If developer mode is enabled on the phone, an attacker could access data through ADB (Android Debug Bridge). Check if USB debugging is enabled in the menu For developers. In normal mode, this feature should be disabled.
If you find that developer mode is enabled without your knowledge, disable it immediately. It is also recommended to reset debugging permissions by clicking the “Revoke USB Debugging Permissions” button. This will break the potential connection with external devices that could be used to steal data.
What is ADB and why is it dangerous?
ADB (Android Debug Bridge) is a tool for developers that allows you to control your device from your computer. If an attacker has physical access to the phone and turns on debugging, he will be able to copy any data, install applications or run tracking scripts without the owner’s knowledge.
Monitoring network traffic and connections
Any wiretapping involves transferring data to a remote server. Even if they are just audio files of conversations, they must be sent over the Internet. A sharp increase in traffic consumption is one of the key indicators of leakage.
Check data usage statistics in the section Settings → Network and Internet → Data Usage. Sort applications by the amount of traffic spent. If an unknown application or system process with an unclear name consumes gigabytes of traffic in the background, this requires immediate investigation.
For in-depth analysis, you can use specialized firewall applications, such as NetGuard or GlassWire. They allow you to see in real time which IP addresses your phone is visiting. Suspicious connections to servers in countries where you have no contacts or interests may be a sign of a C&C server (Command and Control).
| Parameter | Normal state | Suspicious sign |
|---|---|---|
| Battery consumption in the background | Less than 5% per hour | More than 15% without active tasks |
| Data traffic | Stable, predictable | Sharp surges at night |
| Case temperature | Room or slightly warm | Hot in standby mode |
| Response time | Instant | Dialing delays numbers |
Radical protection measures and reset
If software verification methods have confirmed your suspicions, but the threat cannot be removed, the last reliable method remains - a full reset to factory settings (Hard Reset). This procedure deletes all data, applications and settings, returning the phone to its “out of the box” state.
Before performing a reset, be sure to save important contacts and photos to external storage or to the cloud, but do not make a full backup of the system, as the virus may be preserved in the archive and return after recovery. After the reset, install applications only from the official store Google Play.
In extreme cases, when there is a suspicion of bootkit infection, it may be necessary to flash the device using official utilities from the manufacturer, such as Odin for Samsung or SP Flash Tool for MediaTek. This is a complex procedure that requires technical skills.
Wipe Data/Factory Reset is the only way to ensure that complex forms of spyware have been removed from your system.
⚠️ Attention: Before performing a hard reset, make sure you remember your Google account information. After the reset, the system will require authorization in the account that was the main one on the device (FRP protection). Without a password, the phone will turn into a “brick.”
Frequently asked questions (FAQ)
Can the phone be tapped when it is turned off?
Technically, a standard smartphone cannot transmit data or sound if it is completely turned off by software, since the radio module does not receive power. However, there are complex hardware bookmarks that can activate a phone remotely, but this is at the level of special services, not everyday espionage. In 99% of cases, a switched off phone is safe.
Is it true that the code *#90# turns on wiretapping?
No, this is a common myth. The code *#90# is not a standard Android service code for enabling wiretapping. In different regions and with different operators, codes may have different purposes, but there is no universal “wiretapping button” via USSD. Most often, such codes either do nothing or show the forwarding status.
How to protect yourself from wiretapping via instant messengers?
Use messengers with end-to-end encryption (End-to-End), such as Signal or secret chats in Telegram. Regularly check the list of active sessions in the application settings and terminate any unfamiliar devices. Also enable two-factor authentication.
Does the Android version affect the likelihood of hacking?
Yes, directly. Older versions of Android (below 9.0) do not receive security updates and contain many known vulnerabilities that are easy to exploit. The current version of the OS with the latest security patches significantly reduces the risk of automatic infection through exploits.