The fear of total surveillance has ceased to be a plot for Hollywood thrillers and has become an everyday reality for millions of smartphone users. Owners of devices based on Android often wonder whether their gadget has turned into a pocket listening device. The spyware industry is developing rapidly, offering attackers tools that can intercept calls, messages and even turn on the camera without the owner’s knowledge. However, panic rarely helps solve the problem, while competent technical analysis can identify the threat.

There is a widespread belief that special combinations of numbers can instantly indicate the presence of wiretapping. This is partly true, but the reality is much more complex. The operating system Android provides access to engineering menus and redirection statistics, but modern viruses have learned to camouflage themselves from standard scans. To get a complete picture of the security of your device, you need to combine checking through USSD codes with analysis of system behavior and the use of specialized software.

In this article we will analyze in detail which codes need to be entered into the dialer, what the results mean and how to distinguish a real threat from false positives of the system. We will also look at signs that cannot be seen in digital codes, but which clearly indicate third-party interference in the operation of your smartphone.

Myths and reality of USSD codes for security checks

The Internet is filled with lists of “magic” codes that supposedly guarantee the detection of any spy. Users enter long sequences of characters, hoping to see a red message that says “Your phone is being tapped.” Unfortunately, mobile security works differently. Most of these codes are designed to check the settings of the telecom operator, and not to scan the file system for Trojans.

However, they cannot be ignored. These combinations allow you to identify a classic type of interception - call forwarding. If an attacker has configured your incoming calls to be redirected to his number, you may not notice this until you check the service status through the service code. This is the basic level of protection that everyone should go through.

⚠️ Attention: Number combinations only work if you have a SIM card and network coverage. In airplane mode or when there is no signal, the forwarding test is not possible.

It is important to understand the difference between system settings and malware. The codes will show where your calls are going, but they won't see the spy app, which simply copies your SMS to the cloud without affecting your phone book or call settings. Therefore, take this data as the first line of defense, and not as a final verdict.

📊 Have you noticed strange behavior of the phone?
Yes, the battery runs out quickly
Yes, the screen turns on itself
No, everything works fine
There were strange sounds in the handset

Basic combinations of numbers to check forwarding

The most accessible and fastest method of initial diagnosis is the use of universal USSD requests. These commands are sent directly to the carrier's server, bypassing most installed applications. This makes them a reliable tool for checking your voice settings.

Enter the following code in the Phone app and press the call button:

*#21#

This prompt shows the forward unconditional status. If a message appears on the screen stating that forwarding is disabled (or the status is “Not forwarding”), this is a good sign. However, if you see an unfamiliar phone number that your calls are being sent to, this is a red flag. In some cases, the operator's voicemail number may be displayed there, which is the norm, but any personal number should raise suspicion.

For a more detailed check, use the code:

*#62#

It displays forwarding settings in case your phone is turned off or is out of network coverage. Often scammers or jealous partners set up forwarding to this exact scenario so as not to miss an important conversation when you are “unavailable”. Compare the number displayed with your operator's official voicemail number.

It's also worth checking the code to cancel all forwarding if you detect suspicious activity:

##002#

This combination resets all forwarding settings to default values. This action is safe and will not delete your contacts or files, but will instantly break the connection with the interceptor number if forwarding was configured through the operator's network.

💡

After entering the code ##002#, wait for a confirmation message from the operator on the screen. If the message does not appear, the code may not have worked due to tariff plan or roaming restrictions.

Engineering menu and hidden Android settings

In addition to operator codes, the system Android there are hidden menus for developers and engineers. They can also be accessed through special combinations in the dialer. These sections contain technical information about the status of the radio module, battery and network usage.

One ​​of the most famous combinations is:

##4636##

Entering this code usually opens the Test menu. Here you can find the Usage Statistics section, which shows how long the device was running, when it was last turned on, and when the network was used. If you see that the phone is “active” while it was turned off or in airplane mode, this may indicate a hidden process is running.

However, on modern smartphones from brands such as Samsung, Xiaomi or Huawei, this code is often blocked by the manufacturer. In this case, the system simply ignores the input or opens standard dialing. This doesn't mean the phone is infected; this means that the manufacturer has limited access to debugging information for ordinary users.

In the engineering menu, you should also pay attention to the network information. If the network type is constantly changing for no apparent reason or the signal level behaves abnormally, this may indirectly indicate interference in the operation of the radio part, although most often these are coverage problems.

What to do if the code does not work?

If the combination ##4636## does not open the menu, try downloading the “Code Secret OS” application or similar from Google Play. Such utilities collect service codes available for your model in one place, but remember that they do not provide privileges beyond those available in the system.

Indirect signs of the presence of spyware

Professional spyware (stalkerware) often bypasses checks through USSD codes, since it works at the application level, and not the operator’s network settings. In this case, the physical signs of unstable operation of the device come to the fore. Malware they consume resources, and it is almost impossible to completely hide it.

Pay attention to the following symptoms that should alert you:

  • 🔋 Abnormal battery discharge: If a phone that previously held a charge for a day and a half is now running low in 4-5 hours with the same usage scenario, a process transmitting data can be running in the background.
  • 🌡️ Case heating: Is the smartphone hot to the touch even in standby mode? This is a sure sign that the processor is actively loaded with hidden tasks, for example, recording audio or sending files.
  • 📶 Increasing traffic: Check data transfer statistics. If an unknown application or system process was using up gigabytes of internet while you were sleeping, this is a clear red flag.
  • 📢 Strange sounds when calls: Clicks, static noise, echoes or delays in conversation may indicate that the line is being used to record or connect a third listener.

Do not discount the strange behavior of the interface. Spontaneous reboots, the screen turning on in the dark, camera flashes without launching the application - all these are signs that someone is remotely controlling your device. It is especially dangerous if the phone is turned on or off for a long time, since at these moments hidden services are often activated.

⚠️ Attention: One single symptom (for example, heating) may be the result of poor network coverage or an outdated battery. The alarm should only be sounded if several signs are combined.

Analysis of installed applications and access rights

The most effective method of detecting a bug is a manual audit of installed apps. Spyware is often disguised as system utilities with names like “System Update,” “Wi-Fi Service,” or “Android Core.” However, they do not have an icon in the application menu, or it is hidden.

To check, follow these steps:

Settings → Applications → Show system processes

Carefully study the list. Look for apps without an icon, with suspicious names, or ones you didn't install. Pay special attention to access rights. Go to the privacy settings and check the rights manager.

Critical permissions that simple utilities should not have:

  • 🎤 Microphone: Only messengers, voice recorder and phone should have access to the microphone. If “Calculator” or “Flashlight” has it, delete it immediately.
  • 📹 Camera: Any application that can secretly take photos is a threat.
  • 📍 Geolocation: Constant access to a location in the background for unnecessary applications is a sign of surveillance.
  • 🔐 Special features: This is the most dangerous item. In the menu Special. capabilities check to see if a suspicious service is activated there. It is through this mechanism that Trojans gain full control over the screen and text input.

☑️ Smartphone security audit

Completed: 0 / 4

If you find a suspicious application, but the “Delete” button is inactive, it means that it has received device administrator rights. To remove it, you must first revoke these rights in the section Settings → Security → Device Administrators.

Table of comparison of wiretapping detection methods

Different verification methods have different effectiveness depending on the type of threat. Below is a summary table that will help you choose the right diagnostic tool.

Verification method What is detected Efficiency Complexity
USSD codes (#21#, #62#) Call forwarding through the operator High (for calls) Low
Engineering menu (##4636##) Use and network statistics Average Medium
Audit of applications and rights Hidden spyware High High
Anti-virus scanners Known virus databases Medium (depending on the database) Low
Reset to factory settings Any Software (except for hardware bookmarks) Maximum High (data loss)

As you can see from the table, there is no universal solution. A combination of numbers is useful for quickly checking communication settings, but in-depth analysis requires manual control of applications. If you suspect a complex targeted attack, no codes will help. a complete reset of the device will be required.

💡

Resetting to factory settings (Hard Reset) is the only way to guarantee the removal of 99% of software bookmarks, but before that, be sure to save important data to an external storage device.

What to do if the fact of wiretapping is confirmed

Detecting signs of surveillance is a stressful situation that requires If you are convinced that your phone is being tapped, do not try to delete suspicious files one by one. Modern Trojans have self-healing mechanisms and can block the device when you try to delete it.

The first step should be to change all passwords from another deviceIf you start changing passwords on an infected one! phone, the keylogger will instantly intercept new data. Change passwords for your Google account, social networks and banking applications on a computer or someone else’s smartphone.

Then do a full reset of the settings, but use the “Return to factory settings” function through the Recovery Mode if you suspect it has been received. root access by an attacker. After the reset, do not restore the data from the old backup, as the virus could get there too. Set up the phone as new.

⚠️ Attention: If you think that you are in real physical danger from a stalker or a criminal group, do not turn on the phone immediately after the reset.

After cleaning your device, install a reliable antivirus from a reputable vendor, such as Kaspersky, Dr.Web or ESETUpdate your operating system regularly, as security updates close vulnerabilities that hackers exploit.

💡

For maximum security in the future, disable the installation of applications from unknown sources in the Android settings. This will prevent accidental installation of spyware through phishing links.

Can the police wiretap a phone without installing apps?

Yes, intelligence agencies and law enforcement agencies have access to the equipment of telecom operators. They can organize wiretapping at the cell tower level, and no codes or antiviruses on your phone will detect this. In this case, the problem. can only be solved by changing the number and device.

Is it true that the code *#9900# helps to find a spy?

No, the code *#9900# opens the system dump menu (SysDump) on Samsung devices. It is intended for engineers and allows you to collect system logs. For the average user, it is useless in terms of searching for viruses and can lead to accidental changes. critical settings.

Will airplane mode protect against wiretapping?

Airplane mode disables the radio modules, so at this moment it is impossible to transfer data from the phone. However, if the device already has spyware, it will record all actions and send them as soon as you disable airplane mode.

How to check if the camera is turned on secretly?

In modern versions of Android (starting from 12th), a green or orange indicator appears in the upper corner of the screen when using the camera or microphone. If you see this icon when you have not launched any applications, urgently check your access rights.

Is it possible to remove a virus. code?

No, there is no magic combination of numbers that will remove the virus. Codes can only reset the forwarding settings. To remove malware, an anti-virus scan or a complete reset of the device is required.