In the era of total digitalization, the privacy of conversations is becoming a matter of serious concern for many users. Rumors that intelligence agencies or attackers can remotely activate your smartphone’s microphone are often exaggerated, but the technical possibility of intercepting traffic or installing hidden forwarding is quite real. Users often look for a “magic” combination of numbers that will instantly indicate the presence of listening devices, but the reality is much more complex and requires an integrated approach to diagnostics.
There are a number of standard USSD requestsdeveloped by telecom operators and GSM network engineers that allow you to check the status of forwarding calls and messages. Redirecting your call to another number is one of the most common methods of intercepting information, available not only to intelligence agencies, but also to ordinary scammers. Understanding how these codes work and what exactly they indicate is the first step to ensuring your digital hygiene.
In this article, we will look in detail at what combinations of characters need to be entered into your device's dialer, how to interpret the responses received from the network, and what additional steps should be taken if you detect suspicious activity. We will also look at myths about total wiretapping and give real recommendations for protecting your Androidsmartphone from spyware.
Myths about magic codes and the reality of GSM networks
The Internet is full of lists of “secret codes” that supposedly instantly disable wiretapping or show a list of everyone connected to your phone devices. It is important to immediately separate the wheat from the chaff: there is no single universal command that would show whether the FSB or CIA is reading you in real time. Most of these “security codes” are either fictitious or standard service menus that have nothing to do with protection against surveillance.
However, in the cellular infrastructure there are real service codes designed to control operator services. Attackers can use these same legitimate tools to organize hidden redirects. For example, if your call automatically goes to voicemail or another number without your knowledge, this may be a sign of tampering. USSD requests helps check the network settings, and not the presence of a physical bug in the battery.
⚠️ Attention: Entering incorrect service codes in rare cases In some cases, it may reset network settings or disable useful services. Be careful when entering characters and do not press the call button without understanding the meaning of the command.
The real threat often comes not from direct interception of the radio signal (which requires expensive equipment and access to base stations), but from malware installed on the phone itself. Spy apps can transmit audio, screenshots and geolocation over the Internet, and no *#...# codes will detect this. Therefore, checking via USSD is just one of the diagnostic stages, relating exclusively to the operator’s communication channels.
Basic USSD codes for checking forwarding
The most reliable way to find out whether your calls are being forwarded to third-party numbers is to use standard codes for checking the forwarding status. These commands work on most devices running Android i iOSas they are processed on the side of the telecom operator, and not the smartphone itself. By entering them into the Phone application, you will receive an instant response from the network in the form of a pop-up window.
The first and most important code is *#21#. This combination allows you to check the status of unconditional call forwarding, that is, unconditional forwarding of all incoming calls, SMS and data. If this service is active, all your calls will be sent to the specified number, even if your phone is turned on and is in the network area. In a normal state, the network response should state that the service is not active or forwarding is not installed.
For a more detailed check, you should use the code *#62#. It shows where the call is routed when your phone is turned off or out of network coverage. Often operators automatically set the voicemail number here, which is the norm. However, if you see an unfamiliar mobile number instead of a voicemail number, this is a serious cause for concern. Also useful is the code ##002#, which serves to completely cancel all types of forwarding.
If the code *#21# shows an unfamiliar number, immediately dial ##002# to cancel the forwarding and contact your operator's call center to change the SIM card.
In addition to checking voice calls, it is important to control the forwarding SMS messages, since confirmation codes for banking applications are often sent through them. Use code *#002# to comprehensively check the status of all forwarding services. Some operators may use their own variations of these commands, so if standard codes do not work, information can be found in the operator’s personal account or help.
Engineering menu and hidden Android settings
In addition to operator USSD codes, smartphones based on Android there are hidden engineering menus designed for testing equipment and network diagnostics. They are also accessed through a set of special combinations in the dialer. One of the most famous codes is ##4636##which opens the “Testing” menu.
In this menu you can find the “Phone Information” section, which displays detailed data about the connection, network type and signal status. Although there is no direct “check wiretapping” button, an experienced user may notice anomalies in the operation of the radio module. For example, if the phone constantly registers in the 2G (GSM) network instead of 4G/LTE for no apparent reason, this may indicate a jammer or an attempt to force the phone to switch to a less secure communication protocol for interception.
⚠️ Attention: Changing settings in the engineering menu (for example, the preferred network type) may lead to loss of communication or unstable operation of the smartphone. Do not change the parameters if you are not sure of their purpose.
Another useful code is ##8255##that starts the GTalk Service Monitor service (if installed by the manufacturer). It allows you to see your connection history and activity of Google services. For device owners Samsung the code #0#often works, opening an extended menu for testing the display, sensor and other components. Although these menus will not directly show the spy, they help assess the overall technical health of the device.
What to do if the codes do not work?
Some manufacturers (for example, Xiaomi, Huawei) block access to standard engineering menus in their shells. In this case, you can try installing the Phone Info SAM application or a similar one from Google Play, which programmatically requests this data.
It is important to understand that having access to the engineering menu does not mean that your phone is protected. Advanced viruses can mask their activity even in system logs. Therefore, the use of these codes should be considered as an additional diagnostic measure, and not as a guaranteed method of detecting a threat.
Signs of the presence of spyware on the device
If combinations of numbers do not reveal redirection, but suspicions remain, you should pay attention to indirect signs of the presence of malicious software. Spyware (stalkeyware) must constantly work in the background, transmitting data to the attacker’s server, which inevitably affects the operation of the smartphone. The first alarm bell is abnormally rapid battery discharge.
Pay attention to the heating of the case. If the phone is hot even at rest, when you are not running heavy games or applications, this may indicate that the processor is busy processing and transferring data from a hidden application. It is also worth checking your traffic consumption: a sharp increase in mobile data consumption without changing your usage habits is a sure sign of a data leak.
Here is a list of the main symptoms that should alert the owner of a Androidsmartphone:
- 📉 Rapid battery drain and overheating of the device in standby mode.
- 📶 Unexplained interference, clicks or echoes during a call (although this is more often a sign of a poor connection, in combination with other factors it may indicate interception).
- 📲 The appearance of unknown application icons that cannot be deleted in the standard way.
- 💾 Spontaneous reboot of the phone or the screen turning on in the dark.
Another sign may be strange interface behavior: delays when entering text, spontaneous opening of applications or turning on the flashlight. Modern spyware tries to disguise itself as system processes (for example, “Update Service” or “Wi-Fi Helper”), so carefully study the list of installed apps in the settings.
☑️ Diagnosis of suspicious activity
Analysis of access rights and device administrators
Spyware often requires elevated privileges to function properly. Attackers can obtain rights device administrator, which allows the virus to prohibit its removal and hide in the system. Checking this setting is a critical diagnostic step that is often overlooked.
To check the list of administrators, go to Settings → Security → Device Administrators (the path may vary depending on the model and version Android). This list should only include trusted services, such as Google's Find My Device or corporate clients if the phone is working. If you see an unknown application here with administrator rights, it is almost guaranteed to be malware.
It is also worth paying attention to Accessibility. Many Trojans use this section to gain permission to read the screen and record keystrokes. Go to Settings → Accessibility and check which services are active. Any service that you did not enable yourself (especially with names like “Screen Recorder”, “Click Assistant”, etc.) should be immediately disabled and deleted.
| Check option | Where to find it in settings | Normal state | Threat sign |
|---|---|---|---|
| Device administrators | Security / Biometrics | Google Find My Device | Unknown applications with a check mark |
| Special features | Special. capabilities | Disabled or TalkBack | Active screen recording services |
| Installation from unknown | Applications / Security | Prohibited | Allowed for browser or instant messenger |
| Battery consumption | Battery / Power | Compliant with use | High consumption in the background of system processes |
Having rights to install applications from unknown sources also makes life easier for viruses. Make sure this feature is disabled globally, or only allowed for specific, trusted applications (for example, your manufacturer's app store), but not for the browser or file manager.
Protection methods and smartphone cleaning
If you find signs of tampering or simply want to protect yourself as much as possible, you need to take a number of active steps. The first step should be a complete audit of installed applications. Remove all apps that you don’t remember or that seem suspicious, even if they are called “System Plugin.”
Next, it is recommended to install a reliable antivirus from a reputable vendor (Kaspersky, Dr.Web, ESET) and conduct a full system scan. Although antiviruses are not all-powerful, they can detect known spyware signatures. After scanning, be sure to change all important passwords (from mail, social networks, banks) from another, obviously clean device.
⚠️ Attention: Changing passwords on an infected phone is useless, since the keylogger will intercept new data immediately after entering it. First, ensure the device is clean, then change accesses.
The most radical, but also the most effective method is a full reset to factory settings (Factory Reset). This will delete absolutely all data, including hidden viruses that could have penetrated deep into the system. Before doing this, be sure to back up only your personal files (photos, contacts), but do not restore the applications themselves from the backup copy, so as not to return the virus back.
Full reset to factory settings with formatting of the internal drive is the only way to guarantee the removal of complex spy bookmarks that are not deleted in the usual way.
To prevent future infections, never click on suspicious links in SMS and messengers, do not download hacked versions of paid applications and regularly update the operating system of your smartphone. Security updates close vulnerabilities through which attackers can gain remote access.
Frequently asked questions (FAQ)
Is it true that the code *#21# shows whether intelligence agencies are listening to me?
No, that's a myth. The code *#21# shows only the call forwarding settings installed in the operator's network. It cannot detect hardware wiretapping, signal interception by intelligence agencies, or the presence of viruses on the phone.
Can the phone listen to me if the screen is turned off?
Technically, this is only possible if there is malware installed that has permission to access the microphone. Standard Android features block background apps from accessing your microphone, but the virus can bypass these restrictions. The microphone indicator (green dot) in new versions of Android should light up whenever the microphone is active.
How to find out who called me during wiretapping?
If forwarding was configured, you can see missed calls on your device if the forwarding did not work instantly. However, with professional interception, the call may be completely invisible to the subscriber. Checking the call details with your operator may reveal strange outgoing calls made from your number.
Will airplane mode help against wiretapping?
Enabling airplane mode turns off all radio modules (GSM, Wi-Fi, Bluetooth), which actually stops external data transmission. However, if information (audio, photo) is already recorded on the phone, it will be transferred immediately after turning off airplane mode. This is a temporary measure, not a solution to the problem.
Is it worth buying special anti-bug detectors for your phone?
Most portable bug detectors sold on the Internet are ineffective against modern digital threats. They can find simple radio beacons, but are powerless against software spying using Internet channels. The best protection is the hygiene of using a smartphone and up-to-date software.