Where Android infections come from
Almost all real-world Android malware arrives through apps installed outside official stores, through links in messages, or through apps that request unusual permissions after installation and then download additional code.
Banking trojans are the most damaging family. They typically ask for accessibility permissions, then use them to read the screen, overlay fake login windows and intercept confirmation codes.
The permissions that deserve suspicion
Accessibility services, device administrator rights, notification access, SMS access and the ability to draw over other apps are the permissions abused by serious malware. A game, torch or photo editor has no legitimate reason to ask for them.
Review these lists occasionally in your settings and revoke anything you do not recognise. This single audit removes most persistent threats.
- Accessibility services
- Notification access
- SMS and call log access
- Display over other apps
- Device administrator rights
Installing apps safely
Prefer Google Play or your manufacturer's store, and even then check the developer name, install count, recent reviews and requested permissions. Cloned versions of popular apps appear regularly and rely on hurried installation.
Never install an APK sent by message, promised as a bank or delivery update, or offered by a caller. That single rule prevents the majority of serious mobile fraud we see across markets.
Settings worth changing today
Turn on Google Play Protect, enable automatic system and app updates, set a strong screen lock, and switch on Find My Device. Enable notification previews to stay hidden on the lock screen so that codes are not readable to someone holding your phone.
Review which apps can install unknown applications, and disable that permission for your browser and messaging apps unless you specifically need it.
Do you need an Android antivirus app?
A reputable mobile security app adds value mostly through web and phishing filtering, scanning of sideloaded files, Wi-Fi checks and anti-theft tools. It is most useful for households where apps are installed from outside the official store, or for less confident users who benefit from a warning layer.
Avoid unknown 'cleaner' and 'booster' apps entirely: many are advertising vehicles, and some are outright malicious.
If you think the phone is compromised
Restart in safe mode to stop third-party apps from running, then remove the suspicious application and revoke its administrator and accessibility rights. Change your banking and email passwords from another device and contact your bank if payments are involved.
If symptoms persist, back up photos and documents only, then perform a factory reset and restore selectively rather than reinstalling everything.
Children, shared phones and older relatives
Shared and inherited devices carry more risk because installation habits vary. Set up a separate user profile or a supervised account for children, disable installation from unknown sources, and review installed apps together every few months rather than policing silently.
For older relatives, the highest-value changes are automatic updates, a security app that warns about suspicious links, and a clear household rule that nobody installs anything requested during a phone call.
Updates, patches and device lifespan
Security updates matter more than the Android version number. Check how long your manufacturer promises updates for the model you own, since several major brands now offer five to seven years while cheaper devices may stop within two.
Once a phone stops receiving security patches, treat it as unsuitable for banking and email. Repurpose it for music, navigation or a child's games device on a separate account.
Public Wi-Fi and network risks on mobile
Phones connect automatically to remembered networks, which is convenient and occasionally dangerous near lookalike hotspots. Forget networks you no longer use, disable automatic connection to open networks, and prefer mobile data for banking.
A VPN adds protection on networks you do not control, but keeping apps updated and using the official banking app matters more in practice.
Messaging apps, links and payment fraud
Most money lost on mobile devices today is lost through messages rather than malware. Fake delivery notices, refund offers, job adverts and account warnings all lead to a convincing page or to an app the sender wants you to install.
Slow the process down: never act on a link in an unexpected message, open the service's own app instead, and treat any request to install something, share a code or move money as fraudulent until independently verified.
Backing up and preparing for loss or theft
Turn on automatic backup for photos and documents, note the device identifier, and confirm that Find My Device can locate, lock and erase the phone remotely. Keep a second recovery method on your Google account so a stolen phone does not also lock you out of recovery.
If the device is stolen, lock it remotely, contact your operator to block the SIM, and change the password on the accounts tied to it, starting with email and banking.
