Android security: what actually matters

    Android is a far harder target than it was a decade ago, but it remains the mobile platform where malware genuinely circulates. The risk is concentrated in a few specific behaviours, and avoiding them matters more than any app you install.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Where Android infections come from

    Almost all real-world Android malware arrives through apps installed outside official stores, through links in messages, or through apps that request unusual permissions after installation and then download additional code.

    Banking trojans are the most damaging family. They typically ask for accessibility permissions, then use them to read the screen, overlay fake login windows and intercept confirmation codes.

    The permissions that deserve suspicion

    Accessibility services, device administrator rights, notification access, SMS access and the ability to draw over other apps are the permissions abused by serious malware. A game, torch or photo editor has no legitimate reason to ask for them.

    Review these lists occasionally in your settings and revoke anything you do not recognise. This single audit removes most persistent threats.

    • Accessibility services
    • Notification access
    • SMS and call log access
    • Display over other apps
    • Device administrator rights

    Installing apps safely

    Prefer Google Play or your manufacturer's store, and even then check the developer name, install count, recent reviews and requested permissions. Cloned versions of popular apps appear regularly and rely on hurried installation.

    Never install an APK sent by message, promised as a bank or delivery update, or offered by a caller. That single rule prevents the majority of serious mobile fraud we see across markets.

    Settings worth changing today

    Turn on Google Play Protect, enable automatic system and app updates, set a strong screen lock, and switch on Find My Device. Enable notification previews to stay hidden on the lock screen so that codes are not readable to someone holding your phone.

    Review which apps can install unknown applications, and disable that permission for your browser and messaging apps unless you specifically need it.

    Do you need an Android antivirus app?

    A reputable mobile security app adds value mostly through web and phishing filtering, scanning of sideloaded files, Wi-Fi checks and anti-theft tools. It is most useful for households where apps are installed from outside the official store, or for less confident users who benefit from a warning layer.

    Avoid unknown 'cleaner' and 'booster' apps entirely: many are advertising vehicles, and some are outright malicious.

    If you think the phone is compromised

    Restart in safe mode to stop third-party apps from running, then remove the suspicious application and revoke its administrator and accessibility rights. Change your banking and email passwords from another device and contact your bank if payments are involved.

    If symptoms persist, back up photos and documents only, then perform a factory reset and restore selectively rather than reinstalling everything.

    Children, shared phones and older relatives

    Shared and inherited devices carry more risk because installation habits vary. Set up a separate user profile or a supervised account for children, disable installation from unknown sources, and review installed apps together every few months rather than policing silently.

    For older relatives, the highest-value changes are automatic updates, a security app that warns about suspicious links, and a clear household rule that nobody installs anything requested during a phone call.

    Updates, patches and device lifespan

    Security updates matter more than the Android version number. Check how long your manufacturer promises updates for the model you own, since several major brands now offer five to seven years while cheaper devices may stop within two.

    Once a phone stops receiving security patches, treat it as unsuitable for banking and email. Repurpose it for music, navigation or a child's games device on a separate account.

    Public Wi-Fi and network risks on mobile

    Phones connect automatically to remembered networks, which is convenient and occasionally dangerous near lookalike hotspots. Forget networks you no longer use, disable automatic connection to open networks, and prefer mobile data for banking.

    A VPN adds protection on networks you do not control, but keeping apps updated and using the official banking app matters more in practice.

    Messaging apps, links and payment fraud

    Most money lost on mobile devices today is lost through messages rather than malware. Fake delivery notices, refund offers, job adverts and account warnings all lead to a convincing page or to an app the sender wants you to install.

    Slow the process down: never act on a link in an unexpected message, open the service's own app instead, and treat any request to install something, share a code or move money as fraudulent until independently verified.

    Backing up and preparing for loss or theft

    Turn on automatic backup for photos and documents, note the device identifier, and confirm that Find My Device can locate, lock and erase the phone remotely. Keep a second recovery method on your Google account so a stolen phone does not also lock you out of recovery.

    If the device is stolen, lock it remotely, contact your operator to block the SIM, and change the password on the accounts tied to it, starting with email and banking.

    Frequently asked questions

    Does Android really need an antivirus app?

    It is not essential for someone who installs only from Google Play and keeps the system updated. It adds a useful phishing and scanning layer for households that sideload apps or include less confident users.

    Is Google Play Protect enough on its own?

    It catches a great deal of known malware but is less effective against freshly published or sideloaded threats, and it does not filter phishing links in messages and browsers.

    How do I know if an app is a banking trojan?

    The clearest signal is a request for accessibility permissions from an app that has no reason to need them, often followed by overlay windows appearing over banking apps.

    Are cleaner and booster apps useful?

    Almost never. Android manages memory itself, and many such apps exist to serve advertising or collect data.

    Does a factory reset remove all malware?

    Nearly always, yes, provided you do not restore the malicious app from a backup afterwards. Restore data selectively rather than reinstalling everything.