Stalkerware: How to Detect Monitoring Apps Hidden on Your Phone


There is a category of software sold openly, marketed to worried parents and suspicious spouses, that does exactly what a criminal spy tool does: reads your messages, logs your keystrokes, tracks your location, records your calls, and sends all of it to someone else's dashboard. It runs invisibly on your phone. It is called stalkerware, and it is a legal grey area rather than an underground product.

Unlike a hidden Bluetooth tracker, stalkerware does not just tell someone where you are. It tells them what you say, who you say it to, and what you type. If you are worried someone has installed it on your device, this guide explains how to look — and, more importantly, what to do carefully once you find it.

What Stalkerware Actually Does

Once installed, a typical stalkerware app can access:

  • Messages — SMS and, on some configurations, the contents of WhatsApp, Signal, Telegram and Messenger, captured on the device before or after encryption
  • Location — continuous GPS with history
  • Call logs and recordings
  • Keystrokes — including every password you type
  • Photos, files, contacts and calendar
  • Camera and microphone — remote activation on some products
  • Screen content — periodic screenshots

Critically, this defeats end-to-end encryption entirely. Signal protects a message in transit; it cannot protect a phone that is screenshotting the conversation for someone else.

Installation almost always requires brief physical access to the unlocked device — a few minutes is enough. On iPhone it more often takes the form of iCloud credential abuse or a configuration profile rather than a hidden app, because iOS is more restrictive. On Android, a sideloaded app with accessibility and device-admin permissions can hide its icon entirely.

Warning Signs

None of these alone proves anything — phones misbehave for boring reasons. Look for several together, especially starting around the time of a relationship change or after someone had your phone.

  • Battery drains noticeably faster than it used to, with no change in your usage.
  • The phone is warm when idle and unused.
  • Mobile data usage jumps with no explanation — exfiltration costs bandwidth. Check per-app data usage for unfamiliar entries.
  • The device is slower, apps crash more, or it restarts by itself.
  • The screen lights up or shows activity when you are not touching it.
  • Unknown apps with generic names — "System Service", "Device Health", "Sync Manager", "WiFi Helper".
  • Settings changed by themselves — "install unknown apps" enabled, a new device administrator, an accessibility service you did not turn on.
  • Someone knows things they should not — quoting a private message, referencing a place you went, or knowing a plan you only discussed in a chat.
  • You get 2FA codes you did not request, or password reset emails for accounts you did not touch.
  • The person had your phone recently, or gave you the phone as a gift, or set it up for you.

How to Check Your Phone

On Android

  1. Google Play Protect. Open the Play Store, tap your profile, then Play Protect → Scan. Make sure "Improve harmful app detection" is on. Play Protect now flags many stalkerware families.
  2. Device admin apps. Settings → Security → Device admin apps. Stalkerware requests this to prevent uninstallation. Anything unfamiliar here is a serious red flag.
  3. Accessibility services. Settings → Accessibility. This permission lets an app read everything on screen. Legitimate uses exist, but review every entry and disable what you did not enable.
  4. Notification access. Settings → Apps → Special app access → Notification access. An app here reads every notification, including message previews.
  5. Full app list. Settings → Apps → See all apps, then use the menu to show system apps. Search any name you do not recognise before removing it — some genuine system components look odd.
  6. Data usage by app. Settings → Network → Data usage. Look for background data from something you never open.
  7. Unknown sources. Settings → Apps → Special app access → Install unknown apps. If a browser or file manager has this enabled and you did not do it, someone sideloaded something.

On iPhone

  1. Configuration profiles. Settings → General → VPN & Device Management. On a personal phone there should usually be nothing here. A profile you did not install is the single clearest sign.
  2. Is the phone jailbroken? Look for apps like Cydia or Sileo. Most iPhone stalkerware requires a jailbreak.
  3. iCloud is the more common route. Check Settings → your name for devices you do not recognise, and confirm that iCloud Backup, Photos, and Messages are not syncing to an account someone else controls.
  4. Safety Check. Settings → Privacy & Security → Safety Check. This is built specifically for this situation. "Manage Sharing & Access" walks you through everyone who can see your data, and "Emergency Reset" can cut all sharing at once.
  5. Screen Time. A Screen Time passcode set by someone else can be used to monitor and restrict. Check whether one exists that you did not set.
  6. Family Sharing and Find My. Review who is in the family group and who you share location with.

Both platforms

  • Check account-level access, not just the phone. Google Account → Security → Your devices. Apple ID → Devices. Remove anything unfamiliar.
  • Review linked sessions in WhatsApp, Signal, Telegram and your email. A linked desktop session is a live mirror of your messages and requires no app on your phone at all.

If You Find Something — Read This First

The instinct is to delete it immediately. In an abusive situation, that instinct can be dangerous.

  1. Consider your safety before you act. Removing stalkerware tells the person you know. Many products alert the operator when monitoring stops. If the person may react badly, contact a domestic abuse support organisation first and plan the timing with them. Do this from a device they cannot see — a friend's phone, a work computer, or a library machine.
  2. Preserve evidence. Screenshot the app, the permissions it holds, the device admin entry, and the install date. This can matter legally.
  3. Assume every password is compromised. A keylogger captured everything you typed. Change passwords from a different, clean device — not from the phone you suspect. Start with email, then banking, then everything else.
  4. Do not reuse the same recovery email or phone if the person has access to them. Set up a new, clean recovery address.
  5. Check for account-level monitoring too. Removing the app does nothing if they still have your iCloud or Google password, or a linked WhatsApp session.
  6. Then clean the device. The most reliable fix is a full factory reset followed by setting up as a new device — not restoring a backup, which can reinstate the problem. Reinstall apps individually.
  7. Re-enable two-factor authentication everywhere after the reset, using an authenticator app rather than SMS.
  8. Get a new device if you can. For serious situations, a clean phone bought and set up privately, with a new account, is the only way to be certain.

How to Reduce the Risk

  • Use a strong lock screen passcode that nobody else knows — six digits or alphanumeric, not a four-digit PIN and not a pattern someone has watched you draw.
  • Do not register anyone else's biometrics on your phone. Check Face ID / Fingerprint settings for enrolled prints or faces that are not yours.
  • Keep the operating system updated. Many stalkerware installs rely on old vulnerabilities.
  • Do not share your Apple ID or Google account with a partner. Shared accounts are the most common monitoring mechanism and they are entirely invisible.
  • Review linked devices and sessions in your messaging apps every few months.
  • Be cautious with a phone given to you by a partner, employer, or family member — it may have been configured before you got it.
  • On Android, turn off "install unknown apps" for every app that does not genuinely need it.

The Bottom Line

Stalkerware is not an exotic threat. It is a commercial product, cheap, easy to install in five minutes with your unlocked phone in someone's hand, and it undoes every other security measure you have taken.

Do the check even if you are not worried: review device admin apps and accessibility services on Android, configuration profiles and Safety Check on iPhone, and linked sessions in every messaging app. It takes ten minutes.

And if you find something and it frightens you, treat it as a safety situation rather than a technical one. Do not delete it in the moment. Get support, preserve what you found, change your passwords from a device the other person cannot reach, and plan the removal with someone who does this for a living.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed