Most spyware does not announce itself. It does not flash a warning or change your wallpaper. It sits inside apps that look normal and behave normally most of the time. The signs are subtle, and they only become obvious once you know what to look for.

Here are nine of them.

1. The App Requests Permissions It Does Not Need

Camera on a flashlight. Microphone on a calculator. Contacts on a weather app. If an app asks for access to something unrelated to its core function, that is the single clearest warning sign.

Permission creep happens because developers import SDKs that request broad permissions by default. The developer may not even realize the library they added for crash reporting also declared microphone access in the manifest. But the result is the same: your microphone is accessible to code you did not choose to trust.

We wrote a detailed breakdown of how to evaluate permission requests and what the common traps are. The short version: if the permission does not match the feature, something is wrong.

2. Your Battery Drains Faster Than Usual

Background processes that continuously send data drain your battery. A well-built app uses almost no power when you are not actively using it. If your battery started dropping faster without any obvious change in your habits, something is running when it should not be.

This is not a definitive signal on its own. A poorly optimized game or a stuck sync process can do the same thing. But combined with other signs on this list, unexpected battery drain is worth investigating. Check Settings > Battery > Battery Usage to see which apps consumed the most since your last charge.

3. Your Phone Gets Warm When Idle

CPU activity generates heat. When your phone is sitting on a desk and feels warm to the touch, something is working in the background. Normal idle state should produce no noticeable heat.

Spyware that continuously collects sensor data, records audio, or transmits location updates keeps the CPU engaged. If you notice heat without active use, check your running processes and recent battery stats. The combination of heat and battery drain is a stronger signal than either one alone.

4. Unusual Data Usage Spikes

Go to Settings > Network > Data Usage and look at per-app consumption. If an app that should not need much data is consuming hundreds of megabytes, it is sending something you did not ask it to send.

A notes app using 500MB of mobile data per month has no legitimate explanation. A calculator that consumes any measurable amount of background data is suspicious. The numbers do not lie. Apps that exfiltrate data need a network connection to do it, and data usage is the one metric they cannot hide.

5. The Privacy Label Does Not Match the Permissions

Google’s Data Safety section on every Play Store listing is self-reported. Developers fill out a form declaring what data they collect. Google does not verify any of it. Mozilla’s 2023 audit found that these labels were inaccurate or misleading in roughly 80% of cases.

If an app’s Data Safety section says “no data collected” but the app holds microphone and location permissions, those two facts cannot both be true. One of them is wrong, and it is usually the label. We covered what four independent studies found about app store privacy claims in detail.

6. The App Was Not Downloaded From Google Play

Sideloaded APKs bypass whatever store review exists. An APK someone sent you on WhatsApp, a download link on a website, an app that asked you to enable “Install from unknown sources” before it would install. All of these skip the only automated check between you and untested code.

Repackaged apps are a common tactic. They look identical to the original but contain extra code injected before redistribution. AppXpose includes APK integrity checks that detect repackaged and tampered apps by comparing signing certificates against a crowdsourced database.

7. Unknown SDKs in the Bytecode

This is the most technically reliable signal and the one you cannot check without a scanner.

Apps contain compiled code from third-party SDKs. Some of those SDKs are well-known tracker libraries. Others are not in any public database. In the AppXpose corpus, apps with unknown SDKs average 6.6 trackers per app. That is roughly three times the average for apps containing only known advertising SDKs.

Unknown does not automatically mean malicious. But it means the code has not been publicly audited, documented, or categorized by any independent research group. You can explore the full research data and category breakdowns to see how tracker density varies across app categories.

8. The App Requests Boot Permission

RECEIVE_BOOT_COMPLETED is an Android permission that lets an app start automatically every time you power on your phone. Most apps have no legitimate reason for this. A calculator does not need to start at boot. A photo editor does not need to start at boot.

In our corpus, 75% of news apps request boot permission. The stated reason is usually “to refresh content” or “to deliver notifications.” But the practical effect is that the app and all its tracker SDKs begin running the moment your phone turns on, whether you open the app or not.

If you find an app with boot permission that does not need it, revoke the permission or consider replacing the app.

9. The Developer Has Multiple Copycat Apps

Search the developer name on the Play Store. If they have 20 nearly identical apps with slightly different names, icons, and descriptions, that is a distribution pattern, not a product line.

Volume app publishing is a common tactic for maximizing ad impressions and tracker installs. Each app is a thin wrapper around the same SDK bundle. The developer makes money from the tracking libraries, not from the app itself. If the developer profile looks like an app factory, the apps are probably built like one.

What to Do Next

None of these signs alone is definitive. Battery drain can be a bug. Warm phones can be a hardware issue. One unnecessary permission might be a developer’s oversight.

But the combination matters. An app with three or more of these signs deserves a closer look. The most reliable check is scanning the APK directly to see what code is actually bundled inside. If you want to understand what spyware looks like on Android and how to remove it, we covered that separately.

If you want to check your own apps, AppXpose is free on Google Play. Five scans a week, full results, no account required. The scan takes three seconds and shows you everything the Play Store listing does not.