In 2019, Google pulled CamScanner from the Play Store. It had over 100 million installs, a 4.4 star rating, and had been on people’s phones for years without incident. The app itself hadn’t changed its purpose. What changed was a third party advertising module bundled into a later update, one that quietly dropped a trojan downloader onto devices. Users who had installed the app in 2016 were still running it in 2019, trusting reviews written about a completely different piece of software.

That’s the pattern nobody talks about when they say “apps you should delete immediately.” The scary apps aren’t the obviously sketchy ones with 12 reviews and a name like “Super Battery Saver Pro Max.” The scary ones are the boring utilities you installed three or four years ago and never opened the update log for again: the flashlight app, the PDF converter, the ringtone cutter, the QR scanner. Somewhere between install and now, a lot of these apps quietly changed hands.

the app flipping economy

There is an actual secondary market for abandoned Android apps. Developer accounts with an established install base, decent ratings, and years of review history get listed and sold, sometimes for a few hundred dollars, sometimes for tens of thousands if the download count is high enough. The buyer isn’t paying for the code. Code for a flashlight app is trivial. They’re paying for distribution: an existing user base that will receive updates automatically, an app store listing with social proof already baked in, and a search ranking that took years to build.

Once the transfer happens, the new owner pushes an update. Maybe it adds two ad SDKs. Maybe it adds a location permission “to serve local content.” Maybe it just starts phoning home to a new analytics endpoint that didn’t exist in the original build. Nobody sees a new install prompt. Nobody re-reads the permission list with fresh eyes, because as far as your phone is concerned, this is the same app you already trusted last year.

We’ve looked at listings where the developer name changed twice in five years while the package name and app icon stayed identical. Reviews from 2019 praising “no ads, works great” sit directly above a 2024 version that ships with four ad networks and a session-replay SDK capturing screen taps. The install base doesn’t know the difference. It just keeps updating.

why this is worse than an obviously bad app

A scam app gets flagged fast. Bad reviews pile up within weeks, security researchers write it up, Google usually pulls it within a couple of app store sweeps. The economics of an obvious scam are short and brutal.

A resold utility app is patient. It inherited years of good reviews it never earned. It has a name that shows up in “best free flashlight apps 2020” roundup articles still ranking on Google. It doesn’t need new installs to be valuable, because the value was already sitting on millions of phones before the sale even happened. That’s the entire business model: buy trust cheaply, monetize it slowly, stay under the threshold that triggers a takedown review.

the signals worth checking

Before you decide what stays and what goes, check three things on any utility app you installed more than 18 months ago and haven’t thought about since:

Developer name history. Play Store listings show a developer name and, if you dig into cached versions or old app store archive pages, you can sometimes catch a change. A flashlight app that switched from “BrightApps LLC” to a generic-sounding shell name is a signal, not proof, but a signal worth acting on.

Version jump without feature change. If an app went from version 2.1 to version 6.0 and the interface looks exactly the same, something happened in that gap that wasn’t about the user experience.

Permission additions that don’t map to new features. A ringtone maker asking for coarse location in 2021 and fine location plus contacts in 2024, with no new “find nearby ringtones” feature to justify it, is not a coincidence.

Privacy policy domain. Check the privacy policy link in the store listing. If it points to a domain registered eight months ago while the app has existed for six years, that domain almost certainly belongs to the new owner, not the one you originally trusted.

what actually to delete

Single-purpose utility apps are the highest risk category here, precisely because they’re the most forgettable. A flashlight, a QR scanner, a PDF tool, a screen recorder you used once for a school project. None of these need to exist as standalone apps anymore. Android has a flashlight toggle in the quick settings panel. Google Lens scans QR codes from the camera app. Most of what these apps do, the OS already does natively, without a developer account that could get sold to someone else next year.

The uncomfortable truth is that “delete immediately” isn’t really about the app’s current behavior. It’s about the fact that you have no reliable way to verify who is currently receiving the data it collects, or whether that’s the same entity you agreed to trust when you tapped install. If an app’s only job could be replaced by a built-in OS feature, the safest move isn’t scanning it for trackers. It’s removing the variable entirely.