A security researcher I know ran an experiment last month. She installed a known spyware app on a test phone, then ran it through five popular mobile security suites. Four of them gave her a clean bill of health. The fifth flagged an unrelated ad library as “potentially unwanted” and missed the actual spyware entirely.

This is the false negative problem, and it explains why most people who think they’ve checked for spyware haven’t actually checked for anything meaningful.

The signature trap

Traditional antivirus tools work by comparing apps against a database of known threats. If the app’s signature matches something in the database, it gets flagged. If it doesn’t match, you get a green checkmark and a false sense of security.

The problem: spyware developers know this. They change their code constantly. A surveillance app that gets added to a blocklist on Monday gets recompiled and resubmitted under a new package name by Wednesday. The signature is different. The behavior is identical. Your scanner sees nothing wrong.

Research from 2025 found that signature-based detection catches roughly 27% of stalkerware and commercial spyware on Android devices. That leaves nearly three quarters of actual threats sitting quietly on phones while security apps report “No threats found.”

What detection tools actually look for

Most consumer-grade spyware scanners check three things: known malicious package names, suspicious permission combinations, and basic behavioral flags like “requests admin privileges.” This catches the amateur stuff. Script kiddie malware. Apps so obvious that they practically announce themselves.

What they don’t catch: legitimate-looking apps that happen to exfiltrate your location every six minutes. Business communication tools that record your conversations with explicit consent buried in paragraph fourteen of the terms. “Optimization” utilities that mirror your clipboard to a server in Romania. Perfectly legal surveillance that users technically agreed to.

The technical term for this is “grayware.” Apps that sit in the murky space between outright malware and legitimate software. They’re not violating Play Store policies because they disclosed what they do, buried somewhere. They’re not breaking laws because they got consent, however coerced or deceptive. But they’re absolutely spying on you.

The behavioral analysis gap

A proper spyware detection system needs to watch what apps actually do, not just what they claim to be. This requires behavioral analysis: monitoring network traffic, tracking API calls, logging data access patterns over time.

Most phone users don’t have tools that do this. The Android security apps you can download from the Play Store can’t do deep behavioral analysis because Google’s sandbox won’t let them. They’re restricted to the same limited view of the system that any other app gets. You’d need root access or a custom ROM to run truly comprehensive monitoring, and most people aren’t doing that.

This creates a coverage gap. The apps that can scan broadly are blocked from seeing deeply. The tools that could see deeply require technical changes most users won’t make. Spyware thrives in this gap.

What actually works

If signature scanning is theater and behavioral analysis is out of reach, what’s left?

First: manual permission audits. Go through every app on your phone and look at what it can access. Not what it needs, what it CAN access. If a flashlight app has location permission, that’s not a false positive waiting to be explained. That’s a red flag that deserves investigation.

Second: network monitoring at the router level. Run your phone through a network you control and watch what it talks to. Apps that ping obscure Chinese servers at 3am are telling you something. Listen.

Third: static analysis of the actual APK files. There are open source tools that can decompile an Android app and show you what libraries it includes, what servers it’s configured to contact, what data collection frameworks it’s bundled with. This takes technical skill but produces actual answers.

Fourth: differential analysis. Install the app on a clean test device, use it for a day, then examine what changed. What new files appeared? What background services started? What network connections got established? Compare this behavior against what the app’s privacy policy claims.

The incentive problem

Here’s why this situation won’t improve: everyone involved has the wrong incentives. Security companies want to report high threat counts to justify their subscriptions, so they flag harmless ad libraries as “dangerous.” They want to avoid false positives that generate support tickets, so they ignore anything that might be legitimately installed. App developers want clean security scores, so they use the same tracking libraries everyone else uses, creating safety in numbers. Phone manufacturers preinstall agreements with data brokers, then lock down the system so you can’t audit what they’ve done.

The result is a detection ecosystem optimized for everyone except the person trying to find actual surveillance on their device.

You can check if an app has known malware signatures. That’s trivial and mostly useless. You can audit what permissions an app holds. That’s helpful but incomplete. What you can’t easily do is answer the question that actually matters: is this app surveilling me in ways I didn’t meaningfully consent to?

Until detection tools are designed to answer that question, instead of designed to produce reassuring green checkmarks, the false negative problem will remain. Your phone will pass its security scan while quietly reporting your location to six different data brokers, and the tools you trusted to protect you will tell you everything is fine.