How to Check If Your Android Phone Is Hacked or Tracked (And What to Do Right Now)

Trickswd
Trickswd
An infographic showing security status options on an Android smartphone, illustrating steps to check if a device is hacked or tracked, including scanning for unknown apps, detecting battery drain, and revoking permissions.
Check If Your Android Is Hacked

A few months ago, I noticed my phone doing something completely unexplainable. I was sitting at my desk, working on my laptop, while my Android phone rested quietly beside my keyboard. Out of nowhere, the screen lit up, unlocked itself briefly, and then went black. A few minutes later, the back of the device felt warm to the touch even though I hadn't touched a single app or made a call in hours.

When I checked my battery settings that evening, my device had dropped by over 40% in standby mode. A random app with a blank name and a generic gray icon had consumed over 2.5 GB of cellular data in the background while I was asleep.

That was the exact moment panic set in. Was someone reading my text messages? Tracking my live location? Accessing my mobile banking apps?

Fortunately, modern Android smartphones have built-in security systems that leave clear digital footprints whenever an unauthorized app or tracking script tries to spy on you.

If you suspect your phone is acting strangely or fear someone might be tracking your every move, here is my hands-on, step-by-step guide to finding out if your Android phone is compromised and how to clean it up safely.

The 6 Dead Giveaways Your Android Phone Is Hacked or Tracked

Before running complex diagnostic USSD codes or downloading scanner utilities, pay close attention to how your hardware and software are behaving. When malware or stalkerware runs on a smartphone, it creates unavoidable physical side effects:

1. The Green Privacy Indicator Dot Won't Go Away

Starting with Android 12, Google introduced a critical visual security alert: a small green dot in the top right corner of your status bar. This dot lights up whenever an app accesses your Camera or Microphone. If that green dot flickers or stays illuminated while you are sitting on your home screen or reading an offline article, a background app is secretly listening or watching.

2. Sudden Battery Drain and Overheating While Idle

Spyware scripts run 24/7 in the background, keeping your processor awake, taking screenshots, logging keystrokes, and uploading compressed data files to remote command servers. If your phone feels hot inside your pocket or loses 20% to 30% battery overnight on your nightstand, background execution is almost certainly taking place.

3. Spikes in Background Mobile Data Usage

Spyware doesn't just harvest your photos, texts, and location coordinates; it has to transmit those files back to the hacker. If your monthly mobile data usage spikes suddenly without you watching extra videos or downloading games, hidden background data transfers are the primary suspect.

4. Strange Text Messages with Code Strings

Stalkerware tools often rely on hidden, encrypted SMS commands sent by a remote controller to trigger actions (like pinging your GPS location or taking a photo). If your SMS inbox receives strange text messages containing random numbers, symbols, or gibberish words from unknown numbers, those are remote execution triggers.

5. Pop-Ups, Random Restarts, or Apps Crashing

If your browser constantly redirects you to shady prize-winning sites, or if your phone takes an unnaturally long time to shut down when you press the power button, malicious code is likely interfering with normal Android system shutdown protocols.

6. Unrecognized Accounts or Authorized Devices

If friends mention getting weird links from you on WhatsApp or Instagram, or if you notice strange login alerts in your primary Google Account session logs, someone may have compromised your cloud credentials to monitor your synced data.

Step-by-Step Guide: How to Check Your Phone Right Now

If you noticed any of the warning signs above, don't panic. Take your phone, follow these exact step-by-step checks, and let's find the culprit.

Method 1: Check Call Forwarding Status (Secret USSD Codes)

One of the oldest tricks in the book is unauthorized call forwarding. Hackers or jealous acquaintances who get brief physical access to your phone can dial secret MMI codes to divert your incoming phone calls, SMS messages, and 2FA authentication codes to their own phone number.

Open your phone's Dialer/Phone App and type the following codes:

  1. Dial *#21# and press the Call button.
    • What it does: Displays whether your calls, voice messages, SMS, and data are being forwarded to another number.
  2. Dial *#62# and press the Call button.
    • What it does: Shows where your calls and messages are routed when your phone is unreachable or switched off.

How to Fix It: If you see an unfamiliar phone number listed next to Call or SMS forwarding, open your phone dialer, type ##002#, and press Call. This master code immediately erases and resets all conditional and unconditional call forwarding rules on your carrier network.

Method 2: Audit "Device Admin Apps" (The Stalkerware Zone)

To stop you from tapping "Uninstall," sophisticated spyware requests Device Administrator privileges during installation. This locks the app into your system layer, graying out the uninstall button in standard menus.

Search Device Admin Apps on Android Settings
  1. Open Settings.
  2. Search for Device Admin in the settings search bar (or go to Settings > Security & Privacy > More Security Settings > Device Admin Apps).
  3. Review the list of apps holding administrator status.
  4. Legitimate entries: Find My Device, official carrier tools, or security suites you explicitly installed.
  5. Suspicious entries: Any app with a generic name like System Service, Device Health, Backup Utility, or an icon you don't recognize.
  6. If you spot an unknown app, tap it and select Deactivate.

Method 3: Inspect "Accessibility Services" Permissions

Stalkerware heavily abuses Android's Accessibility framework. Designed to aid users with physical impairments, accessibility permissions allow an app to read everything displayed on your screen, tap buttons on your behalf, and log every key you press (keylogging) across banking apps and private chats.

  1. Go to Settings > Accessibility.
  2. Scroll down to Downloaded Apps or Installed Services.
  3. Inspect every service listed as ON.
  4. If an utility or app you don't completely trust has full screen-reading permissions enabled, tap it and toggle it OFF immediately.

Method 4: Audit Background Data Usage

To catch spyware in the act of uploading your data, inspect your system data logs:

  1. Go to Settings > Network & Internet > Mobile Data Usage (or Connections > App Data Usage).
  2. Change the timeframe to inspect the last 30 days.
  3. Scroll past known data hogs like YouTube, TikTok, or Chrome.
  4. Look for blank icons, generic utility names, or apps you rarely open that have consumed hundreds of megabytes in the Background tab.

Method 5: Run a Deep System Scan with Google Play Protect

Google Play Protect continuously scans your device for malicious APKs, sideloaded stalkerware, and known malware signatures.

  1. Open the Google Play Store app.
  2. Tap your profile picture in the top right corner.
  3. Select Play Protect.
  4. Tap the Scan button.

For an additional layer of security, download a reputable mobile security tool like Malwarebytes or Bitdefender from the Play Store and execute a second deep scan.

How to Completely Clean a Hacked or Tracked Android Phone

If you discovered an active spyware installation or if your phone continues to exhibit severe compromise indicators, here is how to clean your device thoroughly:

Step 1: Boot into Safe Mode

If a malicious app prevents you from deleting it or keeps crashing your Settings screen, boot your phone into Safe Mode. Safe Mode prevents all third-party software from launching in the background.

  1. Press and hold your physical Power Button.
  2. Touch and hold the on-screen Power Off prompt until Reboot to Safe Mode appears.
  3. Tap OK.
  4. Once your phone reboots (you will see "Safe Mode" written in the bottom corner), go straight to Settings > Apps, locate the suspicious app, and tap Uninstall.

Step 2: Revoke Google Account Access

If a hacker obtained your credentials, they might be tracking your real-time location via Google Maps Timeline or accessing your synced photos without needing an app on your physical phone.

  1. Open your browser and visit myaccount.google.com.
  2. Go to Security > Your Devices.
  3. Tap Manage all devices.
  4. If you see an active session from a web browser or device you don't recognize, tap it and select Sign Out.
  5. Immediately change your Google Account password and enable Two-Factor Authentication (2FA) using an authenticator app (like Google Authenticator or Bitwarden).

Step 3: The Nuclear Option — Factory Data Reset

If you suspect deeply entrenched stalkerware, a persistent keylogger, or a system-level exploit, a Factory Data Reset is the single most effective way to guarantee complete removal. A reset wipes your device storage clean, reformatting the operating system back to its original factory state.

Crucial Advice: Manually back up your photos, contacts, and personal documents to a cloud service. Do not perform a full automated system image restore afterward, as cloud backups can occasionally re-install the infected APK file alongside your legitimate apps!

To reset: Go to Settings > System > Reset Options > Erase All Data (Factory Reset).

Summary Checklist: Android Security Audit

Security Test Dial Code / Setting Path What to Look For
Call Diverts Dial *#21# or *#62# Ensure no unknown numbers are listed
Reset Call Forwarding Dial ##002# Wipes all active call/SMS diverts
Device Administrators Settings > Security > Device Admin Revoke unknown apps with admin control
Accessibility Audit Settings > Accessibility Turn off screen-reading access for non-essential apps
Active Google Sessions myaccount.google.com/devices Sign out of unrecognized phones or browsers

3 Critical Mistakes to Avoid

  • Relying Solely on Antivirus Apps: Stalkerware is often manually sideloaded by someone who had physical access to your unlocked phone. Because stalkerware often disguises itself as legitimate parental control or diagnostic software, traditional antivirus apps can sometimes miss it. Always perform manual audits of accessibility and administrator permissions alongside running scans.
  • Keeping Weak Lock Screen Security: Over 80% of consumer stalkerware is installed physically by someone who knows the victim's lock screen PIN. If your PIN is easy to guess (like 1234, 0000, or your birth year), anyone around you can grab your phone while you sleep and install a tracking app in under three minutes. Switch to an alphanumeric password or strong biometric lock immediately.
  • Sideloading Modified APK Files: Never download cracked apps, game "mods," or paid app APKs off random web forums. Premium app mods are one of the most common distribution vectors for trojans and remote access tools (RATs). Stick strictly to verified app stores.

Final Thoughts

Your smartphone holds the keys to your financial accounts, private conversations, location history, and personal life.

If your Android phone has been running warm, draining battery rapidly, or showing mysterious privacy indicators, don't ignore the warning signs. Taking ten minutes today to check your dial codes, audit your Device Administrator list, and clean out unused apps will give you complete peace of mind and keep your personal data strictly where it belongs in your hands alone.

About The Author

You may like these posts

Post a Comment