How to Check If Your Android Phone Is Hacked or Tracked (And What to Do Right Now)
![]() |
| Check If Your Android Is Hacked |
A few months ago, I noticed my phone doing something completely unexplainable. I was sitting at my desk, working on my laptop, while my Android phone rested quietly beside my keyboard. Out of nowhere, the screen lit up, unlocked itself briefly, and then went black. A few minutes later, the back of the device felt warm to the touch even though I hadn't touched a single app or made a call in hours.
When I checked my battery settings that evening, my device had dropped by over 40% in standby mode. A random app with a blank name and a generic gray icon had consumed over 2.5 GB of cellular data in the background while I was asleep.
That was the exact moment panic set in. Was someone reading my text messages? Tracking my live location? Accessing my mobile banking apps?
Fortunately, modern Android smartphones have built-in security systems that leave clear digital footprints whenever an unauthorized app or tracking script tries to spy on you.
If you suspect your phone is acting strangely or fear someone might be tracking your every move, here is my hands-on, step-by-step guide to finding out if your Android phone is compromised and how to clean it up safely.
Before running complex diagnostic USSD codes or downloading scanner utilities, pay close attention to how your hardware and software are behaving. When malware or stalkerware runs on a smartphone, it creates unavoidable physical side effects:
Starting with Android 12, Google introduced a critical visual security alert: a small green dot in the top right corner of your status bar. This dot lights up whenever an app accesses your Camera or Microphone. If that green dot flickers or stays illuminated while you are sitting on your home screen or reading an offline article, a background app is secretly listening or watching.
Spyware scripts run 24/7 in the background, keeping your processor awake, taking screenshots, logging keystrokes, and uploading compressed data files to remote command servers. If your phone feels hot inside your pocket or loses 20% to 30% battery overnight on your nightstand, background execution is almost certainly taking place.
Spyware doesn't just harvest your photos, texts, and location coordinates; it has to transmit those files back to the hacker. If your monthly mobile data usage spikes suddenly without you watching extra videos or downloading games, hidden background data transfers are the primary suspect.
Stalkerware tools often rely on hidden, encrypted SMS commands sent by a remote controller to trigger actions (like pinging your GPS location or taking a photo). If your SMS inbox receives strange text messages containing random numbers, symbols, or gibberish words from unknown numbers, those are remote execution triggers.
If your browser constantly redirects you to shady prize-winning sites, or if your phone takes an unnaturally long time to shut down when you press the power button, malicious code is likely interfering with normal Android system shutdown protocols.
If friends mention getting weird links from you on WhatsApp or Instagram, or if you notice strange login alerts in your primary Google Account session logs, someone may have compromised your cloud credentials to monitor your synced data.
If you noticed any of the warning signs above, don't panic. Take your phone, follow these exact step-by-step checks, and let's find the culprit.
One of the oldest tricks in the book is unauthorized call forwarding. Hackers or jealous acquaintances who get brief physical access to your phone can dial secret MMI codes to divert your incoming phone calls, SMS messages, and 2FA authentication codes to their own phone number.
Open your phone's Dialer/Phone App and type the following codes:
*#21# and press the Call button.
*#62# and press the Call button.
How to Fix It: If you see an unfamiliar phone number listed next to Call or SMS forwarding, open your phone dialer, type ##002#, and press Call. This master code immediately erases and resets all conditional and unconditional call forwarding rules on your carrier network.
To stop you from tapping "Uninstall," sophisticated spyware requests Device Administrator privileges during installation. This locks the app into your system layer, graying out the uninstall button in standard menus.
Stalkerware heavily abuses Android's Accessibility framework. Designed to aid users with physical impairments, accessibility permissions allow an app to read everything displayed on your screen, tap buttons on your behalf, and log every key you press (keylogging) across banking apps and private chats.
To catch spyware in the act of uploading your data, inspect your system data logs:
Google Play Protect continuously scans your device for malicious APKs, sideloaded stalkerware, and known malware signatures.
For an additional layer of security, download a reputable mobile security tool like Malwarebytes or Bitdefender from the Play Store and execute a second deep scan.
If you discovered an active spyware installation or if your phone continues to exhibit severe compromise indicators, here is how to clean your device thoroughly:
If a malicious app prevents you from deleting it or keeps crashing your Settings screen, boot your phone into Safe Mode. Safe Mode prevents all third-party software from launching in the background.
If a hacker obtained your credentials, they might be tracking your real-time location via Google Maps Timeline or accessing your synced photos without needing an app on your physical phone.
myaccount.google.com.If you suspect deeply entrenched stalkerware, a persistent keylogger, or a system-level exploit, a Factory Data Reset is the single most effective way to guarantee complete removal. A reset wipes your device storage clean, reformatting the operating system back to its original factory state.
Crucial Advice: Manually back up your photos, contacts, and personal documents to a cloud service. Do not perform a full automated system image restore afterward, as cloud backups can occasionally re-install the infected APK file alongside your legitimate apps!
To reset: Go to Settings > System > Reset Options > Erase All Data (Factory Reset).
| Security Test | Dial Code / Setting Path | What to Look For |
|---|---|---|
| Call Diverts | Dial *#21# or *#62# |
Ensure no unknown numbers are listed |
| Reset Call Forwarding | Dial ##002# |
Wipes all active call/SMS diverts |
| Device Administrators | Settings > Security > Device Admin | Revoke unknown apps with admin control |
| Accessibility Audit | Settings > Accessibility | Turn off screen-reading access for non-essential apps |
| Active Google Sessions | myaccount.google.com/devices |
Sign out of unrecognized phones or browsers |
1234, 0000, or your birth year), anyone around you can grab your phone while you sleep and install a tracking app in under three minutes. Switch to an alphanumeric password or strong biometric lock immediately.Your smartphone holds the keys to your financial accounts, private conversations, location history, and personal life.
If your Android phone has been running warm, draining battery rapidly, or showing mysterious privacy indicators, don't ignore the warning signs. Taking ten minutes today to check your dial codes, audit your Device Administrator list, and clean out unused apps will give you complete peace of mind and keep your personal data strictly where it belongs in your hands alone.