Cyberlium

Android › Module 1 › Lesson 4

BeginnerModule 1Lesson 4/5

Spyware Indicators

Battery drain, odd permissions, stalkerware clues, and when to suspect surveillance

15 min+15 XP3 quiz
Module progress4 of 5
Hidden app · Mic · Location

Opening

Not every threat wants a bank PIN. Some of it wants a person — and the installer may already know the PIN.

Banking trojans are industrial and remote: a clone, a chat APK, a fake cleaner. Spyware can be that too. A harsher pattern is stalkerware: software meant to watch messages, location, microphone, or photos, often placed by someone who had the phone in their hands or who knew the Google password. Partners, jealous contacts, and abusive situations show up in this category more than Hollywood spies. Indicators are patterns — battery that dies with the screen off, an Accessibility service you did not enable, location always on for an app you do not use, Device admin you do not remember — not a single warm phone. This lesson is safety-first and defensive. You will learn what clues can mean on YOUR device, and that stalkerware often needs physical or account access. You will not learn how to install, hide, market, or operate surveillance apps. You will not learn how to evade them as a cat-and-mouse lab (hiding from an abuser with DIY tricks can escalate risk). If intimate-partner violence or coercive control is possible, technology steps are second to a safety plan and official help. For a phone that is only yours, the lab is Settings → Apps permission review plus notes in $HOME/cyberlium-lab — never a stalkerware sample.

1. Spyware is unwanted observation; stalkerware often starts with a hand on the phone

Spyware, in defender language, is software that collects a person’s activity or data without that person’s informed consent: location trails, message contents, microphone, camera, keystrokes, screenshots of other apps. Remote crimeware can do some of that after a malicious APK (lessons 1–3). Stalkerware is the subset aimed at a specific human, frequently installed when the device is unlocked in front of someone, when a PIN was shared, or when a cloud account was known. That is why “I never clicked a Telegram APK” does not close the case if someone else had the device. The installer needed opportunity, not a novel exploit you will be taught. This course will not describe setup wizards, concealment features, or which commercial products to buy. Naming the access path is enough: physical unlock or account unlock is the usual door.

Consent is the line. A parent using a device they own, with a child who knows, is a different conversation from secret monitoring of an adult partner. This lesson does not litigate family law. It tells adult learners: secret surveillance of another adult is abusive and often illegal; do not do it; do not ask Mentor how to do it. If you suspect you are the person being watched, the priority is whether changing settings on this phone could be seen and punished. That is a safety question, not a CTF. Official local resources, trusted people, and planning beat a dramatic uninstall while the other person holds a spare password. We will not teach “how to hide that you looked.” We will teach that looking can have consequences, so get help that understands that.

2. Technical clues are patterns: battery, data, hidden icons, location, Device admin, Accessibility

Battery and data spikes with the screen off mean something is working when you are not. Many innocent apps sync; the clue is change after a new install, after someone borrowed the phone, or a drain you cannot map to a game you played. Settings → Battery and Settings → Network & internet → Data usage (paths vary by OEM) show which packages ate the budget. An unknown name, a “system” label you do not recognize, or a utility you would not have chosen is worth writing down. Do not download a “stalkerware scanner APK” from a random site to confirm — that is lesson 1 again. Do not install commercial spy tools “to see what they look like.”

Hidden or missing launcher icons are a tell you already met with banking trojans: the package runs without a home-screen tile. You still find it in Settings → Apps → See all apps (show system if you know how on your OEM, without following random internet “show hidden spy” guides that are themselves malware). Unusual Device admin / device owner / “uninstall blocked” states are another: admin exists so IT and lost-phone locks can enforce policy; a dating-app-shaped package or a “battery” fictional like com.ultra.battery.example should not be an admin. Always-on location for an app that is not maps, a ride-share you use, or a family tool you chose is a permission mismatch. Accessibility you did not enable is the same red flag as the cleaner in lesson 3 — refuse and document, do not reverse-engineer the service.

Permission sprawl is the supporting list, not a replacement for the story. SMS, call logs, contacts, microphone, camera, notification access, and Accessibility stacked on a package that claims to be a wallpaper or optimizer is enough to distrust it. One permission in isolation is often a real app doing its job (maps wants location). The mechanism is mismatch plus unexpected presence plus, for stalkerware, a human who had access. Write the mismatch. Do not publish a “how we hide from Settings” guide. Do not disable someone else’s protections. Your lab is your phone if it is yours to administer.

3. Safety-first if someone close may be involved — tech is not the whole response

If you believe an intimate partner, family member, or other person with access may be monitoring you, treat this as a safety situation. Changing passwords, wiping a phone, or confronting the person with screenshots can increase harm if they still have physical access, account recovery, or a willingness to escalate. Conceptually: talk to people and services whose job is safety planning and local help; use a device the other person does not control if you need to communicate; do not store a diary of suspicions in an obvious notes app on the watched phone. This course will not name a single hotline for every country, will not coach you to secretly image a disk, and will not teach counter-stalkerware tradecraft. Official help knows the local law and the risk of retaliation. Cyberlium’s job is: do not become a surveillance operator, and do not treat an abusive situation as a permission-lab high score.

If the phone is clearly yours, nobody else has the PIN or the Google account, and you are dealing with a shady app you installed yourself, the ordinary path is: revoke wild permissions, uninstall the package from Settings, change the Google password from a browser you trust, keep Play Protect on, consider a factory reset after a backup you chose. That path is for remote junk and your own mistakes. It is the wrong first move when the threat is a person in the room. Either way, you still do not install unknown APKs “to test spyware,” and you still do not attack anyone’s device.

4. Wrong vs right: hunting stalkerware as a sport vs reviewing YOUR phone and seeking safety help

Worked failure — same battery drain, opposite harm. Right never includes running or hiding surveillance software.

  • Wrong

    Install a “spy app” on someone else’s phone, or on yours “to learn the UI.” Follow a blog on how to hide icons and dodge Settings. Download a random anti-stalkerware APK. Confront an abusive partner with a permission screenshot as a gotcha. Store live passwords, locations of shelters, or accusations in a world-readable file. Ask Mentor for product names and setup steps. Treat IPV as a Module 1 quiz.

  • Right

    On a phone that is yours to administer: Settings → Apps, Battery, location, Accessibility, Device admin; revoke mismatches; uninstall what you do not trust. Write findings in $HOME/cyberlium-lab with chmod 600 and no live secrets. If a person with access may be watching, prioritize safety planning and official help over DIY removal theater. Never install samples. Never operate stalkerware.

5. Practical: permission review on YOUR phone — notes, not a spy sample

Only if this device is yours and reviewing it will not put you in danger: walk Settings → Apps (permissions for location, SMS, microphone, camera), Settings → Accessibility, Device admin / device admin apps, Battery, and data usage. Copy package labels you do not recognize into $HOME/cyberlium-lab/spyware-indicators.txt — package names and permission names only, not message contents, not photos, not a dossier about another person. chmod 600 so other local accounts cannot read it. If this review feels unsafe, skip the phone steps and write only the conceptual rule: stalkerware needs access; I will not run it; I will seek appropriate help. Do not search for live stalkerware packages. Do not use com.ultra.battery.example as a download target; it remains fiction.

Command guide

YOUR Settings review template — no surveillance software

DEFENSIVE. YOUR phone if it is safe to review. NEVER install, hide, or operate stalkerware. NEVER download a "spy scanner" APK from a random site.

Command — copy this

mkdir -p "$HOME/cyberlium-lab"
NOTES="$HOME/cyberlium-lab/spyware-indicators.txt"

Command — copy this

{
  echo "=== CONTEXT (circle in your head; do not write accusations about others) ==="
  echo "device_is_mine_to_admin: yes / no"
  echo "someone_else_had_PIN_or_Google: possible / no"
  echo "if_IPV_or_coercion_possible: safety_plan_and_official_help_first — skip risky DIY"

Command — copy this

echo ""
  echo "=== SETTINGS WALK (only if safe) ==="
  echo "path: Settings → Apps → permissions (Location / SMS / Mic / Camera)"
  echo "mismatches_I_do_not_recognize:"
  echo "Accessibility services ON:"
  echo "Device admin / device admin apps:"
  echo "Battery or data spikes (package labels only):"
  echo "location_always_on_for:"

Command — copy this

echo ""
  echo "=== FICTIONAL mismatch (do not search/install) ==="
  echo "com.ultra.battery.example + hidden icon + Accessibility + always-on location = distrust"
  echo "I_do_not_detonate_samples: yes"

Command — copy this

echo ""
  echo "secrets: no PINs, no OTPs, no shelter addresses, no other people's messages in this file"
} > "$NOTES"

Command — copy this

chmod 600 "$NOTES"

Windows: WSL/Git Bash, or restrict the file in your profile.

NEVER: install stalkerware or anti-spy APKs from chat NEVER: teach or practice hiding from Settings NEVER: put live passwords or victim data in NOTES

Mission: indicators file in spyware-indicators.txt (mode 600)

1) Write that stalkerware often needs physical or account access, and that you will not install or operate it. 2) If it is safe, review YOUR Apps / Accessibility / Device admin / Battery and list mismatches (labels only). 3) If IPV or coercion is possible, write that safety planning and official help come first — no DIY evasion. Save to $HOME/cyberlium-lab/spyware-indicators.txt and chmod 600. No samples. No dossiers about other people.

Stuck? Ask Cyberlium AI Mentor

If “I should install a spy app so I know the screens” still feels like learning, ask for a hint — not a product. Try: "Hint only: why does stalkerware usually need physical or account access, which Settings lists on MY phone are enough as clues, and why is safety planning first if a partner may be involved — without how-to for hiding or running it?" You still fill the notes. No samples.

You now treat spyware as unwanted observation, stalkerware as something that often needs a hand on the phone or the account, and clues as battery, permissions, hidden icons, location, Device admin, and Accessibility — patterns, not a sport. Safety planning outranks DIY when a person close to you may be involved. Next — Quiz — Android Threats — ten APPLY items on APKs, fake store listings, banking trojans, and these indicators, then Android Hardening begins with Dangerous Permissions to Avoid.

Knowledge Check

1

APPLY: After a partner borrowed the phone, battery dies overnight, an unknown Accessibility service is on, and a package has always-on location. IPV feels possible. First frame?

Multiple choice

Knowledge Check

2

APPLY: The phone is only yours. Settings shows com.ultra.battery.example (fiction) as Device admin with SMS and hidden icon. Correct lab action?

Multiple choice

Knowledge Check

3

APPLY: True or False: A warm battery alone proves stalkerware, so you should follow an internet guide on hiding your Settings checks from a monitor.

True or False

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)