Android › Module 3 › Lesson 2
What to Do If Your Phone Is Infected
Containment steps: revoke access, remove apps, reset safely, and recover accounts
Opening
Shame is a delay tactic. Do not keep "just checking" the bank on a dirty phone — the next 15 minutes are containment of YOUR device and YOUR accounts.
Battery nosedives. An Accessibility service you do not remember sits in Settings. A cleaner you sideloaded hid its icon. Banking opens and the login looks a pixel off (Module 1 overlays). Freeze feels moral — as if sitting still undoes the install. Attackers budget for that freeze. Every extra transfer you confirm on the infected handset is another OTP the overlay can steal, another session cookie a notification listener can copy, another minute Device admin uses to block uninstall. This lesson is incident response for a phone you own and accounts you own. You will contain, then recover access you still control. You will not hack the malware C2 back. You will not remotely wipe someone else's device. You will not "find the stalker" with locate tools, exploits, or doxxing. Factory reset is a last step on YOUR hardware after photos you care about are copied as files — not as a full app backup that reinstalls the trojan. Topic 5 taught the same shape for a phishing click: order beats panic. Topic 4 taught unique passwords and MFA. You will use both — from a CLEAN device — after you stop feeding the dirty one.
1. Stop using money apps on the dirty phone — contain the session
If you suspect infection, the banking app on that handset is a hostile keyboard. Do not type the PIN, password, or OTP there. Do not "check the balance to see if it is real." Do not approve a push from a prompt that appeared over the real icon. Disconnect Wi-Fi and mobile data if money is actively leaving or the device is screaming traffic you cannot explain — that is containment, not a forever airplane lifestyle. Then pick up a second phone, a computer, or a family member's device they consent to lend for five minutes: a CLEAN session you initiate. Containment means: stop giving the malware more. Close the overlay. Do not install a second "antivirus APK" from a blog to "fight" the first one — that is how droppers stack. Do not factory-reset yet if you have not copied photos you cannot replace; reset without a file backup is how people postpone IR until next year. Do not keep browsing the mystery app "to screenshot proof" while it still has Accessibility. A click-plus-OTP on a dirty phone is a credential-and-device incident. Shape is the same as Topic 5: stop the poisoned session, recover from a session you started on hardware you still trust.
If the phone is also a possible stalkerware situation (someone had your PIN, insisted on "checking" the device, installed a "parental" or "anti-theft" tool you did not want), the technical order below still applies to YOUR phone — uninstall mystery admin, reset YOUR device if it persists — but personal safety may come first: a trusted person, local resources, evidence you already have. That is not a license to hack their phone, remotely wipe them, or run a find-the-installer attack. You recover a device you own. You do not counter-stalk.
2. From a CLEAN device: revoke sessions, then rotate secrets (Topic 4 / 5)
Password change and session revoke happen off the dirty phone. On a computer or second phone you trust, type the real Google account, bank, mail, and authenticator-issuer URLs (or the password manager's saved official origins). Sign out other sessions / devices. Then generate unique passwords in the manager. Enable or confirm MFA (authenticator or key; SMS is weaker and is exactly what SMS-permission malware wanted). If you typed an OTP into an overlay, assume the attacker completed login until sessions are dead and the password is new. Priority order: Google (it is the phone's identity and Find My Device), primary email (it resets everything else — Topic 4), banking and wallets, then messengers. Review account activity for devices you do not own. Call the bank using the number on YOUR card if money moved — not a number in an SMS, not in-app chat on the dirty phone. Topic 5's 15-minute sheet still holds: forwarding rules and recovery phone/email on mail you own; no reset of a classmate's inbox "to practice." Work MDM or payroll: tell IT facts (time, what you installed, what you typed). You are containing blast radius, not confessing a crime for installing a flashlight.
Authenticator apps on the dirty phone may be compromised if Accessibility or notification access was granted. After cleanup you will re-enroll MFA from backup codes you stored OFF the phone (next lesson). If those codes exist only on the infected device, recover via each site's official account-recovery on a clean browser — still only accounts you own. Do not paste new passwords, OTPs, or backup codes into this app, Discord, or Mentor.
3. On the phone: mystery apps, Device admin, Accessibility — then reset if it persists
Settings → Accessibility. Settings → Device admin / Device admin apps (OEM names vary). Settings → Special app access → Notification access, Appear on top / Display over other apps, Device administrators. Anything you do not recognize: disable, then uninstall. Play Protect scan is a supporting check, not a blessing that mystery admin is fine. If uninstall is blocked, boot Safe Mode (OEM steps differ; search YOUR model's official help) so most third-party apps do not start, then uninstall. Safe Mode is a tool on a device you own. It is not a way to rummage someone else's phone. If the malware persists — icon returns, admin re-enables, overlays continue, you cannot revoke Accessibility — factory reset the device you own after you have copied photos and documents as files (USB, cloud photos, a computer), not as a full "apps + data" backup. Next lesson is the backup split in detail. Reset wipes the handset you control. It does not wipe a partner's phone from the cloud. After reset: reinstall only from Play (Module 2 checklist), deny radioactive permissions, then sign into accounts whose passwords you already rotated from the clean device. Monitor bank alerts for a few days. Shame can wait. The checklist cannot.
Do not "hack back" the APK author. Do not upload the sample to a random Telegram "analyst." Do not DDoS a domain you found in a log. Do not use Find My Device to hunt a person who may have installed stalkerware. If you need a professional opinion, use official bank fraud lines, platform report buttons, or a local helper you already trust — with facts, not revenge. Persistence is a reset problem on your silicon. It is not a license to attack.
4. Wrong vs right: keep banking on the dirty phone vs a 15-minute-plus contain
Worked failure — same suspected infection, opposite next quarter-hour. Recovery is YOUR phone and YOUR accounts only.
Wrong
You open the bank app on the suspect phone "to check," re-type the PIN when an overlay asks, wait overnight because you feel stupid, and install a second unknown antivirus APK from a blog. You skip session revoke because "I will change the password later on this phone." You try to dox whoever installed spyware, remotely wipe their device, or factory-reset a phone that is not yours. You restore a full app backup immediately after reset. Shame plus revenge plus the dirty keyboard — that is how 15 minutes become a drained account.
Right
You stop using banking and mail ON the dirty phone (disconnect if money is leaving). From a CLEAN device you own (or are lent with consent), you revoke Google/bank/mail sessions, set unique passwords, enable MFA. On the phone you own: disable mystery Accessibility / Device admin / notification access, uninstall unknowns (Safe Mode if blocked), Play Protect scan. If it persists: copy photos as files, factory-reset YOUR device, reinstall from Play only. You write the order into $HOME/cyberlium-lab/android-ir.txt and chmod 600. No hack-back. No someone else's wipe. No find-the-stalker.
5. Practical: write YOUR Android IR order in cyberlium-lab
This is a notes lab, not a live malware exercise. You will not download a "test trojan." You will not scan other people's phones. You will not enter a real bank PIN into this app. You will write the order you will actually follow on a device you own, then chmod 600. If you have never had an infection, you still want the sheet — IR that starts after freeze is too late. The filename is android-ir.txt on purpose so it sits next to Topic 5's phishing-15min.txt as the mobile sibling.
Command guide
Suspected Android malware — YOUR phone, YOUR accounts, no hack-back
Notes lab. Do NOT install malware to "practice IR." Do NOT paste live passwords, PINs, OTPs, or backup codes into this file.
Command — copy this
mkdir -p "$HOME/cyberlium-lab" NOTES="$HOME/cyberlium-lab/android-ir.txt"
Command — copy this
{
echo "android IR checklist — MY phone and MY accounts only"
echo "date: $(date -Iseconds 2>/dev/null || date)"
echo ""
echo "0. SHAME DELAY: I will not wait until morning. Freeze helps the malware."
echo "1. STOP BANKING ON THIS PHONE: no PIN, password, or OTP on the suspect handset."
echo " If money is leaving or traffic is wild: disconnect Wi-Fi / mobile data."
echo " Continue from a CLEAN device I own (or am lent with consent)."
echo "2. CLEAN DEVICE — ACCOUNTS I OWN:"
echo " Google: revoke other sessions / devices. Unique password. MFA."
echo " Mail (reset hub): sessions, forwarding, recovery phone/email. Unique + MFA."
echo " Bank/wallet: official site I type or the number on MY card — not SMS links."
echo " Topic 4 uniqueness. Topic 5 session revoke. No classmate accounts."
echo "3. ON MY PHONE:"
echo " Accessibility — disable mystery services"
echo " Device admin — deactivate unknown admins, then uninstall"
echo " Notification access / appear-on-top — revoke strangers"
echo " Uninstall unknown apps. Safe Mode if uninstall is blocked (MY OEM help)."
echo " Play Protect scan — supporting check, not a blessing"
echo "4. IF IT PERSISTS: copy photos/docs as FILES (not full app backup)."
echo " Factory reset THIS phone I own. Reinstall from Play only."
echo "5. AFTER: monitor bank alerts. Re-enroll MFA from OFF-PHONE backup codes."
echo ""
echo "ETHICS (write these so I remember under stress):"
echo "Recovery = MY phone + MY accounts. No hack-back. No doxxing."
echo "No remote wipe of someone else's device. No find-the-stalker attacks."
echo "Factory reset is for hardware I own. No revenge C2 scans."
} > "$NOTES"
chmod 600 "$NOTES"
ls -l "$NOTES"NEVER: type bank secrets on the dirty phone to "see if it still works" NEVER: sideload a second antivirus APK from a blog NEVER: reset or locate a phone that is not yours NEVER: paste new passwords into tickets, Discord, or Mentor
Mission: one Android IR sheet for a phone and accounts you own
1) Create $HOME/cyberlium-lab/android-ir.txt with the order: stop banking on the dirty phone → revoke/rotate from a CLEAN device → Accessibility/Device admin/notification revoke + uninstall (Safe Mode if needed) → factory reset YOUR device if it persists after file-only backup → Topic 4/5 unique passwords + MFA. chmod 600. 2) Read it once out loud so shame cannot reorder the steps. 3) Circle (on paper) one CLEAN device you could use for Google/bank recovery. Do not install malware to practice. Do not hack back. Do not wipe or hunt anyone else's device.
Stuck? Ask Cyberlium AI Mentor
If "I already uninstalled the icon, so I can bank on this phone now" still feels finished, ask for a hint — not a revenge script. Try: "Hint only: why must I stop using banking ON a suspected-infected phone, revoke sessions from a CLEAN device, disable mystery Accessibility/Device admin, and only factory-reset a phone I own — and why is finding or wiping someone else out of scope?" No spoilers; you still write android-ir.txt for your device.
You now treat a suspected Android infection as a timed incident: stop feeding money apps on the dirty handset, kick sessions from a clean device with Topic 4/5 secrets, revoke the permission plane malware loves, reset hardware you own if it persists, and refuse shame, hack-back, and someone else's wipe. Next — Backup Hygiene for Mobile — you will split photos and documents from APKs and "restore all apps," adapt 3-2-1 to a phone, and keep 2FA backup codes off the device so a wipe does not destroy your life or bring the trojan home.
Knowledge Check
APPLY: Accessibility you do not remember is on. You need to see if the bank was drained. First move that matches this lesson?
Multiple choice
Knowledge Check
APPLY: You changed Google's password on the infected phone's browser. You did not open Security → devices on a clean computer. Why can the attacker still be "in"?
Multiple choice
Knowledge Check
APPLY: True or False: Waiting overnight "because I feel stupid," then factory-resetting a roommate's phone to "practice IR," is a reasonable first control.
True or False