Mark is looking for his parking app. Scrolling through the full list of apps, he stops at an entry that means nothing to him: “System Service”, with a grey cog-shaped icon. He doesn’t remember installing it. The first explanation is the most reasonable one: “It must be something that came with the phone.” Quite often, that is exactly what it is.
Sometimes, though, an unknown app has arrived another way: downloaded by a different app, installed by someone who had the phone in their hands, or disguised as a legitimate application. And at that point the question “where did it come from?” gives way to a more useful one: if I didn’t choose it, what is it allowed to do?
This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that the risks of apps installed without your knowledge amount to much more than “one extra icon”.
It expands on the recommendation about removing unknown apps from your phone with a regular check. We’re not talking here about apps you installed yourself and then forgot, which are covered by the recommendation on removing the apps you no longer use, but about the ones you never chose at all.
Three questions to measure an impact
Faced with any app you don’t recognise, and before you even decide whether to remove it, these are the right questions to ask:
- What can an app I didn’t choose find out about me? — this is the confidentiality question.
- What can it change or do on the phone in my place? — this is the integrity question.
- What does it take away from me: battery, data, speed, money? — this is the availability question.
When you install an app on your own initiative, these questions at least have a first answer: you read the description, you saw the permissions it asked for, you made the decision. An app that arrived without your knowledge skips exactly that step. That is where the maths changes: the impact of an unknown app isn’t measured by what it claims to be, but by what it has been allowed to do — and, by definition, those permissions are ones you never weighed up.
1. Confidentiality: your location, messages, voice and photos stay yours
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. An app installed without your knowledge weakens it because it can gather information on behalf of someone you don’t know, through the permissions it has obtained: the authorisations to access your location, contacts, microphone, camera, photos and notifications.
A practical example
In the list of apps there’s a “Wi-Fi Manager” you never went looking for. Opening its page in the settings, you find it has access to your location “all the time”, to the microphone and to your photo gallery. A connection manager needs none of the three: those permissions tell you more about its real purpose than its name does.
What the incident looks like
The most delicate case is an app installed by someone who had physical access to the phone, even for just a few minutes. There are programs designed specifically to watch someone in secret: they’re called stalkerware, and the article on stalkerware and spy apps explains how they work. In this scenario the data doesn’t end up in an anonymous archive, but with someone who knows you: where you’ve been, who you’ve been writing to, what you’ve photographed. The gathering itself is already the harm, and it rarely shows on the screen.
What to watch for
- an app you don’t recognise appears among those that have recently used your location, microphone or camera;
- the microphone or camera indicator lights up when you aren’t using any app that needs it;
- an unknown app turns out to be allowed to read your notifications, meaning it can see previews of messages, emails and verification codes;
- someone seems to know where you’ve been or what you’ve written.
These are clues, not proof: the signs of a hidden app are best read calmly, telling them apart from the harmless explanations.
What to do
Before removing an app you don’t recognise, open its page and look at what it can access: that tells you what to check afterwards. Then review the phone’s list of permissions, as suggested in the recommendation on checking what your apps can do. If you suspect someone has installed an app to keep tabs on you, move carefully and, if you feel unsafe, first seek support from a person you trust or a specialist service: removing the app can alert whoever installed it.
2. Integrity: the phone does only what you’ve decided
Integrity is the guarantee that data and settings aren’t altered by anyone without the right to do so. Here an unknown app weighs in a different way: it’s no longer about what it can see, but about what it can change or do on the phone in your place.
A practical example
For a few days now the browser has been opening on a home page you didn’t choose, and adverts are appearing even on top of apps that have never shown any, such as the calculator. This is injected advertising: adverts inserted by an app that has obtained permission to appear over other applications.
What the incident looks like
The most insidious changes involve the phone’s special roles. An app that registers itself as a “device administrator” — a role intended for functions such as locking or wiping the phone remotely — becomes much harder to remove: the uninstall button may be greyed out. An app that gains access to accessibility services, which are designed to help people who find the screen difficult to use, can read what appears on it and tap buttons on your behalf: in practice, remote control of the phone. If you come across an app that resists removal, the guide on how to remove an app that will not uninstall explains the steps to follow.
What to watch for
- settings that are different from how you left them: the browser home page, the default keyboard, the app used for text messages;
- adverts that appear over other apps or on the lock screen;
- an unknown app in the list of device administrators or among those with accessibility access;
- the button to uninstall an app is disabled, or the app comes back after you’ve removed it.
What to do
Every so often, check two lists that hardly anyone ever opens: device administrators and apps with accessibility access. They should contain only things you recognise. To find apps that have no icon on the home screen as well, the article on how to find every installed app shows you where to look.
3. Availability: your battery, data and money stay at your disposal
Availability is the guarantee of being able to use your phone, your data and your services when you need them. It’s the easiest impact to notice, because you can feel it in your hand and, sometimes, see it on your bill.
A practical example
You downloaded a torch app from a link you found on a website, outside the official store. The torch works, but it has installed a second component with no icon that runs in the background, meaning while you aren’t using it. The phone gets warm while idle and the battery lasts half a day.
What the incident looks like
A loss of availability can remain a nuisance or turn into a cost. In the mild version, the phone slows down and apps are sluggish to open. In the more concrete version, the app signs you up to paid services charged to your mobile credit or your phone bill: small amounts every week, which carry on until someone notices. To keep the data side under control, there’s the recommendation on keeping an eye on your data usage.
What to watch for
- a battery that drains noticeably even when the phone is idle;
- data usage attributed to an app you don’t recognise or never open;
- sudden slowdowns that aren’t linked to a recent update or to a full memory;
- charges on your credit or phone bill for services you never asked for.
What to do
Look every now and then at which apps use the most battery and the most data: an unfamiliar name at the top of the list deserves a closer look. Check the itemised detail of your phone bill too, and ask your mobile provider to block premium-rate services. If an app resists removal, a scan with a reliable security app, downloaded from the official store, can help; if instead the signs point to wider malware — software designed to cause harm — the recommendation on spotting the signs of malware on your phone helps you read the situation.
| Aspect | What an app installed without your knowledge can do | Why it matters |
|---|---|---|
| Confidentiality | Gathers your location, messages, audio from the microphone, photos and notifications | The information reaches someone you don’t know, or someone who knows you all too well |
| Integrity | Changes settings, inserts adverts, takes on special roles and acts in your place | Makes the phone less yours and the app harder to remove |
| Availability | Uses up battery and data, slows the phone down, signs you up to subscriptions | It’s the impact you can see, but it often arrives after the other two |
One scenario that brings them together
Mark receives an email that appears to come from a supplier: “The document is in a special format, download the reader from here.” He downloads the app from an external page, reads the document and forgets about it. Meanwhile, the app has installed another one, with no icon, called “Service Update”.
From there, in sequence: the second app gains access to notifications and location, and starts sending message previews and places visited somewhere else (confidentiality); it registers itself as a device administrator and inserts adverts over other apps (integrity); it works day and night in the background and signs him up to a weekly subscription charged to his credit (availability). Three different impacts, a single origin: an app that came from a source other than an official store, as the recommendation on downloading apps only from official stores points out.
The impacts that show up later
Some effects remain even after the app has gone: “I uninstalled it, that’s the end of it” isn’t always a complete check.
- Data that has already left. Whatever the app gathered before it was removed — locations, photos, conversations — stays wherever it was sent. You can limit how it’s used by changing the passwords of any accounts whose codes passed through your notifications.
- Twin apps. If you remove an app but the component that downloaded it stays, it can reinstall it.
- Permissions and roles left with another entry. An administrator role or accessibility access granted to a component with a different name keeps working until you revoke it.
- Recurring charges. A subscription activated behind your back doesn’t stop when the app is removed: it has to be cancelled with the mobile provider or the service itself.
This isn’t a reason to look at your phone with suspicion. It’s the reason the regular check matters: reviewing the full list of apps and the special permissions every so often reduces all four of these effects, including the ones you’ll never see. If you want to understand what happens when a hidden app stays on a phone for a long time, the follow-up is in consequences of a hidden app on your phone.
Not all unknown apps weigh the same
The impact depends on what the app has obtained, more than on what it’s called.
| What the app has obtained | Main impact | Why |
|---|---|---|
| Accessibility services | All three, with a multiplier effect | It reads the screen and acts in your place, even granting itself other permissions |
| Device administrator role | Integrity and availability | Makes the app hard to remove and can lock phone functions |
| Access to notifications and text messages | Confidentiality and integrity | Sees messages and verification codes, which are the temporary keys to your accounts |
| Location, microphone, camera, photo gallery | Confidentiality | Reveals places, conversations and private images |
| Appearing over other apps | Integrity | Inserts adverts or screens that imitate the real ones |
| Permission to install other apps | Low on its own, high as a way in | It’s how one unknown app brings in others |
The last row is the one that counts: the app that seems to do nothing may be the one that let the others in.
Why a “system” app matters too
Some apps installed without your knowledge are built precisely to look harmless or untouchable.
| How it presents itself | Why it’s still risky |
|---|---|
| A generic name such as “System Service” or “Update” | It discourages removal: you worry about breaking something |
| No icon on the home screen | You never see it, but it keeps working in the background |
| A duplicate of an app you already use, with an almost identical icon | It imitates a legitimate app to gather data or sign-in details |
| A “cleaner” or “protection” app you never installed | It promises to solve a problem and often creates one |
Many apps you don’t remember are perfectly legitimate, installed by the manufacturer or the mobile provider. The point isn’t to distrust everything, but to know that the name alone isn’t enough to decide.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that an app you didn’t choose brings with it permissions nobody has weighed up |
| Skills | Being able to read confidentiality, integrity and availability as three concrete questions about an unknown app |
| Secure Behaviour | Regularly checking the full list of apps, their permissions and the special roles |
Reference level: FL2 — Beginner. This is the level at which you move from “there’s an app I don’t know” to “I understand what it could do and where to look”. To see where you stand, you can take the digital resilience self-assessment.
Summary
- Confidentiality is about what the app gathers: location, messages, audio from the microphone, photos, notifications.
- Integrity is about what the app changes or does in your place: settings, injected advertising, special roles, remote control.
- Availability is about what the app takes away from you: battery, mobile data, the phone’s speed, money in the form of subscriptions.
An unknown app isn’t always dangerous. But when it is, you read the danger in the permissions it holds, not in the name it shows.
One thing to do today. Open your phone’s settings and check three lists: all installed apps, including those without an icon; apps with accessibility or notification access; and device administrators. It takes about ten minutes, and it covers all three impacts at once.
Related content
- Removing unknown apps from your phone — the recommendation this expands on
- Consequences of a hidden app on your phone — from technical impacts to concrete effects on money, relationships and personal safety
- Signs of a hidden app — how to notice that one of these impacts is already under way
- How to remove an app that will not uninstall — what to do when an app resists removal
- How to find every installed app — where to look to see apps without an icon too
- Stalkerware and spy apps — how apps designed to watch someone in secret work
- Unused apps still active on your phone — the signs that concern forgotten apps
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- App Permissions: Deciding What Each App Can Reach
- Fake Security Apps: When the Protection Is the Problem
- Phone Running Slow: Malware, or Just an Older Device?
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



