Your phone feels warm in your pocket, the battery doesn’t last until evening, and you start to wonder whether something is running on it that shouldn’t be. The temptation is to install the first app that promises to clean everything up. Before you do, it’s worth knowing that your phone already has several tools for answering that question, and that each one sees a different part of the picture.
Understanding how malware scanning works helps you read the results without anxiety: “no threats found” is not an absolute guarantee, and a warning is not always a disaster. Malware is software designed to damage a device or steal data, often without you noticing; the tools that look for it work with clues, not certainties.
This post goes through those tools one by one, with their real advantages and limits, without naming any product. It is the technology side of the recommendation on spotting malware on your phone: the tools keep watch, but you are usually the first to notice the everyday signs.
How to read this list
The technologies are organised into four functions, the same ones used in the post on what to do if your phone has malware:
- prevention — stopping a harmful app from installing or staying active;
- detection — noticing that something on the phone is behaving oddly;
- response — isolating the problem and getting the phone back to a clean state;
- governance — the habits that keep everything in order over time, including in a family or at work.
For each one you’ll find the risk it reduces, its advantages, its honest limits, and how complex it is to use. None of them, on its own, can tell you for certain that your phone is clean.
1. Prevention technologies
Built-in system protection
The security service that comes with your phone’s operating system, switched on by default on most devices. It checks apps when you install them and checks them again from time to time afterwards. The check at installation is covered in the post on built-in protection against harmful apps; here we look at what happens after that.
- Risk reduced: harmful apps already on the phone, including ones that arrived from outside the official store.
- Advantages: it works in the background, without you having to start it; it knows the system from the inside, so it sees things an outside app cannot; when it finds something, it can disable the app or offer to remove it.
- Limits: it is more effective against known threats than new ones; if you switch it off to install an app it was blocking, it stops protecting you exactly when you need it.
- Complexity: none for you, as long as you leave it on.
Signatures of known malware
The oldest and most widespread method. A signature is a kind of fingerprint of a piece of malware that has already been studied: a set of features that identifies it. The scan compares every app against a large list of these fingerprints.
- Risk reduced: malware that has already been identified and catalogued, and that keeps circulating in identical or near-identical copies.
- Advantages: it is precise, fast, and produces few false alarms.
- Limits: it only recognises what someone has already seen; a modified version of the malware can slip through until the list is updated.
- Complexity: none for you.
System and definition updates
Signature lists, analysis rules, and fixes to the system all arrive with updates. A scanning tool is only as good as its latest version.
- Risk reduced: malware that exploits flaws already fixed, and threats the protection doesn’t yet know about.
- Advantages: by keeping your software up to date automatically, the protection improves on its own while you get on with other things.
- Limits: a phone that no longer receives updates stays exposed to new flaws; the Resource on what happens when device updates stop covers this.
- Complexity: basic.
2. Detection technologies
Behaviour analysis
Instead of asking “does this app look like known malware?”, behaviour analysis asks “does this app behave like malware?”. It watches what an app does: whether it starts up secretly, hides its own icon, asks for permissions out of proportion to its purpose, or keeps sending data to unusual addresses.
- Risk reduced: new or modified malware that no signature knows about yet.
- Advantages: it can pick up threats nobody has seen before; it complements signatures, which look backwards, by watching what is happening now.
- Limits: it works on probabilities, so it sometimes flags legitimate apps that do unusual things; cautious malware that only wakes up occasionally can go unnoticed.
- Example: a torch app installed yesterday asks for access to your notifications and runs in the background all night; the system flags it as suspicious.
- Complexity: none for you; you just need to read the warning calmly.
Battery statistics by app
The section of your settings that shows how much battery each app has used, often separating on-screen use from background use, meaning the time an app is working while you aren’t using it.
- Risk reduced: apps that work in secret and stay active while the phone seems to be idle.
- Advantages: the figures come from the system itself, not from a third-party app; they let you compare what you see with what you’d expect. How to read unusual consumption is explained in the post on a phone battery draining fast.
- Limits: they don’t say why an app is using power; malware can use a name that looks like a system component; an ageing battery shortens battery life without any app being to blame.
- Example: a game you haven’t opened for days is near the top of the list, almost all of it in the background. It’s a clue worth following up, not proof.
- Complexity: basic.
Usage by app: data, memory and storage
The system also keeps track of how much data each app uses, how much memory it takes up, and how much storage it fills. Data has a post of its own, on monitoring your data usage; here it’s enough to know that these statistics are best read together.
- Risk reduced: apps that send information or use resources for no reason connected with what they do.
- Advantages: cross-checking several statistics cuts down false suspicions: an app that uses battery and data in the background, without you using it, deserves more attention than one that does only one of the two.
- Limits: the entries change name and position from one phone to another; some legitimate apps, such as backup or navigation apps, use a lot by nature.
- Complexity: basic.
Scanning with a security app from an official source
Dedicated apps that run scans on demand or on a schedule, also using signatures and behaviour analysis. Only install them from the official store and from developers you can identify.
- Risk reduced: malware that has slipped past the other checks, especially on phones that no longer receive system updates.
- Advantages: they offer a second opinion; some add link checking.
- Limits: on a phone every app lives in its own isolated space, so a security app sees less than it would on a computer; some show exaggerated alarms to push you into paying. There are also imitations that are themselves the problem: the Resource on fake security apps explains how to recognise them. One app is enough; several at once don’t add up to more protection, only, quite often, to more battery drain.
- Complexity: basic.
3. Response technologies
Safe mode
Many phones offer a way of starting up that loads only the system and the pre-installed apps, leaving everything you’ve added switched off. It is called safe mode, and how you turn it on varies from one model to another.
- Risk reduced: harmful apps that restart themselves or resist being removed while they’re running.
- Advantages: it’s a simple experiment: if the phone is fast again and the battery lasts in safe mode, the cause is very likely an installed app; in this mode, a suspicious app is often easier to uninstall.
- Limits: not every system offers it; it doesn’t tell you which app is responsible, so it needs to be combined with the statistics.
- Example: in safe mode, the full-screen adverts that kept appearing outside your apps disappear: the problem lies in an app you installed recently.
- Complexity: intermediate.
Removing the app and revoking special permissions
Uninstalling the suspicious app, after first revoking its most sensitive permissions: access to notifications, accessibility, and device administration. The last of these is a special permission that, if granted to a harmful app, can stop it from being removed until it is taken away.
- Risk reduced: apps that go on reading your data, notifications and verification codes.
- Advantages: it resolves most common cases; how to recognise the apps to remove is explained in the recommendation on removing unknown apps from your phone.
- Limits: if the app has already read passwords or codes, removing it isn’t enough: the credentials need changing, ideally from another device.
- Complexity: basic.
Factory reset
The operation that erases all data, apps and settings, returning the phone to the state it was in when it left the factory.
- Risk reduced: infections that survive the other remedies.
- Advantages: it is the most thorough remedy within anyone’s reach, effective against the vast majority of common infections; afterwards you have a phone whose contents you know.
- Limits: without a backup you lose your photos and documents; restoring a backup wholesale can reinstall the same app; it doesn’t repair accounts that have already been compromised. It is the last option, not the first.
- Example: after removing the suspicious app the symptoms continue; you save your photos and contacts, run the reset, and reinstall from the store only the apps you actually use.
- Complexity: intermediate.
4. Governance technologies
These are what keep the other technologies effective over time, especially when there is more than one phone to look after.
Regular backups
Periodic copies of your photos, contacts and documents, to a storage service or another device.
- Risk reduced: having to rule out a factory reset for fear of losing everything.
- Advantages: it turns the last option into a calm choice; useful for theft and breakdowns too.
- Limits: backing up apps, not just data, can bring the problem back with them.
- Complexity: basic.
Managing phones in the family and at work
Parental controls on children’s phones and, in organisations, centralised device management: a system that applies the same security rules to every work phone.
- Risk reduced: protections switched off by mistake, and apps installed without a second thought.
- Advantages: it keeps protections on even on the phones of less experienced people; it makes it possible to act quickly on a compromised device.
- Limits: it needs to be explained, not imposed; on work phones it must respect the private life of the person using them.
- Complexity: intermediate.
Comparison table
| Function | Technology | Risk reduced | Main advantage | Main limit | Complexity |
|---|---|---|---|---|---|
| Prevention | Built-in protection | Harmful apps already installed | Works in the background | Less effective on new threats | None |
| Prevention | Signatures | Known malware | Precise and fast | Can’t see what’s new | None |
| Prevention | Updates | Known flaws and old definitions | Improves on its own | Ends when support ends | Basic |
| Detection | Behaviour analysis | New or modified malware | Catches the unknown | False alarms | None |
| Detection | Battery statistics | Hidden activity | Figures from the system | Doesn’t explain why | Basic |
| Detection | Usage by app | Disproportionate use of resources | Cross-checked clues | Entries vary by model | Basic |
| Detection | Security app | Threats that slipped through | Second opinion | Sees less than the system; imitations exist | Basic |
| Response | Safe mode | Apps that restart themselves | Isolates the cause | Doesn’t name the app | Intermediate |
| Response | Removal and permission revocation | Apps reading your data | Resolves common cases | Doesn’t repair accounts | Basic |
| Response | Factory reset | Persistent infections | A clean phone | Erases everything | Intermediate |
| Governance | Backups | Fear of losing data | A calm reset | Can bring the problem back | Basic |
| Governance | Phone management | Protections switched off | Consistent rules | Needs explaining | Intermediate |
How to choose
If you’re an individual. Leave the built-in protection on, accept updates, and look at your battery and data statistics once a month: once you know what normal looks like, anything unusual stands out straight away. If something doesn’t add up, safe mode will tell you whether an app is the cause. An extra security app makes most sense when the phone no longer receives updates.
If you have a family. Check that the built-in protection is on for your children’s and parents’ phones too, and set up automatic backups for everyone. Explain that a “virus” warning that pops up while browsing and asks you to install something is almost always a trick: that’s the subject of the Resource on scareware, the warning that is itself the attack.
If you use your phone for work, or run a small organisation. Add centralised device management and an agreed procedure for anyone who notices odd behaviour: who to tell, how to isolate the phone, who changes the credentials.
A rule of thumb. Malware scanning reduces the risk a great deal, but no scan sees everything: signatures don’t know what’s new, behaviour analysis sometimes gets it wrong, outside apps see less than the system does. The combination that gives the best result for the effort is built-in protection switched on + updates + a monthly look at the statistics: the technology looks for what is known, and your knowledge of your own phone notices what is out of place.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how signatures, behaviour analysis and statistics work, and using safe mode and a factory reset when they’re needed |
| Awareness | Recognising that “no threats found” is an indication, not a guarantee, and that a fake security app can be the problem itself |
| Secure Behaviour | Keeping protections on, updating, and checking consumption regularly, not only when you’re worried |
Reference level: FL3 — Autonomous. This is the level at which you use your own device’s tools without step-by-step guidance, knowing how to interpret what they show and when to ask for help.
Conclusion
No malware scan is infallible, and none needs to be: signatures recognise what is known, behaviour analysis watches the present, statistics show what the eye can’t see, and safe mode and a factory reset offer a way out. Knowing how they work leaves less room for fear and more for decisions.
To see how solid your digital habits are overall, you can start with the digital resilience self-assessment.
What to do next. Check in your settings that the built-in protection is switched on, and look at the battery statistics for the last few days. Make a note of the three apps that use the most: they’ll be your reference point next time you check.
Related content
- Spotting malware on your phone — the recommendation this belongs to
- What to do if your phone has malware — how to put these technologies into practice, in order
- Malware hidden in apps — the threats these scans look for
- Phone battery draining fast — the signs to read in your phone’s statistics
Related resources
Short reads from the Resources section, for anyone who wants to focus on a single aspect:
- Phone Running Slow: Malware, or Just an Older Device?
- Fake Security Apps: When the Protection Is the Problem
- Scareware: The Warning That Is Itself the Attack
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



