Mark notices it on the train home from work. His phone is warm in his pocket even though he hasn’t touched it for an hour, and the battery is already below twenty per cent. The first explanation that comes to mind is the simplest: “It’s just getting old.” Very often, that’s exactly right.
Sometimes, though, behind that slowness and that drain there is malware: software designed to act on a device without you knowing, to collect information, show advertising, use the phone’s resources or take control of it. At that point the question “is it malware or not?” gives way to a more useful one: if it were, what would be touched?
Battery life and speed are only the visible part. The impact of malware on your phone is measured on the three aspects by which the security of any information is judged: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability.
This post expands on the recommendation on spotting malware on your phone from the signs your device gives you. It doesn’t repeat how to read those signs or what to do when you notice them: it focuses on what is at stake.
Three questions to measure an impact
Before getting into the details, it’s worth having the right questions at hand. They apply to any app, and not only when something seems wrong:
- What could a hidden program on my phone read or collect? — this is the confidentiality question.
- What could it change, install or send in my name? — this is the integrity question.
- What would I no longer be able to use: the phone, the battery, my data, my accounts? — this is the availability question.
Applied to a phone, these three questions almost always produce the same answer: a lot. A phone is not just another device. It receives the codes that confirm your payments, holds your conversations, knows where you are and is used to recover almost every other account you have. That is why the impact of malware is not measured on the phone itself, but on everything the phone can unlock.
1. Confidentiality: your messages, photos, codes and location stay yours
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. Malware weakens it because it can see whatever the apps you have authorised can see.
A practical example
You installed an app to scan documents. When you first opened it, it asked for access to your notifications “so we can tell you when your scan is ready”, and you agreed without a second thought. From that moment on, the app can read the content of every notification that arrives: messages, email previews and verification codes — the short-lived numbers a service sends you to confirm that it really is you.
What the incident looks like
A phone holds far more than most people think: photos of identity documents, screenshots of bank details, private conversations, the history of the places you have been. Malware that collects this information doesn’t need to change anything: it copies it and sends it elsewhere, often while the phone is idle. The harm has already happened, even though nothing shows on the screen.
What to watch for
- apps asking for permissions that have nothing to do with what they do, such as a torch app that wants to read your text messages;
- verification codes arriving for sign-ins or payments you didn’t start;
- apps allowed to read notifications or to use accessibility services without you remembering granting it;
- background data use that doesn’t match how you use the phone, a topic covered by the recommendation on keeping an eye on your data usage.
What to do
Every so often, open the list of apps with access to notifications, text messages, location and camera, and ask whether each one really needs it. That is the idea behind the recommendation to check what your apps can do: removing a permission from an app that doesn’t need it reduces what any malware could see.
2. Integrity: your phone and your accounts do only what you decide
Integrity is the guarantee that data and settings aren’t altered by anyone without the right to do so. Here malware weighs in a different way: it’s no longer about what it can see, but about what it can change or do on your behalf.
A practical example
One morning you find an icon on your home screen for an app you never installed, and your browser opens on a different home page from usual. In the settings you discover that an app has registered itself as a “device administrator” — a role meant for features such as remote locking, which also makes the app harder to remove.
What the incident looks like
The most damaging changes don’t concern the phone, but the accounts the phone gives access to. Malware with accessibility services switched on — features designed to help people who find the screen hard to use — can read what appears and press buttons for you. It can send your contacts a message with a link, which looks believable precisely because it comes from you: this is the scenario described in the recommendation on messages sent in your name. It can sign you up to premium-rate services charged to your mobile credit or phone bill, or confirm a transaction using the code it has just read.
What to watch for
- apps you don’t remember installing, sometimes with generic names such as “System Service” or “Update”;
- settings that are different from how you left them: browser home page, default keyboard, text messaging app;
- contacts telling you about strange messages sent from your number or your profiles;
- charges on your mobile credit or phone bill for services you never asked for.
What to do
Check the full list of apps and the list of device administrators from time to time. If you find something you don’t recognise, the recommendation on finding and removing unknown apps explains how to go about it calmly. Keep your software up to date with automatic updates: many fixes close exactly the gaps that malware uses to change settings.
3. Availability: battery, performance, data and the phone itself stay at your disposal
Availability is the guarantee of being able to use your device, your data and your services at the moment you need them. It’s the easiest impact to notice, because it’s the one you feel in your hand: the phone that heats up, slows down, runs flat.
A practical example
An app that looks harmless uses the processor in secret, even with the screen off, to run calculations for someone else. This is known as cryptocurrency mining: using a device’s computing power to generate digital currency. The result is a phone that runs hot, a battery that lasts much less and apps that open sluggishly.
What the incident looks like
Losing availability can stay a nuisance or turn into a lockout. In the mild version, the battery drains faster, your mobile data runs out sooner than expected and advertising takes over the screen. In the more serious version, ransomware — malware that locks the device or makes its files unreadable and demands a payment to give them back — shows a screen you cannot close. And if the malware has already used the codes it read to change the passwords of some services, the locked door extends to your accounts as well.
What to watch for
- a battery that drops noticeably even when the phone is resting;
- persistent warmth with no games, videos or browsing going on;
- sudden slowdowns that aren’t linked to a recent update or to full storage;
- windows or screens that keep coming back and won’t close.
What to do
Back up your photos, contacts and documents regularly to a storage device or service separate from the phone: that is what makes a lockout recoverable rather than permanent. If you notice a drop in performance or battery drain you can’t explain, run a scan with reputable antivirus software downloaded from the official app stores. To understand what it can and can’t find, see the explainer on how malware scanning works.
| Aspect | What malware can do | Why it matters |
|---|---|---|
| Confidentiality | Reads messages, notifications, verification codes, photos and location | The harm happens silently, with no obvious trace on the screen |
| Integrity | Changes settings, installs apps, sends messages and signs you up to services in your name | Involves your contacts and your money, and makes recovery take longer |
| Availability | Uses up battery, performance and data, and can lock the phone or your accounts | It’s the sign you can see, but it often comes after the other two impacts |
One scenario that brings them together
Mark’s phone has been slow for a few weeks. While he’s reading an article, a warning pops up: “Your device is infected — install the cleaner now.” Mark taps the button, downloads the app from an external page and grants the permissions it asks for, including access to notifications and accessibility services.
From there, in sequence: the app reads his notifications and intercepts the code his bank sends to confirm a transaction (confidentiality); it sends everyone in his address book a message with the same link and signs him up to a premium-rate service (integrity); it runs in the background day and night, and the phone becomes even slower and flatter than before (availability). Three different impacts, a single origin: an app that promised to fix the very symptom Mark had noticed.
The explainer on malware hidden in apps shows how warnings like this one bring malware onto a phone.
The impacts that show up later
Not every effect appears right away. Some develop over time, which is why “the phone seems fine now” isn’t a reliable check.
- Information used elsewhere. Photos of documents or data collected weeks earlier can resurface in a fake profile or in an attempt to sign in to another service.
- Access that stays open. If the malware used a code to get into an account from another device, that session — the “already signed in” state — can remain active even after the app has been removed.
- Contacts drawn in. A message sent from your number may have reached people who, in turn, installed the same app.
- Recurring charges. A paid service switched on in secret keeps costing money every week or every month, until someone spots it on the bill.
This isn’t a reason to look at your phone with suspicion. It’s the reason protection has to be preventive: installing only what you need, from official sources, and granting only the permissions that are necessary reduces all four of these effects, including the ones you’ll never see. If you want to know what happens when an infection goes unnoticed for a long time, read on in consequences of undetected malware.
Not all the data on your phone weighs the same
The impact depends on what the malware manages to reach and on what that part of the phone can open.
| Part of the phone | Main impact | Why |
|---|---|---|
| Notifications and text messages | All three, with a multiplier effect | They carry the verification codes that open your other accounts |
| Banking and payment apps | Integrity and availability | Transactions confirmed in your name, accounts or cards blocked |
| Photo gallery and documents | Confidentiality | Photos of documents, screenshots, years of private life |
| Contacts and messaging apps | Integrity, with effects on others | Messages in your name that reach people who trust you |
| Location | Confidentiality | Reveals habits, times and places you visit |
| Battery, processor and mobile data | Availability | A slow, flat phone and a used-up data allowance |
| Forgotten apps that are never updated | Low on their own, high as a way in | They’re the most common starting point for a problem |
The last row is the one that counts: the highest risk often comes from the app installed years ago and simply left there. That’s where the recommendation to remove the apps you no longer use comes from.
Why “light” malware matters too
The nuisance you see doesn’t measure the impact you suffer. Some forms of malware seem harmless precisely because they bother you so little.
| Form of malware | Why it’s still risky |
|---|---|
| Adware, which “only shows ads” | It often collects data about your habits and can lead you to deceptive pages |
| An app that “only uses a bit of battery” | It may use the processor for someone else, heat the phone and wear out the battery over time |
| An app that “just” wants notification access | It reads verification codes, the temporary keys to your accounts |
| A subscription that costs “only a small amount” | It’s recurring, and often goes unnoticed for months |
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that slowness and battery drain are only the visible part of wider impacts |
| Skills | Being able to read confidentiality, integrity and availability as three concrete questions about your own phone |
| Secure Behaviour | Regularly checking installed apps, permissions and device administrators |
Reference level: FL2 — Beginner. This is the level at which you move from “I know malware exists” to “I understand what it could touch on my phone”. To see where you stand, you can take the digital resilience self-assessment.
Summary
- Confidentiality is about what gets read: messages, notifications, verification codes, photos, location.
- Integrity is about what gets changed or done in your name: settings, installed apps, messages to your contacts, paid services.
- Availability is about what you can no longer use: battery, performance, mobile data, and even a locked phone or locked accounts.
A slow phone isn’t always a sign of malware. But when it is, the symptom you see is usually the last of the three impacts, not the first.
One thing to do today. Open your phone’s settings and check three lists: the apps using the most battery, the apps with access to notifications or accessibility services, and the device administrators. It takes about five minutes, and it covers all three impacts at once.
Related content
- Spotting malware on your phone — the recommendation this expands on
- Consequences of undetected malware — from technical impacts to concrete effects on money, work and relationships
- Phone battery draining fast — how to read the signs your phone gives you
- What to do if your phone has malware — the steps to take, in order of priority
- How malware scanning works — what a scanning tool can find and what it can’t
- Malware hidden in apps — the techniques malware uses to reach your phone
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- Phone Running Slow: Malware, or Just an Older Device?
- Unexpected Phone Charges: When the Bill Is the Signal
- Adware on Your Phone: Reading the Unwanted Ads
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



