Additional resource for the lesson “Fake and Imitation Apps: Spotting the Copies” — Online Security course
Fake security apps are a particular kind of imitation: software that promises to protect your phone and instead collects from it. They are common precisely because the promise disarms the caution you would otherwise apply.
A. Why this matters
Imitation apps copy a real one closely enough to be installed by mistake. Security apps are a favourite category for this, for a reason worth naming: an app that claims to protect you has a plausible excuse to request broad access to your device.
Both official stores review submissions and both let some through, particularly apps that behave normally at first. The store’s checks reduce the problem substantially; they do not remove it.
The key idea: on modern phones, the built-in protection is already competent. The gap a third-party security app fills is smaller than the marketing suggests — and smaller than the access it asks for.
B. Key concepts
Six ideas about imitations and the security category specifically.
Imitation apps
Apps built to resemble a known one: similar name, copied icon, screenshots taken from the original.
Why it matters to you: The resemblance is the whole product. Checking the developer name, as the companion resource describes, defeats most of them in seconds.
Why security apps are imitated often
The category justifies asking for wide permissions, and buyers are motivated by worry rather than by a specific need.
Why it matters to you: Recognising this pattern is more durable than recognising any particular fake app.
What the store checks catch
Known malicious code, obvious policy violations, and behaviour visible at review time.
Why it matters to you: This is genuinely effective and not complete. An app can behave normally for weeks and change afterwards through an update.
Built-in protection
Android runs Play Protect; iOS restricts what apps can do in ways that make traditional antivirus largely unnecessary.
Why it matters to you: Worth knowing before installing anything in this category: on a phone, the platform is doing most of this already.
Sideloading
Installing from outside the official stores, which phones block until you allow it.
Why it matters to you: If a security app asks you to enable this to install it, the request is itself the answer.
Free apps in a paid category
A capable security product costs money to build and maintain.
Why it matters to you: A free one in this category is funded somehow. Sometimes by advertising, sometimes by the data it collects, occasionally by what it does to the device.
C. A practical example: the cleaner that was not
A phone feels slow. A search for a cleaner or optimiser returns dozens of results, several with high ratings and millions of downloads.
- The chosen app requests access to storage, contacts, and permission to display over other apps.
- It shows an animation of files being cleaned, and a count of problems found.
- The problems are not real. The animation is the product.
Meanwhile the permissions granted are real, the advertising it displays is real, and the data it reads is real.
What would have avoided it
- Checking the developer name and the requested permissions.
- Knowing that phone cleaners generally do not do anything the phone does not do itself.
- Following the resource on a slow phone instead, which addresses the actual cause.
The reason people install these is a real problem they are trying to solve. Answering that problem properly is more useful than warning about the category.
D. Try it yourself: audit the category
Ten minutes, and it usually ends with one or two removals.
Step 1 — List what you have in this category
- Antivirus, cleaner, optimiser, battery saver, VPN, privacy app.
- Include anything installed to fix a problem you no longer remember.
Step 2 — For each, check three things
- Who published it, and have you heard of them?
- What permissions does it hold?
- When was it last updated?
Step 3 — Ask what it is actually doing
- Can you name a specific thing it does that the phone does not do itself?
- If not, it is holding permissions in exchange for reassurance.
Step 4 — Remove what does not survive the questions
- Reversible, as always. It can be reinstalled if you find you needed it.
This audit is worth doing because the security category is one of the few where installing more can reduce your protection rather than increase it.
E. Videos, articles and further resources
Independent and institutional sources in English.
Google — Use Play Protect to keep your apps safe and your data private
What Android’s built-in protection already does, which is the context for deciding whether you need more.
https://support.google.com/android/answer/2812853?hl=en
FTC — Malware: how to protect against, detect and remove it
The signs that something is wrong with a device, and the sequence to follow to clean it.
https://consumer.ftc.gov/articles/malware-how-protect-against-detect-and-remove-it
FTC — How to spot, avoid and report tech support scams
The related scam where the warning itself is the product — covered in depth in the scareware resource.
https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams
NCSC (UK) — What to do if your device is infected
A calm sequence of steps for when a device is behaving strangely.
https://www.ncsc.gov.uk/section/respond-recover/citizen-infected-devices
FTC — How to protect your phone from hackers
Practical steps for the device that holds most of your digital life.
https://consumer.ftc.gov/articles/how-protect-your-phone-hackers
NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
Links checked in August 2026.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Awareness pillar at level FL2.
Skills
- Identifying an imitation from the developer name and listing details.
- Judging whether an app in this category adds anything the platform lacks.
- Auditing what is already installed.
For professionals and organizations
- Specifying which security software is approved, so people do not choose under uncertainty.
Awareness
- Understanding why security is a commonly imitated category.
- Knowing that store review reduces but does not eliminate the problem.
- Recognising that free products in this category are funded some other way.
For future instructors and ambassadors
- Addressing the underlying worry rather than dismissing it. People install these because something felt wrong.
Secure Behavior
- Relying on built-in protection on phones.
- Checking the developer before installing anything.
- Never enabling installation from unknown sources for a security app.
For organizations
- Blocking sideloading on managed devices.
G. Questions to sit with
- How many security, cleaner or optimiser apps are on your phone?
- Can you name what each one does that the phone does not do itself?
- Who published them? Had you heard of the developer before installing?
- What problem were you trying to solve when you installed the first one?
H. What to do now
The recommendations (R) and security measures (MS) that apply.
Before installing
- R17 — Install only from official stores, and only apps you went looking for.
- MS7 — Review requested permissions and refuse what does not match the purpose.
Minimum commitment: Never enable installation from unknown sources to install something that claims to protect you.
What actually protects the phone
- R6 — Keep the system and apps updated.
- R5, MS4 — A strong device code.
- R19 — A working backup.
Minimum commitment: These three do more than any app in this category.
In short
- Security is a commonly imitated category because the promise justifies broad access.
- Phones already run competent built-in protection.
- A free product in this category is funded somehow.
- If it asks you to allow installation from unknown sources, that is the answer.
Related resources in this course
The check, and the related scams:
- Check App Details: The Filter Before You Install
- Recognizing and Addressing Scareware
- Phone Running Slow: Malware, or Just an Older Device?
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply