CYBER WELFARE

Protect your Digital Privacy

Signs an app came from outside the store: how to spot them on your phone

Hardly anyone remembers where every app on their phone came from. Some you downloaded from the store, some were already there, and some — perhaps years ago — you installed by following a link. The difference matters, though: an app that came from outside the store has not been through the store’s checks, and often does not get its updates either.

This post brings together the signs an app came from outside the store: where you can see them in your phone’s settings, what they mean and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): observable traces suggesting that something did not go the way it should have.

It is the diagnostic deep dive on the recommendation of downloading apps only from official stores: the recommendation is the rule to follow from now on; the signs help you work out whether, in the past, an app came in through another door.

What indicators mean in this case

Here an indicator is not about how the app behaves, but about where it came from: a setting that was left switched on, an app the store does not recognise as its own, an update that arrives as a file rather than through the store.

It is not proof that the app is harmful. It is a signal that deserves a check: many apps installed from other sources are harmless, and some alternative sources are trustworthy and chosen deliberately. But you cannot say anything about an app whose origin you do not know, and that is why it deserves a closer look.

The value of these indicators is that you can find them before anything happens. The signs of malware — intrusive adverts, a battery that drains fast, strange charges — show up when the problem is already under way. Signs of origin, on the other hand, are something you can look for calmly, with ten quiet minutes.

Why they matter more when an app arrived through a link

An app downloaded from the official store has passed a series of automated checks, receives its updates in an orderly way and, if it turns out to be harmful, can be withdrawn and flagged even on the phones where it is already installed.

An app that arrived through a link in a chat, from a download website or from a file shared in a group has none of these safeguards. Nobody has checked that the package is the original one, nobody will update it when a security flaw is discovered, and the phone’s built-in protection can only recognise it if it is already known to be harmful.

There is also a second, less visible effect: to install that app, you had to give another app — the browser, the chat app, the file manager — permission to install apps from unknown sources. If that permission is still switched on, the door is still open, even if the app that needed it is long gone. The risks of this situation are covered in the post on the risks of sideloading apps — sideloading being the term for installing an app from outside the official store.

Technical indicators

These are the ones you find in your phone’s settings and in the store. The names of the menu items vary from one operating system to another and from one manufacturer to another, but the logic is the same.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
The app does not appear among those installed or bought from the storeThe store has no record of installing it with your accountIt is the most direct signal: the app came from another source“My apps”, “Library” or “Purchases” section of the storeCheck whether it was pre-installed or provided by work; otherwise treat it as being of unknown origin
The app’s info page shows a different sourceSome systems show which app installed it (store, browser, file manager)It tells you exactly where it came fromSettings → Apps → the individual app’s page, usually at the bottomIf the source is a browser or a chat app, consider whether you really need it
“Install unknown apps” permission switched onThe browser, the chat app or the file manager can install other appsIt is the door through which apps from outside the store come in, and it stays open until you close itSettings → Apps → special access, or security settingsSwitch it off for every app that does not need it
Alerts from the built-in protectionThe system flags an app as “unverified”, “from an unknown developer” or potentially harmfulBuilt-in protection keeps checking apps after installation tooSecurity notifications, the protection section of the store or of the settingsDo not ignore it: read the alert and, if in doubt, remove the app
Unknown configuration or management profilesA profile that changes settings or authorises apps is installed on the phoneOn some systems this is how apps are installed outside the store; a profile can also control traffic or certificatesSettings → General → device management or profilesIf you do not recognise it and it is not from your work, remove it
Developer certificates you were asked to “trust”You were asked to trust a developer or a company in order to open an appIt lets apps distributed outside the store run on the phoneThe same section as profiles, under “enterprise apps” or “developer”Withdraw that trust if you do not know who the developer is
An alternative store you do not remember installingAnother app that distributes apps is on the phoneIt can install and update apps under rules that differ from those of the official storeFull list of appsIf you did not choose it, remove it along with the apps it installed

Signs you can observe yourself

These do not require you to open the settings: you notice them while using the phone, or by thinking back to how an app arrived.

SignalWhat it meansWhy it mattersHow you noticeWhat to do
The app never updates from the storeIt never shows up among available updates, while the others doWithout updates, known security flaws stay openThe version stays the same for months, or the app warns you it is “out of date”Look for the official app in the store and, if you need it, install that one
The app asks you to update by downloading a fileA message inside the app sends you to a website or a link for the new versionIt is a way of installing new code outside any checksA window offering “download the update” instead of pointing you to the storeDo not follow the link; check the store for the official app
The store shows the app as “to install”You search the store for the app and, instead of “Open”, it shows “Install”The copy on your phone is not the one the store distributesA store search for the exact nameTreat the installed copy as being of unknown origin
An “unlocked”, “free premium” or “mod” versionThe app offers for free features that are paid for in the originalIt is almost always a version modified by third partiesThe name or the start screen says so openlyRemove it and, if you need it, go back to the official version
You remember allowing “unknown sources”During an installation, the phone asked you for a special permissionIt confirms that the app came from outsideThe memory of a warning screen you clicked throughIdentify the app installed at that moment and check the permission again
Installation files in your downloadsThe downloads folder contains app packagesThey point to installations, carried out or attempted, outside the storeFile manager, “Downloads” folderDelete them, once you have checked what they installed

A concrete example

Sarah has just bought a new phone and, before moving everything across, she decides to tidy up the old one. Scrolling through the list of apps, she finds a photo-editing app she used for her stories: she vaguely remembers that a friend recommended it in a group chat, with a link.

She opens the store and searches for it by name. The app exists, but the button next to it says “Install”, not “Open”. It is not in the “My apps” section. On the app’s page in the settings, the source listed is the messaging app.

So Sarah checks the permission to install unknown apps: it is switched on for the chat app and for the browser. She did not even remember granting it to the browser.

Nothing serious has happened. But that app had not been updated in two years, asked for access to her entire photo gallery, and nobody could tell her what it really contained. Sarah removes it, switches off the permission for both apps and installs the official version from the store. On her new phone, she starts with the door already closed.

The signal had been there for two years. All it took was knowing where to look.

What to check right away

In your phone’s settings

  • the list of apps with permission to install unknown apps;
  • the installation source shown on the page of any app you do not recognise;
  • configuration profiles, device management and developers marked as trusted;
  • the status of the built-in protection, and any alerts.

In the store

  • the “My apps” or “Library” section, compared with the apps on your phone;
  • apps that never appear among the updates;
  • whether automatic updates are switched on.

In your phone’s storage

  • the downloads folder, to find forgotten installation files;
  • any alternative stores you did not install yourself.

If during this check you find apps you do not recognise at all, or apps with no icon, the steps to find and remove them are in the recommendation on finding and removing unknown apps.

If you find a suspicious indicator

  1. Close the door. Switch off the permission to install unknown apps for the browser, the chat app and any app that has no specific reason to have it.
  2. Do not enter any data in the app. No passwords, no payment details, until you have decided what to do with it.
  3. Remove the app of unknown origin and, if you need it, install the official version from the store. If there is a profile or a developer you do not recognise, remove that too.
  4. Run a scan with the phone’s built-in protection, to make sure no other apps are flagged.
  5. Change the passwords of any accounts you signed in to from that app, using another device if you can.

The full procedure, with the settings to check, is in the post on how to block installs from unknown sources. If instead you are already noticing signs of unusual behaviour, the guide on what to do if your phone has malware is the place to start.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: removing legitimate apps over an unfounded suspicion, and getting used to ignoring the real signals.

SituationWhy it is usually not a signal
Apps pre-installed by the manufacturer or the mobile operatorThey come with the phone and may not appear among store purchases; they are updated with the system
Work apps installed by your employerOrganisations distribute apps and profiles through device management systems; you recognise them because you were told about them
An alternative store you chose yourselfThere are trustworthy alternative stores, for example those dedicated to free and open-source software: what matters is that the choice was deliberate
An app moved from your old phone or restored from a backupIt may appear before it is linked to the store; it usually catches up with the first update
An app that does not update because automatic updates are offThe problem is the setting, not the origin: switch them back on
An official app withdrawn from the storeIt did come from the store, but it will not be updated any more; it is not of unknown origin, but it is worth removing
Website shortcuts on the home screenThey are links to a page, not installed apps, and they need no special permissions

The rule of thumb: one isolated signal deserves a check; two signals together mean it is time to remove the app.

How often to check

You do not need a demanding routine. You just need a short habit at the right moments.

FrequencyWhat to check
When the phone asks you to allow unknown sourcesStop: this is the exact moment an app is about to come in from outside
When an alert from the built-in protection arrivesRead it and act right away: it is the most timely information you will get
Every 3 monthsThe “install unknown apps” permission, apps that do not update, installed profiles
When you change phonesWhich apps to move across: it is the ideal chance to leave behind those of uncertain origin
After lending your phone or having it repairedProfiles, trusted developers and installation permissions

A regular check goes well with the recommendation on removing the apps you no longer use: the fewer apps you have, the easier it is to notice the one that did not come from the store.

Two important warnings

An indicator is not proof. An app installed from another source may be perfectly harmless, and an app that does not appear among your purchases may simply have been pre-installed. Check before you get alarmed — but always check: an unknown origin is reason enough to ask yourself whether you really need that app.

No indicators is not a guarantee. Even official stores, which filter out many harmful apps, are not infallible: an app can come from the store and still misbehave. That is why signs of origin should be read alongside signs of behaviour, described in the recommendation on spotting the signs of malware on your phone. And that is why the best protection remains preventive: keeping the unknown-sources door closed and leaving the built-in protection against harmful apps switched on.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to read the phone’s and the store’s settings to work out where an app came from
AwarenessUnderstanding that a permission granted once stays active until you withdraw it
Secure BehaviourChecking permissions and profiles regularly, and stopping when the phone asks you to allow unknown sources

Reference level: FL3 — Autonomous. This is the level at which you recognise a signal and act on it without needing outside support.

Conclusion

Spotting an app installed from outside the store does not mean being suspicious of every app. It means knowing where to look to piece together its history, and closing the doors that were left open without anyone remembering.

What to do right now. Open your phone’s settings and look for the permission to install unknown apps. If it is switched on for any app that does not need it, switch it off: it takes a minute. Then, if you would like to see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.

Related resources

Short guides from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.