Hardly anyone remembers where every app on their phone came from. Some you downloaded from the store, some were already there, and some — perhaps years ago — you installed by following a link. The difference matters, though: an app that came from outside the store has not been through the store’s checks, and often does not get its updates either.
This post brings together the signs an app came from outside the store: where you can see them in your phone’s settings, what they mean and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): observable traces suggesting that something did not go the way it should have.
It is the diagnostic deep dive on the recommendation of downloading apps only from official stores: the recommendation is the rule to follow from now on; the signs help you work out whether, in the past, an app came in through another door.
What indicators mean in this case
Here an indicator is not about how the app behaves, but about where it came from: a setting that was left switched on, an app the store does not recognise as its own, an update that arrives as a file rather than through the store.
It is not proof that the app is harmful. It is a signal that deserves a check: many apps installed from other sources are harmless, and some alternative sources are trustworthy and chosen deliberately. But you cannot say anything about an app whose origin you do not know, and that is why it deserves a closer look.
The value of these indicators is that you can find them before anything happens. The signs of malware — intrusive adverts, a battery that drains fast, strange charges — show up when the problem is already under way. Signs of origin, on the other hand, are something you can look for calmly, with ten quiet minutes.
Why they matter more when an app arrived through a link
An app downloaded from the official store has passed a series of automated checks, receives its updates in an orderly way and, if it turns out to be harmful, can be withdrawn and flagged even on the phones where it is already installed.
An app that arrived through a link in a chat, from a download website or from a file shared in a group has none of these safeguards. Nobody has checked that the package is the original one, nobody will update it when a security flaw is discovered, and the phone’s built-in protection can only recognise it if it is already known to be harmful.
There is also a second, less visible effect: to install that app, you had to give another app — the browser, the chat app, the file manager — permission to install apps from unknown sources. If that permission is still switched on, the door is still open, even if the app that needed it is long gone. The risks of this situation are covered in the post on the risks of sideloading apps — sideloading being the term for installing an app from outside the official store.
Technical indicators
These are the ones you find in your phone’s settings and in the store. The names of the menu items vary from one operating system to another and from one manufacturer to another, but the logic is the same.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| The app does not appear among those installed or bought from the store | The store has no record of installing it with your account | It is the most direct signal: the app came from another source | “My apps”, “Library” or “Purchases” section of the store | Check whether it was pre-installed or provided by work; otherwise treat it as being of unknown origin |
| The app’s info page shows a different source | Some systems show which app installed it (store, browser, file manager) | It tells you exactly where it came from | Settings → Apps → the individual app’s page, usually at the bottom | If the source is a browser or a chat app, consider whether you really need it |
| “Install unknown apps” permission switched on | The browser, the chat app or the file manager can install other apps | It is the door through which apps from outside the store come in, and it stays open until you close it | Settings → Apps → special access, or security settings | Switch it off for every app that does not need it |
| Alerts from the built-in protection | The system flags an app as “unverified”, “from an unknown developer” or potentially harmful | Built-in protection keeps checking apps after installation too | Security notifications, the protection section of the store or of the settings | Do not ignore it: read the alert and, if in doubt, remove the app |
| Unknown configuration or management profiles | A profile that changes settings or authorises apps is installed on the phone | On some systems this is how apps are installed outside the store; a profile can also control traffic or certificates | Settings → General → device management or profiles | If you do not recognise it and it is not from your work, remove it |
| Developer certificates you were asked to “trust” | You were asked to trust a developer or a company in order to open an app | It lets apps distributed outside the store run on the phone | The same section as profiles, under “enterprise apps” or “developer” | Withdraw that trust if you do not know who the developer is |
| An alternative store you do not remember installing | Another app that distributes apps is on the phone | It can install and update apps under rules that differ from those of the official store | Full list of apps | If you did not choose it, remove it along with the apps it installed |
Signs you can observe yourself
These do not require you to open the settings: you notice them while using the phone, or by thinking back to how an app arrived.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| The app never updates from the store | It never shows up among available updates, while the others do | Without updates, known security flaws stay open | The version stays the same for months, or the app warns you it is “out of date” | Look for the official app in the store and, if you need it, install that one |
| The app asks you to update by downloading a file | A message inside the app sends you to a website or a link for the new version | It is a way of installing new code outside any checks | A window offering “download the update” instead of pointing you to the store | Do not follow the link; check the store for the official app |
| The store shows the app as “to install” | You search the store for the app and, instead of “Open”, it shows “Install” | The copy on your phone is not the one the store distributes | A store search for the exact name | Treat the installed copy as being of unknown origin |
| An “unlocked”, “free premium” or “mod” version | The app offers for free features that are paid for in the original | It is almost always a version modified by third parties | The name or the start screen says so openly | Remove it and, if you need it, go back to the official version |
| You remember allowing “unknown sources” | During an installation, the phone asked you for a special permission | It confirms that the app came from outside | The memory of a warning screen you clicked through | Identify the app installed at that moment and check the permission again |
| Installation files in your downloads | The downloads folder contains app packages | They point to installations, carried out or attempted, outside the store | File manager, “Downloads” folder | Delete them, once you have checked what they installed |
A concrete example
Sarah has just bought a new phone and, before moving everything across, she decides to tidy up the old one. Scrolling through the list of apps, she finds a photo-editing app she used for her stories: she vaguely remembers that a friend recommended it in a group chat, with a link.
She opens the store and searches for it by name. The app exists, but the button next to it says “Install”, not “Open”. It is not in the “My apps” section. On the app’s page in the settings, the source listed is the messaging app.
So Sarah checks the permission to install unknown apps: it is switched on for the chat app and for the browser. She did not even remember granting it to the browser.
Nothing serious has happened. But that app had not been updated in two years, asked for access to her entire photo gallery, and nobody could tell her what it really contained. Sarah removes it, switches off the permission for both apps and installs the official version from the store. On her new phone, she starts with the door already closed.
The signal had been there for two years. All it took was knowing where to look.
What to check right away
In your phone’s settings
- the list of apps with permission to install unknown apps;
- the installation source shown on the page of any app you do not recognise;
- configuration profiles, device management and developers marked as trusted;
- the status of the built-in protection, and any alerts.
In the store
- the “My apps” or “Library” section, compared with the apps on your phone;
- apps that never appear among the updates;
- whether automatic updates are switched on.
In your phone’s storage
- the downloads folder, to find forgotten installation files;
- any alternative stores you did not install yourself.
If during this check you find apps you do not recognise at all, or apps with no icon, the steps to find and remove them are in the recommendation on finding and removing unknown apps.
If you find a suspicious indicator
- Close the door. Switch off the permission to install unknown apps for the browser, the chat app and any app that has no specific reason to have it.
- Do not enter any data in the app. No passwords, no payment details, until you have decided what to do with it.
- Remove the app of unknown origin and, if you need it, install the official version from the store. If there is a profile or a developer you do not recognise, remove that too.
- Run a scan with the phone’s built-in protection, to make sure no other apps are flagged.
- Change the passwords of any accounts you signed in to from that app, using another device if you can.
The full procedure, with the settings to check, is in the post on how to block installs from unknown sources. If instead you are already noticing signs of unusual behaviour, the guide on what to do if your phone has malware is the place to start.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: removing legitimate apps over an unfounded suspicion, and getting used to ignoring the real signals.
| Situation | Why it is usually not a signal |
|---|---|
| Apps pre-installed by the manufacturer or the mobile operator | They come with the phone and may not appear among store purchases; they are updated with the system |
| Work apps installed by your employer | Organisations distribute apps and profiles through device management systems; you recognise them because you were told about them |
| An alternative store you chose yourself | There are trustworthy alternative stores, for example those dedicated to free and open-source software: what matters is that the choice was deliberate |
| An app moved from your old phone or restored from a backup | It may appear before it is linked to the store; it usually catches up with the first update |
| An app that does not update because automatic updates are off | The problem is the setting, not the origin: switch them back on |
| An official app withdrawn from the store | It did come from the store, but it will not be updated any more; it is not of unknown origin, but it is worth removing |
| Website shortcuts on the home screen | They are links to a page, not installed apps, and they need no special permissions |
The rule of thumb: one isolated signal deserves a check; two signals together mean it is time to remove the app.
How often to check
You do not need a demanding routine. You just need a short habit at the right moments.
| Frequency | What to check |
|---|---|
| When the phone asks you to allow unknown sources | Stop: this is the exact moment an app is about to come in from outside |
| When an alert from the built-in protection arrives | Read it and act right away: it is the most timely information you will get |
| Every 3 months | The “install unknown apps” permission, apps that do not update, installed profiles |
| When you change phones | Which apps to move across: it is the ideal chance to leave behind those of uncertain origin |
| After lending your phone or having it repaired | Profiles, trusted developers and installation permissions |
A regular check goes well with the recommendation on removing the apps you no longer use: the fewer apps you have, the easier it is to notice the one that did not come from the store.
Two important warnings
An indicator is not proof. An app installed from another source may be perfectly harmless, and an app that does not appear among your purchases may simply have been pre-installed. Check before you get alarmed — but always check: an unknown origin is reason enough to ask yourself whether you really need that app.
No indicators is not a guarantee. Even official stores, which filter out many harmful apps, are not infallible: an app can come from the store and still misbehave. That is why signs of origin should be read alongside signs of behaviour, described in the recommendation on spotting the signs of malware on your phone. And that is why the best protection remains preventive: keeping the unknown-sources door closed and leaving the built-in protection against harmful apps switched on.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read the phone’s and the store’s settings to work out where an app came from |
| Awareness | Understanding that a permission granted once stays active until you withdraw it |
| Secure Behaviour | Checking permissions and profiles regularly, and stopping when the phone asks you to allow unknown sources |
Reference level: FL3 — Autonomous. This is the level at which you recognise a signal and act on it without needing outside support.
Conclusion
Spotting an app installed from outside the store does not mean being suspicious of every app. It means knowing where to look to piece together its history, and closing the doors that were left open without anyone remembering.
What to do right now. Open your phone’s settings and look for the permission to install unknown apps. If it is switched on for any app that does not need it, switch it off: it takes a minute. Then, if you would like to see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.
Related resources
Short guides from the Resources section, for anyone who wants to focus on a single aspect:
Related content
- Downloading apps only from official stores — the recommendation this belongs to
- Modded and pirated apps — the attacks that generate these signals
- How to block installs from unknown sources — what to do, in the right order
- Consequences of installing an app from a link — what gets hit when a signal is confirmed
- Checking an app is genuine — the checks to make before installing, even inside the store
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



