A fake app does not usually announce itself. It has the right colours, a name that is almost identical to the one you were looking for, and an icon that looks like the real thing at first glance. The difference is in the details: who published it, how long it has existed, and what it asks you to do.
This post brings together the signs of a fake app: the ones you can see on the app’s store page before you install it, and the ones that show up on your phone afterwards. For each one you will find what it means, where you can see it and what to do. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): observable traces suggesting that something is not what it should be.
It is the diagnostic deep dive on the recommendation on checking an app is genuine: checking before you install is the prevention; recognising the signs helps you notice in time if something slipped through.
What indicators mean in this case
Here an indicator is a detail that does not add up: a developer name that does not match the service, a publication date that is far too recent, a request for permissions that has nothing to do with what the app is supposed to do.
It is not proof. It is a signal that deserves a check: an odd detail may have a perfectly harmless explanation — a new service, a company that publishes under a legal name different from its brand — or it may mean that the app is a copy built to look like the real one.
The value of indicators lies in when you notice them. Before installation, a signal spares you the problem altogether. In the first few minutes afterwards, it lets you remove the app before it has had time to collect data or obtain important permissions.
Why they matter more when an app imitates a service you know
An unfamiliar app, from a service you have never heard of, is something you already look at with a little caution.
An app that imitates your bank, your parcel delivery company, your town’s parking service or a messaging app you use every day, on the other hand, plays on the trust you already have. You recognise the logo, you recognise the colours, and checking seems unnecessary. That is exactly where the details matter: whoever builds a fake app does not need to convince you that it is trustworthy — it is enough that you do not check.
That is why the signs deserve closer attention precisely on the apps that feel familiar, and above all on those that handle money, credentials or documents.
Technical indicators: before you install
These are the ones you find on the app’s page in the store, or in the way the link reached you. They take a minute of attention, not special skills.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| A developer that does not match the service | The app is published under a name that does not match the company or organisation that should run it | It is the most reliable signal: someone copying an app can imitate how it looks, but publishes it under their own account | “Developer” or “Seller” field on the app’s page | Go to the service’s official website and follow its link to the store to find the real app |
| A name with small variations | Swapped letters, added words such as “Pro”, “Plus”, “Official”, a year, odd spaces or characters | This technique is called typosquatting: using near-identical names to catch people looking for the original | The app’s title in the search results | Compare the name with the one given on the official website, letter by letter |
| Few reviews, all of them recent | The rating is high but there are few reviews, all similar and bunched into the last few days | Reviews can be bought or written in bulk; the rating on its own tells you little | Reviews section, sorted by date | Read the most recent reviews and the negative ones: people who were tricked often say so |
| Few downloads for a widely used service | A service used by millions of people has an app with very few installs | The official app of a well-known service usually has a long download history | Install counter, if the store shows one | Look for the app that matches the official website; do not stop at the first result |
| A recent publication date | The app appears to have been published a few weeks ago, for a service that has existed for years | Fake apps are often removed and republished, which is why they tend to be “young” | App information, “released on” or version history | Be wary if the date does not fit the service’s history |
| Permissions out of proportion to the job | A torch app that wants to read your text messages, a game that asks for your contacts | A permission is an authorisation to reach data or functions on your phone: the unnecessary ones are there for something else | “Permissions” or “Data collected” section on the app’s page | If a permission makes no sense for what the app promises, do not install it |
| A link that arrived by message | You are asked to install an app from a link received by text message, chat or email | Official channels rarely ask you to install an app starting from a message | The message itself, especially if it is urgent or mentions a parcel on hold | Do not use the link: look up the service on its official website and start from there |
| Installing from outside the store | To install the app you have to download a file and allow “unknown sources” | This skips the checks that stores apply to apps | A system screen asking you for a special authorisation | Stop: unless it is a case you know well, an app from a well-known service is installed from the store |
Signs you can observe yourself: after installation
Some fake apps get past a first look, and sometimes past the store’s checks too. In that case the signs come later, as you use your phone.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| Intrusive advertising, even outside the app | Full-screen ads appear on your home screen, on top of other apps or in the browser | The app earns its money from those ads, not from the service it promised | Ads that appear even when the app is closed | Identify the recently installed apps and remove the suspicious one |
| A request to turn on accessibility | The app asks you to enable it in the accessibility services “so it can work properly” | Accessibility features are designed to help people who find a phone hard to use: they can read the screen and act on your behalf | A message guiding you into the settings, often insistently | Do not grant it, unless the app really is an assistive tool you chose |
| A request to become a device administrator | The app asks for special powers over the phone | An app with these powers can be hard to uninstall | A system screen asking you to “activate” the app as an administrator | Refuse; if you already granted it, revoke it before uninstalling |
| The icon disappears | After the first launch the icon is no longer on the home screen | The app may keep running out of sight | You cannot find it among your icons, but it is still in the full list of apps | Look for it in the settings, in the list of installed apps, and remove it |
| The app does not do what it promised | It opens on a blank screen, sends you to a website or immediately asks you to sign in | Often the only purpose was to collect credentials or to get installed | The service you wanted does not work, but you are asked for passwords or details | Do not enter anything; if you already did, change the password from the official website |
| Insistent requests for payment details | You are asked for your card details to “verify your account” or unlock basic features | A legitimate service does not ask for your card for features that should be free | Unusual or repeated payment screens | Close the app; check your statements and active subscriptions |
| Unexpected subscriptions or charges | A subscription appears that you do not remember starting | Some fake apps live off expensive, barely visible subscriptions | Store receipts, bank statement, subscriptions section | Cancel from the store’s subscriptions area and report the app |
| A warning from the system’s protection | The phone or the store flags the app as potentially harmful | Built-in protection keeps checking apps even after installation | A security notification from the operating system | Follow the warning and remove the app; do not dismiss it as a false alarm |
A concrete example
Sarah has just moved and needs to pay for parking with her new local council’s app. She opens the store, types the name of the town and installs the first result: the right colours, a recognisable coat of arms, a high rating.
On first launch the app asks for her card details, then asks her to enable it in the accessibility services “to receive reminders when your parking is about to expire”. Sarah hesitates and says no. When she goes back to the home screen, the icon is gone.
At that point she stops and checks. The app had been published by a developer with an individual’s name, had existed for three weeks and had reviews that were all alike, written in the last few days. The council’s website linked to the real app, published years ago by the company that runs the town’s parking.
Sarah finds the hidden app in the full list of apps and removes it. Then she calls her bank, blocks the card and asks for a new one.
Two signals were visible on the store page in thirty seconds. The third — the accessibility request — came later, and Sarah was right to stop exactly there.
What to check right away
On the app’s page, before you install
- the developer’s name, compared with the service’s name;
- the exact name of the app, compared with the one given on the official website;
- the publication date and the number of downloads;
- the most recent reviews and the negative ones, not just the rating;
- the permissions requested, measured against what the app needs to do.
On your phone, if you have already installed it
- the full list of apps, to find any without an icon;
- the apps active in the accessibility services and among the device administrators;
- the permissions granted to recently installed apps, as explained in the recommendation on checking what your apps can do.
On your accounts and payments
- active subscriptions in the store;
- transactions on the card you used in the app;
- recent sign-ins to the accounts whose credentials you entered.
If you find a suspicious indicator
- If you have not installed it yet, stop. Look up the service on its official website and follow the link it gives.
- If you have installed it, do not enter any more details. Do not complete sign-ups, payments or sign-ins.
- Revoke accessibility and device administrator access, if you granted them, then uninstall the app.
- Change the passwords of any accounts whose credentials you typed in, from another device if possible.
- Check your card and subscriptions, and contact your bank if you entered payment details.
The full sequence, with the steps in the right order, is in the post on what to do after installing a fake app. If you want to understand how these copies are put together, the mechanisms are explained in the post on cloned and counterfeit apps.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: giving up on legitimate apps over an unfounded suspicion, and getting used to ignoring the real signals.
| Situation | Why it is usually not a signal |
|---|---|
| The developer’s name differs from the brand | Many companies publish under their registered company name or under a group company: what matters is that it is the same name given on the official website |
| A few negative reviews | Genuine apps get them too, often because of problems with the service or an unpopular update |
| Few downloads for a small or new service | The app for a local gym or a neighbourhood shop will never have large numbers |
| Advertising inside a free app | It is a common business model; it becomes a signal when it leaves the app and takes over the phone |
| Permissions that fit the job | A navigation app asking for your location, or a video-calling app asking for the camera, is doing what it should |
| An icon or look that changed after an update | This often happens with official apps, especially if the service announced it |
The rule of thumb: one isolated signal deserves a check; two signals together mean do not install it, or remove it.
How often to check
You do not need a demanding routine. You need a short habit at the right moments.
| Frequency | What to check |
|---|---|
| Every time you install a new app | Developer, exact name, date, recent reviews and permissions: one minute before you tap “install” |
| When a message invites you to install an app | Do not follow the link; start from the service’s official website |
| In the first few days after installation | Ads outside the app, accessibility requests, an icon that disappears |
| Every 2–3 months | The full list of apps, apps with accessibility or administrator access, subscriptions in the store |
| After news of fake apps imitating a service you use | That the app you installed is the one published by the official developer |
A regular check goes well with the recommendation on removing apps you no longer use: the fewer apps you have, the easier it is to notice the one that should not be there.
Two important warnings
An indicator is not proof. A developer with an unfamiliar name may be the company that actually runs the service; a recent date may be down to a new version of the app. Check before you get alarmed — but always check: the service’s official website is the reference point that settles almost every doubt.
No indicators is not a guarantee. A well-made copy can have a believable name, carefully managed reviews and no strange requests in the first few days. Even the stores’ checks, which filter out many harmful apps, are not infallible. That is why protection does not rest on hunting for signs, but on the habit of starting from the official website and following its link to the store. Indicators help you notice in time; they do not replace the check.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read an app’s store page: developer, date, reviews, permissions |
| Awareness | Understanding that a fake app exploits the trust you already place in a brand you know |
| Secure Behaviour | Pausing for a minute before installing, and keeping an eye on the phone in the days that follow |
Reference level: FL2 — Beginner. This is the level at which you learn to observe methodically: knowing where to look and what you are seeing, even before you can solve every problem on your own.
Conclusion
Spotting a fake app does not mean treating every app with suspicion. It means knowing which details to check, so that a vague impression — “it looks like the right one” — becomes a one-minute check.
What to do right now. Open the store, look up an app you use often and check the developer’s name, the date and the most recent reviews. It is a useful exercise even when the app is the real one: the next time you look for a new app, you will already know where to look. To see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.
Related resources
Short guides from the Resources section, for anyone who wants to focus on a single aspect:
- Fake App Reviews: Why the Rating Tells You Little
- Fake Security Apps: When the Protection Is the Problem
- Check App Details: The Filter Before You Install
Related content
- Checking an app is genuine — the recommendation this belongs to
- Cloned and counterfeit apps — the attacks that generate these signals
- What to do after installing a fake app — what to do, in the right order
- Impact of fake apps — what gets hit when a signal is confirmed
- How app stores check apps — what the stores’ checks filter out, and where they stop
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



