CYBER WELFARE

Protect your Digital Privacy

Signs of a fake app: how to spot one before and after you install it

A fake app does not usually announce itself. It has the right colours, a name that is almost identical to the one you were looking for, and an icon that looks like the real thing at first glance. The difference is in the details: who published it, how long it has existed, and what it asks you to do.

This post brings together the signs of a fake app: the ones you can see on the app’s store page before you install it, and the ones that show up on your phone afterwards. For each one you will find what it means, where you can see it and what to do. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise): observable traces suggesting that something is not what it should be.

It is the diagnostic deep dive on the recommendation on checking an app is genuine: checking before you install is the prevention; recognising the signs helps you notice in time if something slipped through.

What indicators mean in this case

Here an indicator is a detail that does not add up: a developer name that does not match the service, a publication date that is far too recent, a request for permissions that has nothing to do with what the app is supposed to do.

It is not proof. It is a signal that deserves a check: an odd detail may have a perfectly harmless explanation — a new service, a company that publishes under a legal name different from its brand — or it may mean that the app is a copy built to look like the real one.

The value of indicators lies in when you notice them. Before installation, a signal spares you the problem altogether. In the first few minutes afterwards, it lets you remove the app before it has had time to collect data or obtain important permissions.

Why they matter more when an app imitates a service you know

An unfamiliar app, from a service you have never heard of, is something you already look at with a little caution.

An app that imitates your bank, your parcel delivery company, your town’s parking service or a messaging app you use every day, on the other hand, plays on the trust you already have. You recognise the logo, you recognise the colours, and checking seems unnecessary. That is exactly where the details matter: whoever builds a fake app does not need to convince you that it is trustworthy — it is enough that you do not check.

That is why the signs deserve closer attention precisely on the apps that feel familiar, and above all on those that handle money, credentials or documents.

Technical indicators: before you install

These are the ones you find on the app’s page in the store, or in the way the link reached you. They take a minute of attention, not special skills.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
A developer that does not match the serviceThe app is published under a name that does not match the company or organisation that should run itIt is the most reliable signal: someone copying an app can imitate how it looks, but publishes it under their own account“Developer” or “Seller” field on the app’s pageGo to the service’s official website and follow its link to the store to find the real app
A name with small variationsSwapped letters, added words such as “Pro”, “Plus”, “Official”, a year, odd spaces or charactersThis technique is called typosquatting: using near-identical names to catch people looking for the originalThe app’s title in the search resultsCompare the name with the one given on the official website, letter by letter
Few reviews, all of them recentThe rating is high but there are few reviews, all similar and bunched into the last few daysReviews can be bought or written in bulk; the rating on its own tells you littleReviews section, sorted by dateRead the most recent reviews and the negative ones: people who were tricked often say so
Few downloads for a widely used serviceA service used by millions of people has an app with very few installsThe official app of a well-known service usually has a long download historyInstall counter, if the store shows oneLook for the app that matches the official website; do not stop at the first result
A recent publication dateThe app appears to have been published a few weeks ago, for a service that has existed for yearsFake apps are often removed and republished, which is why they tend to be “young”App information, “released on” or version historyBe wary if the date does not fit the service’s history
Permissions out of proportion to the jobA torch app that wants to read your text messages, a game that asks for your contactsA permission is an authorisation to reach data or functions on your phone: the unnecessary ones are there for something else“Permissions” or “Data collected” section on the app’s pageIf a permission makes no sense for what the app promises, do not install it
A link that arrived by messageYou are asked to install an app from a link received by text message, chat or emailOfficial channels rarely ask you to install an app starting from a messageThe message itself, especially if it is urgent or mentions a parcel on holdDo not use the link: look up the service on its official website and start from there
Installing from outside the storeTo install the app you have to download a file and allow “unknown sources”This skips the checks that stores apply to appsA system screen asking you for a special authorisationStop: unless it is a case you know well, an app from a well-known service is installed from the store

Signs you can observe yourself: after installation

Some fake apps get past a first look, and sometimes past the store’s checks too. In that case the signs come later, as you use your phone.

SignalWhat it meansWhy it mattersHow you noticeWhat to do
Intrusive advertising, even outside the appFull-screen ads appear on your home screen, on top of other apps or in the browserThe app earns its money from those ads, not from the service it promisedAds that appear even when the app is closedIdentify the recently installed apps and remove the suspicious one
A request to turn on accessibilityThe app asks you to enable it in the accessibility services “so it can work properly”Accessibility features are designed to help people who find a phone hard to use: they can read the screen and act on your behalfA message guiding you into the settings, often insistentlyDo not grant it, unless the app really is an assistive tool you chose
A request to become a device administratorThe app asks for special powers over the phoneAn app with these powers can be hard to uninstallA system screen asking you to “activate” the app as an administratorRefuse; if you already granted it, revoke it before uninstalling
The icon disappearsAfter the first launch the icon is no longer on the home screenThe app may keep running out of sightYou cannot find it among your icons, but it is still in the full list of appsLook for it in the settings, in the list of installed apps, and remove it
The app does not do what it promisedIt opens on a blank screen, sends you to a website or immediately asks you to sign inOften the only purpose was to collect credentials or to get installedThe service you wanted does not work, but you are asked for passwords or detailsDo not enter anything; if you already did, change the password from the official website
Insistent requests for payment detailsYou are asked for your card details to “verify your account” or unlock basic featuresA legitimate service does not ask for your card for features that should be freeUnusual or repeated payment screensClose the app; check your statements and active subscriptions
Unexpected subscriptions or chargesA subscription appears that you do not remember startingSome fake apps live off expensive, barely visible subscriptionsStore receipts, bank statement, subscriptions sectionCancel from the store’s subscriptions area and report the app
A warning from the system’s protectionThe phone or the store flags the app as potentially harmfulBuilt-in protection keeps checking apps even after installationA security notification from the operating systemFollow the warning and remove the app; do not dismiss it as a false alarm

A concrete example

Sarah has just moved and needs to pay for parking with her new local council’s app. She opens the store, types the name of the town and installs the first result: the right colours, a recognisable coat of arms, a high rating.

On first launch the app asks for her card details, then asks her to enable it in the accessibility services “to receive reminders when your parking is about to expire”. Sarah hesitates and says no. When she goes back to the home screen, the icon is gone.

At that point she stops and checks. The app had been published by a developer with an individual’s name, had existed for three weeks and had reviews that were all alike, written in the last few days. The council’s website linked to the real app, published years ago by the company that runs the town’s parking.

Sarah finds the hidden app in the full list of apps and removes it. Then she calls her bank, blocks the card and asks for a new one.

Two signals were visible on the store page in thirty seconds. The third — the accessibility request — came later, and Sarah was right to stop exactly there.

What to check right away

On the app’s page, before you install

  • the developer’s name, compared with the service’s name;
  • the exact name of the app, compared with the one given on the official website;
  • the publication date and the number of downloads;
  • the most recent reviews and the negative ones, not just the rating;
  • the permissions requested, measured against what the app needs to do.

On your phone, if you have already installed it

  • the full list of apps, to find any without an icon;
  • the apps active in the accessibility services and among the device administrators;
  • the permissions granted to recently installed apps, as explained in the recommendation on checking what your apps can do.

On your accounts and payments

  • active subscriptions in the store;
  • transactions on the card you used in the app;
  • recent sign-ins to the accounts whose credentials you entered.

If you find a suspicious indicator

  1. If you have not installed it yet, stop. Look up the service on its official website and follow the link it gives.
  2. If you have installed it, do not enter any more details. Do not complete sign-ups, payments or sign-ins.
  3. Revoke accessibility and device administrator access, if you granted them, then uninstall the app.
  4. Change the passwords of any accounts whose credentials you typed in, from another device if possible.
  5. Check your card and subscriptions, and contact your bank if you entered payment details.

The full sequence, with the steps in the right order, is in the post on what to do after installing a fake app. If you want to understand how these copies are put together, the mechanisms are explained in the post on cloned and counterfeit apps.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: giving up on legitimate apps over an unfounded suspicion, and getting used to ignoring the real signals.

SituationWhy it is usually not a signal
The developer’s name differs from the brandMany companies publish under their registered company name or under a group company: what matters is that it is the same name given on the official website
A few negative reviewsGenuine apps get them too, often because of problems with the service or an unpopular update
Few downloads for a small or new serviceThe app for a local gym or a neighbourhood shop will never have large numbers
Advertising inside a free appIt is a common business model; it becomes a signal when it leaves the app and takes over the phone
Permissions that fit the jobA navigation app asking for your location, or a video-calling app asking for the camera, is doing what it should
An icon or look that changed after an updateThis often happens with official apps, especially if the service announced it

The rule of thumb: one isolated signal deserves a check; two signals together mean do not install it, or remove it.

How often to check

You do not need a demanding routine. You need a short habit at the right moments.

FrequencyWhat to check
Every time you install a new appDeveloper, exact name, date, recent reviews and permissions: one minute before you tap “install”
When a message invites you to install an appDo not follow the link; start from the service’s official website
In the first few days after installationAds outside the app, accessibility requests, an icon that disappears
Every 2–3 monthsThe full list of apps, apps with accessibility or administrator access, subscriptions in the store
After news of fake apps imitating a service you useThat the app you installed is the one published by the official developer

A regular check goes well with the recommendation on removing apps you no longer use: the fewer apps you have, the easier it is to notice the one that should not be there.

Two important warnings

An indicator is not proof. A developer with an unfamiliar name may be the company that actually runs the service; a recent date may be down to a new version of the app. Check before you get alarmed — but always check: the service’s official website is the reference point that settles almost every doubt.

No indicators is not a guarantee. A well-made copy can have a believable name, carefully managed reviews and no strange requests in the first few days. Even the stores’ checks, which filter out many harmful apps, are not infallible. That is why protection does not rest on hunting for signs, but on the habit of starting from the official website and following its link to the store. Indicators help you notice in time; they do not replace the check.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to read an app’s store page: developer, date, reviews, permissions
AwarenessUnderstanding that a fake app exploits the trust you already place in a brand you know
Secure BehaviourPausing for a minute before installing, and keeping an eye on the phone in the days that follow

Reference level: FL2 — Beginner. This is the level at which you learn to observe methodically: knowing where to look and what you are seeing, even before you can solve every problem on your own.

Conclusion

Spotting a fake app does not mean treating every app with suspicion. It means knowing which details to check, so that a vague impression — “it looks like the right one” — becomes a one-minute check.

What to do right now. Open the store, look up an app you use often and check the developer’s name, the date and the most recent reviews. It is a useful exercise even when the app is the real one: the next time you look for a new app, you will already know where to look. To see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.

Related resources

Short guides from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.