The fastest way to check if your phone has malware is to run the security tools already on the device, not a new app. On Android, start with Google Play Protect, then run your manufacturer’s built-in scan, then read your app list, battery usage and mobile data usage by hand. On iPhone there is no equivalent scanner, so the check is manual and shorter. Ten minutes covers both.
That matters because most people never find out their phone is infected until something is obviously wrong: a bill for premium SMS, a banking alert from another country, ads on every page. By then the app has had weeks to work. Running the check early, before anything looks broken, is the whole trick.
One honest caveat before we start. No scan is a 100% guarantee, and a clean Play Protect result does not clear a phone that carries tracking software installed deliberately by someone with access to it. Those cases need the account and profile checks at the end, not just the malware scan.
Table of Contents›
- What You Need
- Step-by-Step: How to Check If Your Phone Has Malware
- Check for Suspicious or Unknown Apps
- Look for Unusual Battery, Data, or Performance Behavior
- Run a Security Scan and Review Security Alerts
- Check Browser Activity, Notifications, and Account Security
- Remove or Quarantine Suspected Malware
- Common Mistakes
- Frequently Asked Questions
- Does Google Play Protect find all malware?
- What is the best malware scanner for Android phones?
- Can an iPhone get malware?
- How do I remove malware from my phone without a factory reset?
- What are the signs my phone might be hacked?
- How do I know whether a strange app is a real system app?
- Conclusion
What You Need
You need very little, and most of it is already on the phone.
- Your phone, charged above 50%. Scans and system updates can take ten minutes or more, and a phone that dies mid-update is an unhappy phone.
- The built-in security tools. Google Play Protect on Android, Device Care or Security on your phone’s own Settings app, and on iPhone the software update screen and the VPN and device management screen.
- A reputable security app, optional. Useful as a second opinion, and only if you install it from the official store rather than from a link someone sent you.
- Access to your accounts. Your Google or Apple ID password, plus the password for your email and your bank. You will need these if you find something, and you will want to change them from a device you trust.
- A recent backup. Not for this check, but for the removal stage. People facing this check on an older phone often cannot afford to lose their photos and files, which is exactly why the non-destructive route comes first.
On a second-hand or inherited phone, add one more thing: the password to the previous owner’s Google or Apple account, because until that is removed the phone can be remotely wiped and you cannot fully trust it.
Step-by-Step: How to Check If Your Phone Has Malware

Work through these in order. The early steps are fast and app-free, the middle steps take a few minutes, and the last step only matters if one of the earlier ones found something.
Check for Suspicious or Unknown Apps
Most infections on Android arrive as an app, which makes this the highest-value check you will run. On Android, open Settings > Apps > See all apps and sort by recently installed, or by size, which is the trick people on community boards use to spot a fake system app sitting oddly among the real ones.
For each app you do not recognise, look at three things:
- The developer name under the app title. Real tools are published by a company name, not by something like “Apps Studio” or a string of capital letters.
- Whether the app was installed from the store. A setting under Settings > Apps > Special app access > Install unknown apps shows which app, if any, is allowed to install other apps. That permission turned on is a yellow flag on its own.
- What the app asks for. A flashlight or a simple calculator that wants your SMS messages, call logs, contacts and accessibility control is not a flashlight.
On iPhone, open Settings > General > VPN & Device Management. Anything listed there is a configuration profile, often installed by your employer or school, and a profile you did not install is worth understanding before you delete it. Also check Settings > General > iPhone Storage for apps you have never opened.
If an app looks wrong, do not open it to see what it does. That is how data leaves.
Look for Unusual Battery, Data, or Performance Behavior
Battery drain and data spikes are the two complaints that send people looking for malware, and both have innocent explanations. On Android, open Settings > Battery > Battery usage and check the top consumer, then compare it against how long the phone was on screen. One app using 40% of the battery in a day of heavy use is normal. The same app using 40% while the screen was off for most of that time is not.
Then open Settings > Network & internet > Data usage or Settings > Mobile network > Data usage and sort by mobile data. Most background traffic on a modern phone is the usual suspects: messaging apps, video streaming, cloud sync, and advertising inside free games and free weather apps. The pattern worth worrying about is one small app using hundreds of megabytes a month, or a jump in usage that began on a specific day. Note the date and compare it to what you clicked that day.
Other signals fit the same test. Pop-ups that appear outside the browser, a phone bill with premium SMS charges, apps crashing repeatedly, a device that gets hot while idle, and a home screen full of browser shortcuts you never added are all worth noting. A phone that got slow after four years of use is usually a phone that got slow after four years of use. Judge the symptom by when it started.
Run a Security Scan and Review Security Alerts
How to check if your phone has malware on Android starts with the scan you already have. Open the Play Store, tap your profile picture in the top right, choose Play Protect, then tap Scan. The scan starts immediately and usually takes well under a minute. While you are there, check that Play Protect is switched on, because malware that removed the protection usually turns it off first.
The result screen takes three forms. No issues found is the good one. A warning about a specific app means Play Protect has flagged it and offers to uninstall it, and you should read the reason before dismissing it. A notice that your device is not certified usually means the manufacturer or Google has revoked the device’s certified status, which is unusual on a phone you have owned for a while and worth looking into.
Next, run the manufacturer scan. Menu labels shift between firmware versions, so look for the words Device care, Security, Device protection or Security scan in your Settings list.
- Samsung: Settings > Device care > Device protection > Scan phone. On older models the same tool sits under Battery and device care.
- Pixel and stock Android: Settings > Security & privacy > More security settings > Security scan.
- Motorola: Settings > Security, then the device security or scan option inside it.
- Xiaomi and Redmi: Settings > General settings > Security, or open the Security app from the home screen and run its scan.
- OnePlus and Oppo: Settings > Security > Security scan, or Device care on some models.
On iPhone there is no malware scanner, and that is not an oversight. iOS does not install applications from outside its own store, which removes the route most Android infections travel. What you can check is the software itself: Settings > General > Software Update should show an up-to-date iOS version, because a phone missing security patches is a phone with known holes in it.
If you want a second opinion, install one well-known security app from the official store and run its free scan. The trap here is real and worth naming: some fake antivirus apps exist purely to install malware, and they usually arrive through pop-ups and ad-driven search results rather than the store. If a security app asks for accessibility control, device administrator rights or permission to run in the background before it will scan anything, that is not a scanner, and that is the pattern to watch for.
Check Browser Activity, Notifications, and Account Security
Some of the worst problems never show up as an app. A browser that redirects every search to a different site, notifications from apps you do not recognise, and a phone that buzzes with verification codes you never requested all point the same direction.
On Android, review notifications under Settings > Notifications > App notifications and turn off anything you cannot place. On iPhone, the same list lives under Settings > Notifications, and unknown sources at the top of the list are the ones to remove first.
Then check the account layer, because password theft is what these attacks are actually for. Sign in to your Google account on a computer, open Security and look at Your devices; anything you do not recognise, sign out of. Do the same for your Apple ID device list. If a password changed without you changing it, that is not malware any more, that is an account compromise, and the password needs changing today from a device you trust.
For suspected tracking rather than a dodgy app, there is a rough test people in Android support communities pass around: put the phone in airplane mode and leave it there, then check whether it still seems to be reporting or responding. It is a weak signal, not proof, and some hardware keeps activity running. But if a phone that should be offline is behaving as though it is not, that is reason enough to look at accessibility services and device administrator apps, both of which live under Settings > Apps > Special app access.
Remove or Quarantine Suspected Malware
If the check found something, work in this order and stop at the first step that clears the problem.
- Force stop the app so it stops running while you decide what to do with it.
- Revoke Device Administrator access first. This is the step people skip, and it is why uninstall buttons are greyed out on infected phones. Go to Settings > Apps > Special app access > Device admin apps, switch off the suspicious app, then uninstall it. You cannot remove the app until the permission is gone.
- Uninstall the app and delete its leftover data through Settings > Apps.
- Clear your browser data and installed web apps. Malicious installs often leave a home screen shortcut or a notification permission behind after the app is gone.
- Change your passwords from a clean device, start with your email, then your Google or Apple ID, then banking. Turn on two-factor authentication while you are there.
- Update the operating system and every remaining app, then re-run the built-in scan. A clean result after these steps is the signal that worked.
A factory reset is the last step, not the first. It is the only thing that removes something which has installed itself deep in the system, but it deletes everything on the phone, and plenty of people reading this are trying to keep an old device usable. Try the ordered steps above first, and reset only if the behaviour survives a clean scan and a reboot. Restore your backup afterwards, and if the phone came from someone else, reset it before you set up your own account rather than after.
Common Mistakes

Most failed checks fail for the same handful of reasons.
Deleting legitimate system apps. Files, Bluetooth, Google Play Services and similar entries look alarming in the app list because their names mean nothing. Sort by size and check the developer name before removing anything; a system app has the phone maker’s name as its publisher.
Installing a security app from a link or a pop-up. Searching for a phone virus checker free and clicking the first ad result is how people end up with the thing they were checking for. Go to the official store, read the developer, and check the review count and update date.
Treating a slow phone as an infected phone. Four-year-old hardware, a failing battery and full storage all look like malware from the inside. Check Settings > Storage and the battery health reading before you uninstall anything.
Ignoring browser-only threats. A malicious page or a rogue search extension can live entirely in the browser and never appear as an app. If the symptoms happen only while you browse, check your browser’s extensions and search provider.
Skipping the update. Many problems are fixed by the security patch already sitting in your update menu. Skipping system updates is not saving time, it is leaving a known hole open.
Cleaning the phone but keeping the same passwords. If the malware was on the device long enough to read a keylogger log or intercept a banking session, a clean phone is all that is left of the evidence. Change the passwords on another device, every time.
Frequently Asked Questions
Does Google Play Protect find all malware?
No. Play Protect checks apps in the Play Store as they are installed and re-checks apps already on your phone, which catches most Android malware. It is far less reliable against software installed deliberately with your permission, such as tracking apps given accessibility control, and against a phone that has been rooted. Treat a clean result as good evidence, not proof, and pair it with the manual app and account checks.
What is the best malware scanner for Android phones?
Start with Google Play Protect, which is free, already installed, updated by Google, and covers sideloaded apps when its scanning is enabled. A reputable second scanner from the official store is useful for a second opinion and for offline checks. Paid tiers mainly add automatic phishing link blocking and scheduled scans, so they are optional unless you browse risky links often.
Can an iPhone get malware?
Real iOS malware is rare because apps cannot be installed from outside the App Store. What iPhones are more likely to have is a configuration profile installed by someone with physical access or through a fake update prompt, and subscription scams that trick you into approving a payment. Check Settings, then General, then VPN and Device Management, and remove any profile you did not install.
How do I remove malware from my phone without a factory reset?
Most infections can be cleared without one. Force stop the app, revoke its Device Administrator access under Settings, Apps, Special app access, Device admin apps, uninstall it, clear your browser data, then change your email, Google or Apple, and banking passwords from a trusted device and turn on two-factor authentication. Re-run the built-in scan afterwards to confirm it worked.
What are the signs my phone might be hacked?
Common signs include apps you never installed, pop-ups outside the browser, a battery that drains fast while the screen is off, mobile data usage far above your normal, notification spam, redirected searches, changed passwords, sign-in alerts from unfamiliar locations, premium SMS charges, and a device that stays active in airplane mode. Any one of these can be innocent. Several together, starting on the same day, are the pattern worth acting on.
How do I know whether a strange app is a real system app?
Open it and read the developer name under the title. System apps are published by your phone maker, and core Android components are published by Google, so the name is short and specific. Look-alike apps use long strings of capitals, unrelated words, or a name that imitates a service you know. A simple game or utility asking for accessibility control, SMS and call logs is not a simple game or utility.
Conclusion
If you only do four things, do these: open your app list and deal with anything you do not recognise, run Google Play Protect and read the result carefully, change your email and banking passwords from a device you trust, and install the operating system update that is waiting for you.
The full check takes about ten minutes and costs nothing. Do it now while the phone feels normal, because that is the moment the evidence is still readable.


