Skip to content Skip to sidebar Skip to footer

Stalkerware Detection on Phone

By Dana Reyes

“Stalkerware” is the term security researchers use for commercial apps sold openly as “parental monitoring” or “employee tracking” software that get installed on someone’s phone without their knowledge or consent to secretly track location, messages, calls, and browsing. Unlike malware you accidentally download, stalkerware is usually installed deliberately by someone with physical access to the device — a partner, ex-partner, or family member — which is what makes detection and removal genuinely dangerous to get wrong.

Read This First If You Suspect an Abusive Partner

If you believe stalkerware was installed by a current or former abusive partner, do not immediately delete it. Removing the app can tip off the person monitoring you the moment the data feed goes dark, which security researchers and domestic violence advocates warn can escalate real-world risk. The Coalition Against Stalkerware and the National Domestic Violence Hotline (1-800-799-7233) both recommend safety planning before you act on what you find.

Warning Signs Worth Checking

  • Battery draining faster than normal — a hidden app running location and microphone access in the background is expensive on power.
  • Mobile data disappearing quicker than usual — stalkerware regularly uploads screenshots, texts, and location pings to a remote server.
  • Phone running hot when idle, or taking longer than usual to shut down.
  • Location services, Wi-Fi, or mobile data turning themselves back on after you’ve switched them off.
  • Unexplained rise in data/storage usage from an app you don’t recognize or that’s disguised with a generic name like “System Service” or “Sync.”

How to Check — Android

Go to Settings → Accessibility and review which apps have Accessibility permissions — this permission set is what most consumer stalkerware abuses to read what’s on your screen, since it was designed for legitimate assistive tools. Also check Settings → Apps → Special app access → Device admin apps, since stalkerware frequently requests device-admin rights to resist uninstallation, and run Google Play Protect (Play Store → profile icon → Play Protect) for a baseline scan, understanding that Play Protect alone regularly misses stalkerware because these apps aren’t classified as traditional malware.

How to Check — iPhone

iOS’s sandboxing makes classic stalkerware rarer without a jailbreak, but check Settings → General → VPN & Device Management (labeled “Profiles & Device Management” on older iOS versions) for any configuration profile you didn’t install — a rogue MDM (mobile device management) profile is the most common way an iPhone gets remotely monitored, since it can grant remote visibility into the device the way a company IT profile does. If that screen shows nothing, that’s a good sign; no profile means no MDM-based monitoring is active.

Detection Tools Compared

Tool Platform How It Works Best For
Kaspersky TinyCheck Android & iOS (external scanner) Free, open-source; runs on a separate device (commonly a Raspberry Pi) and inspects your phone’s network traffic without installing anything on the phone itself Anyone worried an abuser might notice a new app appearing — it leaves no trace on the monitored phone
Certo AntiSpy / Certo Mobile Security iOS & Android On-device scan for known spyware/stalkerware signatures and suspicious configuration profiles A fast, install-and-scan first check
iVerify (Trail of Bits) iOS only Forensic-style checks for jailbreak indicators, unusual profiles, and device-integrity anomalies iPhone users who want a more technical, security-researcher-grade audit
Malwarebytes / Lookout (mobile) Android & iOS General mobile antivirus with growing stalkerware-signature databases A baseline scan alongside one of the dedicated tools above, not a replacement for them

Common Mistakes

Relying on one scan and stopping there is the biggest one — stalkerware vendors update their apps specifically to dodge detection signatures, so a clean scan from a single tool isn’t proof of a clean phone. Factory-resetting the device is tempting but destroys evidence if you may need it for a protective order later; if that’s a possibility, photograph what you find first and consult a domestic violence advocate about evidence preservation before wiping anything.

FAQ

Does a VPN protect against stalkerware? No. A VPN encrypts your network traffic from outside observers like your ISP, but stalkerware runs directly on the device and reads data before it ever reaches the network layer — a VPN can’t see or block it.

Will a factory reset remove stalkerware for certain? Almost always, yes, since it wipes all installed apps — but see the evidence-preservation caution above before you do it in a domestic-violence context.

Can stalkerware be installed remotely, without physical access? Consumer stalkerware overwhelmingly requires a few minutes of physical access to install; remote-only compromise is far rarer and usually points to a different (and more serious) category of spyware, which is a reason to also check for unrecognized MDM profiles as described above.

Verdict

Start with the free warning-sign checklist and settings checks above — they cost nothing and take ten minutes. If you find something and safety is a concern, TinyCheck’s off-device approach is the least likely to alert whoever installed it, while Certo or iVerify are the fastest single-app options if discretion isn’t the priority. Either way, treat a positive finding as a safety-planning moment, not just a technical cleanup task.