TL;DR: Three different things get called "spyware," and they need different responses. Stalkerware is consumer software a partner or family member installed with physical access. Government-grade spyware (Pegasus, Graphite) is sent to you specifically by a state-level adversary. The middle ground is consumer monitoring apps that market themselves as "parental control" or "employee monitoring." If you are not a journalist, activist, or diplomat, you almost certainly have the first or third kind. Detection on Android is straightforward: check for unfamiliar apps and run a stalkerware scan. Detection on iPhone is harder because iOS restricts background apps. If Apple or Google sends you a threat notification, treat it as real and call Access Now's helpline.
The Three Threat Levels
Most guides collapse these into one bucket. They are not the same problem.
- Stalkerware: a partner, ex, or family member physically installed monitoring software on your phone. They know your passcode or got the phone unlocked. Examples include apps like Certo, mSpy, and pcTattletale.
- Consumer monitoring: an employer, parent, or "family tracker" app that is technically disclosed but easy to overlook. Often marketed as parental control or fleet management.
- Government-grade (mercenary) spyware: state-sponsored tools like NSO Group's Pegasus or Paragon's Graphite, delivered through exploits in iMessage, WhatsApp, or your browser. Apple and Google send notifications when they detect this on your device.[1]
Which one you suspect changes what to do. Stalkerware removal may alert the installer. Government-grade infection means someone with serious resources is watching you and you need professional help.
Warning Signs That Apply to All Three
None of these signs is proof on its own. The Coalition Against Stalkerware notes that stalkerware "may" run without any visible symptoms at all, so absence of these signs does not mean absence of stalkerware.[2] Trust your gut alongside the checklist.
- Battery draining faster than usual: a process constantly uploading your data burns power.
- Data usage spikes you cannot explain: every keystroke and location ping leaves the device.
- Phone runs warm when idle: a background monitoring process keeps the radio active.
- Screen Time or Digital Wellbeing shows a strange spike: if you barely used your phone this week but the chart is climbing, something is.
- Someone knows things they should not: a partner quoting a private chat, a boss mentioning your location, an ex referencing a photo you never sent.
- Phone was out of your control: left in a hotel room, given to a "friend" for repair, gifted to you pre-configured.
How to Detect Spyware on Android
Android is the easier platform to check, because sideloaded apps can run in the background with broad permissions. The Coalition Against Stalkerware recommends two parallel steps: a free antivirus scan from a coalition-partner app, and a manual check for hidden or side-loaded apps.[2]
Step 1: run a stalkerware-aware antivirus scan
Generic antivirus often misses stalkerware because stalkerware is a deliberately commercial, semi-legal category. Look for apps that specifically name stalkerware detection:
- Malwarebytes (free tier scans for known stalkerware signatures)
- Norton 360 or Bitdefender Mobile Security (flag known monitoring apps)
- Certo AntiSpy (built specifically for this)
- Avast or AVG (free mobile scans include some stalkerware detection)
Step 2: check for apps you did not install
- Go to Settings → Apps → See all apps.
- Sort by Last used or Install time. Anything you do not recognize is suspect.
- Generic names are a tell: "System Service," "Device Health," "Wi-Fi Helper," "Sync Manager." Real system apps come from Google or your phone maker and have recognizable icons.
- For any unfamiliar app, long-press the icon, tap App info, and check the install source.
Step 3: check device administrator apps
- Go to Settings → Security → Device admin apps (the exact path varies by Android version; on Samsung it is under Settings → Biometrics and security → Other security settings → Device admin apps).
- Anything beyond "Find My Device" and a known work MDM is suspicious. Stalkerware loves this permission because it makes uninstall harder.
Step 4: check what apps can use sensitive permissions
- Go to Settings → Privacy → Permission manager.
- Look at Location, Camera, Microphone, SMS, and Call logs. An app with all five and no obvious purpose (a calculator that wants your texts) is a flag.
Step 5: check sideloading
Go to Settings → Apps → Special access → Install unknown apps. If a browser or messaging app has permission to install APKs, stalkerware could have been installed outside the Play Store.
How to Detect Spyware on iPhone
iOS is harder to infect than Android, but not impossible, especially if the phone was jailbroken or someone knows your Apple ID password. Apple does not allow apps to fully hide in the background the way Android does.
Step 1: check for jailbreak
Look for the Cydia, Sileo, or Zebra app on the home screen or in App Library. If any is present, the phone has been jailbroken and is much more vulnerable to monitoring software.
Step 2: check configuration profiles
- Go to Settings → General → VPN & Device Management.
- Look for profiles you did not install. Employer MDM is expected and named. Anything else deserves scrutiny.
Step 3: verify iCloud Backup
The Coalition Against Stalkerware flags one specific iPhone red flag: if your device is backing up to iCloud but you do not remember enabling that, someone else may have done it from your Apple ID.[2] To check:
- Go to Settings, tap your name at the top.
- Scroll down and tap your device in the list.
- Confirm iCloud Backup is the setting you would expect.
Step 4: review Apple ID device list
- Go to Settings → [Your Name] and scroll to the bottom of the Apple ID device list.
- Any device you do not recognize should be removed.
- Check Find My: if someone else is signed in to your iCloud, they can see your location.
Step 5: review privacy access
Go to Settings → Privacy & Security and look at Location Services, Microphone, and Camera. An app with "Always" location access that has no business needing it is suspicious.
Step 6: check battery usage
Go to Settings → Battery. Scroll to the bottom for per-app battery use. A monitoring app will often show heavy background activity.
If You Got a Threat Notification From Apple or Google
Apple has sent threat notifications to users in over 150 countries since 2021, multiple times per year.[1] Google's equivalent warns users of "government-backed attackers." These notifications are not spam. They mean a high-confidence detection that you were individually targeted by mercenary spyware.
Apple's notification lands three ways: at the top of Settings, in your email (from [email protected]), and as a banner on account.apple.com after you sign in.[1] A real Apple threat notification will never ask you to click links, install apps, or share your Apple ID password.
If you got one:
- Enable Lockdown Mode immediately. Path: Settings → Privacy & Security → Lockdown Mode. Apple describes it as defense for users who "have good reason to believe you may be individually targeted."[1]
- Contact Access Now's Digital Security Helpline. They run a 24/7 rapid-response service for civil society targets, with a two-hour response time, free of charge, in ten languages.[3] Apple itself tells notified users to contact them.[1] Email: [email protected].
- Treat the device as compromised. Modern mercenary spyware uses smash-and-grab tactics: extract everything, then delete itself. By the time you see the notification, your messages, contacts, photos, and passwords may already be in someone else's hands.
- Move sensitive conversations to a separate, clean device. Lockdown Mode prevents future attacks. It does not erase what has already been taken.
For Android, Google's counterpart is the Advanced Protection Program.[4] It requires a passkey or physical security key (like a Titan Key or YubiKey) for sign-in, restricts app installs to Google Play and your device maker's verified store, and limits which third-party apps can touch your Google data.
What to Do Once You Find Something
The right next step depends on what you found and who installed it.
If you found stalkerware on an Android phone: a factory reset is the only guaranteed kill. Back up only what you need to a computer (not a cloud account the installer might also control), reset the device, set it up as new rather than restoring a backup, then change every important password from a different device.
If you found stalkerware on an iPhone: remove the suspicious configuration profile (Settings → General → VPN & Device Management → [profile] → Remove Profile). Change your Apple ID password from a clean device. Enable Stolen Device Protection on the iPhone so a passcode thief cannot disable Find My.
If you are in an abusive relationship: the Coalition Against Stalkerware is blunt: removing stalkerware may alert the person who installed it and may escalate the situation.[2] Use a device the abuser has never touched to research help. In the US, the National Domestic Violence Hotline is 1-800-799-7233.
If you found a profile that looks like work MDM: confirm with your employer before removing it. Some companies monitor company-owned devices as part of their employment contract. If the phone is yours and the profile was installed without your consent, removing it is reasonable.
What These Steps Cannot Do
Be honest about the limits:
- No consumer scan catches everything. Stalkerware is a moving target and detection rates vary between products.
- On a non-jailbroken iPhone, true zero-click government spyware may leave no trace a consumer tool can find. Apple and Google are the ones who can detect it, which is why their threat notifications matter.
- Removing stalkerware without a safety plan can be dangerous if the installer is an abusive partner.
- Once mercenary spyware has extracted your messages and contacts, no tool can put that data back. Damage from a successful Pegasus infection is done before you ever see the notification.
If you suspect something serious and the simple checks above do not reassure you, stop reading guides and call Access Now's helpline at [email protected] or contact Citizen Lab. They do this for a living.