§ Guide

Android Malware Stalkerware And Compromise

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 20 pages · 27 min read · Published 2026-09-02

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-09-02. Original material of the practice, free to read, cite and download. The authority behind this subject is NCSC incident management guidance, which you should read alongside this guide. See every guide's author and source.

§ Full text of Android Malware Stalkerware And Compromise

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.

Compromise

The Open Platform's Larger Threat Surface, What Can Be Found, and the Duty

of Care That Comes First

11 Questions to ask · Suggested wording

12 Checklist and red flags · When to involve a digital forensic expert

13 Frequently asked questions

14 Glossary · References · Disclaimer · How a specialist laboratory can assist

Executive summary

The headline point: Android's openness gives it a larger threat surface than iOS, sideloaded stalkerware and

malware are easier to install and sweeping permissions let them see a great deal, but the most common

surveillance is still consumer stalkerware installed with physical access or the misuse of legitimate features,

openness also lets an examiner inspect apps and permissions more fully, and, as on iOS, the person's safety

comes before the evidence.

§ 12 · QUICK CONTROL

Checklist and red flags · When to involve a digital forensic

expert

When to involve a digital forensic expert

19. This guide continues the Android block. Through cflab.uk and e-discovery.uk, Android compromise work

Is Android more vulnerable to stalkerware than iPhone?

My client thinks their phone is being tracked. Where do we start?

How can stalkerware be found on Android?

Does an app with broad permissions prove it is spyware?

Sources and authoritative references

35 and CrimPR Part 19 reporting): cflab.uk/digital-forensics-services · guides library: cflab.uk/guides

Working with Computer Forensics Lab

Speak to a forensic examiner, not a salesperson.

§ Common questions

Frequently asked questions

Is Android more vulnerable to stalkerware than iPhone?
Its threat surface is larger, and its visibility is greater (
My client thinks their phone is being tracked. Where do we start?
With their safety, before any exam in at i on (
Does an app with broad permissions prove it is spyware?
No, permissions are necessary but not sufficient (
Should we just uninstall any stalkerware we find?
Not reflexively, because removal can escalate risk (
§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp