Android Malware Stalkerware And Compromise
20 pages · 27 min read
- Mobile and messaging evidence
- Cyber incidents and ransomware
Guide · 20 pages · 27 min read · Published 2026-09-02
Read this guide on your phone, browse guides by topic or go back to the full PDF library.
20 pages · 27 min read
Published by Computer Forensics Lab on 2026-09-02. Original material of the practice, free to read, cite and download. The authority behind this subject is NCSC incident management guidance, which you should read alongside this guide. See every guide's author and source.
Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.
The Open Platform's Larger Threat Surface, What Can Be Found, and the Duty
of Care That Comes First
12 Checklist and red flags · When to involve a digital forensic expert
14 Glossary · References · Disclaimer · How a specialist laboratory can assist
The headline point: Android's openness gives it a larger threat surface than iOS, sideloaded stalkerware and
malware are easier to install and sweeping permissions let them see a great deal, but the most common
surveillance is still consumer stalkerware installed with physical access or the misuse of legitimate features,
openness also lets an examiner inspect apps and permissions more fully, and, as on iOS, the person's safety
comes before the evidence.
Checklist and red flags · When to involve a digital forensic
expert
19. This guide continues the Android block. Through cflab.uk and e-discovery.uk, Android compromise work
My client thinks their phone is being tracked. Where do we start?
Does an app with broad permissions prove it is spyware?
Speak to a forensic examiner, not a salesperson.
17 pages · 25 min read
19 pages · 26 min read
Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.