Outsourcing the IT department doesn’t remove the governance problem, it
Before You Sideload That APK: A Practical Android Safety Guide
Over the past couple of years, police in several Indian states have issued warnings about a message that looks entirely harmless. It arrives on WhatsApp from a number that may even be saved in your contacts, and it says something like “You’re invited to our wedding, please see the card.” Attached is a file. It is not a PDF or an image. It is an APK, and anyone who opens and installs it may be giving a stranger access to their SMS messages, their one-time passwords and eventually their bank account.
Variations of the same trick arrive as traffic challan notices, electricity disconnection warnings, bank “KYC update” apps and delivery tracking links. They all rely on one thing: Android lets you install apps from outside the Play Store, and most people have never been shown how to judge whether that is safe.
Table of Contents
What Sideloading Actually Means?
An APK is the installation file for an Android app. When you install one from somewhere other than the Play Store, that is sideloading.
Sideloading is not inherently dangerous, and there are plenty of legitimate reasons to do it. Open-source apps are distributed through alternative stores such as F-Droid. Developers share beta versions directly with testers. Companies install internal tools on staff phones. Some services never list their apps on the Play Store at all because of store policies in their category.
What sideloading removes is a layer of review. Apps on the Play Store are scanned and are subject to Google’s policies. An APK passed around in a chat group has had no such check, so you become the reviewer.
Why Attackers Favour APK Files?
From an attacker’s point of view, a sideloaded app is ideal. Nobody has vetted it. It can request powerful permissions the moment it opens. And it arrives with a story attached, whether that is a wedding, a fine or a bank warning, which pushes people to tap before they think.
Once installed, malicious apps commonly try to do some combination of the following:
- Read incoming SMS messages to capture one-time passwords.
- Abuse accessibility features to read what is on screen and tap buttons on the user’s behalf.
- Draw fake login screens over genuine banking apps to capture credentials.
- Hide their own icon so the user forgets the app is there.
- Forward messages to contacts so the same file spreads further.
None of this requires a sophisticated hack. It only requires a user to install the file and grant the permissions it asks for.
Why “It Came From Someone I Know” Means Nothing?
The most convincing part of these scams is often the sender. The message comes from a cousin, a colleague or someone from the building’s residents’ group, so the usual suspicion never switches on.
That familiarity is exactly how the malware spreads. Once one phone is infected, many malicious apps send the same file to that person’s contacts, from that person’s own WhatsApp account. The sender is usually a victim, not an accomplice, and has no idea their phone is sending anything.
So the name at the top of the chat tells you very little about the file underneath it. If a friend unexpectedly sends an APK, call them and ask, using a normal phone call rather than a reply in the same chat. If their account has been taken over, a reply in the chat may be answered by the attacker.
The Permissions That Should Stop You Cold
The single most useful habit is checking whether an app’s permissions make sense for what it claims to do. A few deserve particular suspicion:
- Accessibility service. Essential for genuine assistive tools. For almost anything else, and especially for an app that arrived in a chat, it is a serious red flag.
- Read and receive SMS. This is how most OTP theft happens.
- Notification access. Lets an app read the contents of your notifications, including OTPs that appear there.
- Display over other apps. The permission behind fake login screens.
- Device admin. Makes an app much harder to uninstall.
- Install unknown apps. An app that wants to install other apps should have a very good reason.
A simple rule covers most cases. A wedding invitation doesn’t need to read your SMS. A challan viewer doesn’t need accessibility access. If the permission doesn’t fit the purpose, don’t grant it, and uninstall the app.
Checks Before You Tap Install
Before installing any APK, work through these:
- Check the source. Download only from the developer’s official website, reached by typing the address yourself. Never install an APK that arrived as a chat attachment, however familiar the sender.
- Check the file itself. An “invitation”, “challan” or “bill” should never be an APK. If the file name and the file type don’t match the story, stop.
- Scan it. Upload the file to a multi-engine scanner such as VirusTotal before installing. Google Play Protect can also scan apps installed from outside the Play Store.
- Compare the hash. Some developers publish a SHA-256 checksum for their APK. If the checksum of your file doesn’t match, it isn’t the file the developer released.
- Search for the name. A quick search for the app name alongside words like “fake” or “scam” often turns up warnings from other users.
- Anything that insists you install immediately is using urgency as a tool. A genuine app will still be there tomorrow.
Settings That Do Half the Work for You
Android already has most of the protection you need. It only has to be switched on and left alone.
- Keep Play Protect enabled. You’ll find it in the Play Store under your profile menu.
- Treat “Install unknown apps” as temporary. On modern Android, this permission is granted separately to each app, such as a browser or file manager. Allow it only for the install you intend, then switch it off again.
- Stay up to date. Security patches close holes that malicious apps rely on. Install system updates promptly.
- Use enhanced protection in Chrome. Safe Browsing’s enhanced mode warns about dangerous downloads and sites more aggressively.
The landscape is also changing. Google has announced plans to require developers of apps installed outside the Play Store to verify their identity, starting with a small group of countries in 2026 and widening after that. That should make anonymous malicious APKs harder to distribute, but it will not replace careful habits.
Do You Need the App at All?
A surprising number of services work perfectly well in a mobile browser, which avoids the installation question entirely.
Many sites support “Add to Home screen”, which creates an app-like icon that opens the website without installing anything. Shopping, news, ticket booking and many streaming services all run comfortably this way. For banking, the safest route remains the bank’s own app from the Play Store, or its official website.
The same applies to some sports and gaming services. Services built around a cricket online ID, for example, typically issue a login that works in the phone’s browser, so installing anything is rarely part of the process. That makes an unexpected request to install an unfamiliar APK to “activate” such an account a reason for extra caution. Rules on real-money gaming also vary between countries and have changed in India, so the legal position is worth checking before signing up to anything in that category.
Signs an App Has Already Gone Wrong
If you have installed something and feel uneasy about it, watch for these:
- Battery or mobile data usage rising sharply for no obvious reason.
- OTP messages arriving for logins or transactions you didn’t start.
- Friends mentioning messages from your number that you never sent.
- An app whose icon vanished shortly after installation.
- An accessibility service or device admin app you don’t recognise under Settings.
- An app that refuses to uninstall.
What to Do If You Installed Something Bad
Speed matters here, because malicious apps work fast.
- Turn off mobile data and Wi-Fi to cut the app’s connection.
- Revoke powerful access. Check Accessibility settings and device admin apps, and switch off anything unfamiliar.
- If the app blocks removal, restart the phone in safe mode, which disables third-party apps, and uninstall it from there.
- Secure your accounts from another device. Change passwords for email and banking, and turn on two-factor authentication.
- Call your bank. Ask them to block cards and UPI access if there is any chance they were exposed, and review recent transactions.
- Report it. Use the 1930 helpline or cybercrime.gov.in, especially if money has been taken.
- Reset if in doubt. Back up photos and contacts, not apps, and perform a factory reset.
Setting Up Phones for Parents and Children
The people most likely to install a malicious APK are often the ones least likely to read a guide like this one. A few minutes with their phone can do more than any warning forwarded to the family group.
For older parents, check that Play Protect is on, make sure no browser or messaging app has permission to install unknown apps, and remove any unfamiliar apps together. Then agree on one simple rule: no installing anything that arrives in a message without calling a family member first.
For children, Google Family Link lets parents supervise the apps a child can install and review what is already on the device. It is worth pairing with an honest explanation of why a free “mod” version of a popular game, downloaded from a random site, is such a common way for malware to get onto a phone.
A Habit, Not a Product
No antivirus app can fully protect a phone whose owner installs whatever arrives in a chat and taps “Allow” on every prompt. The good news is that the habits that do protect you are simple. Get apps from official sources. Match permissions to purpose. Prefer the browser when an app isn’t needed. And treat any file that claims to be an invitation, a fine or a bill but ends in .apk as exactly what it is.