In short: Stalkerware is spy software installed not by a stranger, but by someone you know — a jealous partner, overprotective parent, or suspicious employer. It hides its icon, runs in the background, and sends your messages, location, and photos to a specific person. The clearest signs are rapid battery drain and unfamiliar entries in Accessibility Services and Device Admin settings. If you find a suspicious app, do not delete it immediately: the stalker may receive an alert, and you will lose evidence. First assess your safety, change passwords from a trusted device, then act.
What stalkerware is and how it differs from ordinary spyware
Stalkerware is a type of spyware that requires physical access to the victim's phone to install. Unlike a banking trojan that arrives through phishing and sends data to anonymous criminals, stalkerware follows a different model: a specific person you know installs it and receives the data in their private dashboard on the vendor's website.
This distinction matters. An ordinary trojan tries to steal money or credentials; stalkerware is about control — where you are, who you talk to, what you write. That's why the Coalition Against Stalkerware — an international coalition of domestic violence organisations and cybersecurity companies — classifies it as a separate threat category.
Who installs stalkerware and why
Three typical installation scenarios:
- A jealous partner or ex. Wants to know who you talk to, where you go, and to read your messages. Usually installs while they have brief access to your unlocked phone.
- An "overly caring" parent. Installs on an adult child's phone without consent, seeing it as normal. The line between legal parental controls on a minor's device and illegal surveillance of an adult is particularly thin here.
- A suspicious employer. MDM profiles on corporate devices are legal with employee consent. Hidden spyware on a personal phone is not.
| Attribute | Stalkerware | Legitimate parental controls | Classic spyware trojan |
|---|---|---|---|
| Who installs it | Someone you know, with physical access | Parent, on a child's device | Hacker via phishing / malicious file |
| Consent / disclosure | None | Usually none for minors; required for adults | None |
| Is the icon visible | Hidden or disguised as a system app | Typically disclosed | Hidden |
| What it collects | Location, messages, calls, photos, microphone | Location, screen time, websites | Passwords, bank data, clipboard |
| Data goes to | A specific person via web dashboard | The parent | Anonymous criminals |
| Legality | Illegal (surveillance of adult without consent) | Partially legal (minors) | Illegal |
Why stalkerware apps can't be trusted: the 2026 breaches
In February 2026, a data activist leaked a database containing 536,000 customer records belonging to Struktura (also known as Ersten Group) — the developer behind Geofinder, uMobix, Peekviewer, and Xnspy. The leak included buyer email addresses, payment amounts, and the last four digits of payment cards. The incident was independently confirmed by TechCrunch (2026-02-09) and SC Media. According to TechCrunch's count, this is at least the 27th stalkerware company breached since 2017.
This pattern reveals risks on both sides. The victim loses privacy — the watcher sees their data. But the watcher is also exposed: their email, payment details, and the fact that they purchased spyware can end up with criminals who breach the vendor's servers. Stalkerware companies systematically underinvest in security, as Malwarebytes Labs has documented through its analysis of repeated breach incidents.
The conclusion is straightforward: stalkerware is technically unsafe for everyone involved — not just the victim.
Signs stalkerware may be on your phone
No single sign guarantees spyware is present — overheating can come from video streaming, and a data spike from updates. But a combination of several signals is reason to investigate.
- Rapid battery drain and overheating at idle. Stalkerware runs constantly in the background, transmitting GPS coordinates and recording audio — all of which drain the battery and warm the processor even when the screen is off.
- Unusual mobile data usage. The app regularly uploads data to a server. Check which app is consuming mobile data in your settings — especially suspicious if it's labelled as a system app or has a generic name.
- Unknown apps or "system" duplicates. Stalkerware often disguises itself as "Sync Manager", "System Monitor", or "Battery Manager", or hides its icon entirely while remaining in the full app list.
- Unknown app in Accessibility Services. This is the most reliable signal: Accessibility access lets an app read everything displayed on screen. Legitimate apps rarely need this, and always with a clear explanation.
- Unknown app with Device Admin rights. Device Admin grants powerful privileges that protect the app from being deleted. Stalkerware often requests this during installation.
- The person "knows too much." They know where you've been, what you've written, what you've searched — without any logical explanation. This behavioural signal can outweigh any single technical indicator. For how to distinguish a compromise from a device issue, see signs your phone has been hacked.
How to safely check your phone
Your check should be discreet. If the watcher receives a notification about suspicious activity — such as removing a "monitoring" app — it may provoke a confrontation. Work methodically without revealing your intentions.
Android
Android offers more transparency, making a thorough check more achievable.
- Accessibility Services. Settings → Accessibility → Installed services. Make sure only apps you consciously granted access — screen readers, password managers — are listed.
- Device Admin apps. Settings → Security → Device Admin apps. An unfamiliar app with this right is a red flag.
- All apps. Settings → Apps → change the filter to All. Look for apps with neutral names, zero screen time, but high data or battery consumption.
- Permissions — especially microphone, location, and SMS. Settings → Privacy → Permission Manager. Select Microphone and Location and review which apps have always-on access. For a full breakdown, see dangerous app permissions.
- Install from unknown sources. Settings → Apps → Special app access → Install unknown apps. If a browser or file manager has this right, it was likely the pathway the stalkerware used to get on your device.
- Google Play Protect. Play Store → Profile → Play Protect → Scan. The built-in scanner detects many stalkerware apps as monitoring programmes or potentially unwanted applications.
- TinyCheck. Kaspersky's network-analysis tool: if you have an OpenWrt-compatible router, TinyCheck can be deployed to monitor traffic from the phone without installing anything on the device — detecting suspicious connections without alerting the spyware.
iPhone
Full-featured stalkerware without a jailbreak is rare on iPhone: the App Store blocks apps with covert monitoring capabilities, and iOS restricts background access to other apps' data. But surveillance is still possible through other mechanisms.
- MDM or configuration profiles. Settings → General → VPN & Device Management. An unfamiliar profile you didn't consent to can grant third-party servers broad access — including email, location, and app installation.
- Apple ID and iCloud access. This is the primary surveillance vector on iPhone. Anyone who knows your Apple ID password can see your iCloud photos, track your location through Find My, and read iMessage backups stored in iCloud. Check: Settings → [Your name] → review the device list and Find My; change your password and enable two-factor authentication if you suspect unauthorised access.
- Family Sharing and location sharing. Settings → [Your name] → Family Sharing; Settings → Privacy → Location Services → Find My Friends. Make sure your location isn't shared with anyone without your knowledge.
- Signs of jailbreak. Full stalkerware is possible on a jailbroken iPhone. Signs: Cydia or Sileo apps, unusual process names, anomalous traffic on non-standard ports.
On a modern non-jailbroken iPhone, the real threat vector is not a hidden app — it's access to your account. Changing your Apple ID password from a trusted device closes most of these scenarios.
What to do if you find stalkerware — checklist
- Do not delete the app immediately. Many stalkerware apps send the watcher an alert when deleted or when permissions change. Sudden action may escalate a conflict and destroys evidence if you plan to involve law enforcement.
- Assess your safety. If the surveillance is linked to violent or aggressive behaviour, your safety comes before preserving evidence. Seek help from a trusted device — a friend's phone or a library computer — before taking any technical steps.
- Change your key passwords from a different device. Email, Apple ID / Google account, messaging apps, banking. Only do this from a device you trust — on the compromised phone, the watcher may see everything you type.
- Enable two-factor authentication. Also from a trusted device. 2FA blocks access to your accounts even if a password is leaked.
- Review connected access. Apple ID / Google account: check the list of devices with access and revoke unfamiliar ones. For Google: myaccount.google.com → Security → Your devices.
- Preserve evidence. If you plan legal action — screenshot the app, the Accessibility settings, and the Device Admin list before deleting anything.
- Update your OS. A fresh Android or iOS update patches vulnerabilities the spyware may have used to persist.
- Factory reset — clean slate. When you're ready: a full reset will completely remove stalkerware. Do not restore a backup from the period when the app may already have been installed — reinstall apps manually and change all passwords again. Otherwise the app may return from the backup.
How to protect your phone from stalkerware going forward
The main stalkerware vector is physical access to an unlocked phone. Your first line of defence is keeping the device in your hands and using a strong lock screen code.
- Strong PIN / password + biometrics. Don't hand an unlocked phone to others — even briefly. Stalkerware can be installed in under a minute.
- Regular Accessibility and Device Admin audits. Check these sections monthly — nothing unfamiliar should be there.
- Permissions audit. Permanent microphone or location access is needed by very few apps. Review and revoke what's unnecessary. See dangerous app permissions for what to look for.
- Don't install apps from unknown sources. On Android: don't allow APK installation from browsers or file managers without a specific, deliberate reason.
- Two-factor authentication on Apple ID and Google account. Even if someone learns your password, they won't be able to sign in without the second factor.
- Keep your OS updated. Security patches close vulnerabilities that spyware uses to persist in the system.
LiMP VPN does not remove or block stalkerware already on your device — it runs locally inside the system, and the VPN tunnel doesn't reach it. But VPN addresses a separate threat layer: traffic interception on untrusted and public networks. LiMP VPN for Android encrypts all internet traffic so neither your ISP nor the owner of a hotspot can read it — an additional protection layer on top of your anti-stalkerware measures. For a broader look at phone privacy, see how to protect your phone from tracking.
Frequently asked questions
Can stalkerware run on an iPhone without a jailbreak?
Full-featured stalkerware — rarely. The App Store blocks apps with covert monitoring capabilities, and iOS strictly limits background data access. But surveillance can still happen through your Apple ID and iCloud (anyone with your password sees photos, location via Find My, and iMessage backups) or through a configuration or MDM profile. Check Settings → General → VPN & Device Management, and change your Apple ID password if you have doubts.
Is stalkerware visible in the app list?
Not always. Stalkerware typically hides its icon from the home screen and disguises itself as a system app with a neutral name. To find it, look not at the home screen but in the full installed-app list (Settings → Apps → All), and check the Accessibility and Device Admin sections.
Will an antivirus detect stalkerware?
Partly. Google Play Protect and mobile antivirus apps detect many stalkerware products as monitoring programmes or potentially unwanted applications. But professional products can evade signature-based detection. An antivirus is a useful first layer, but it doesn't replace a manual check of Accessibility, Device Admin, and permissions.
Does LiMP VPN protect against stalkerware?
No — and it's important to be honest about this. Stalkerware runs locally on the device: it is already inside the system and reads data directly, without passing through the network tunnel. A VPN encrypts traffic between the device and the internet but has no visibility into what happens inside the device itself. LiMP VPN's value here is different: closing traffic interception on public networks as a separate security layer.
Is it legal to track a spouse's or child's phone?
Tracking an adult without their consent is illegal in most jurisdictions. In the US and EU it can violate wiretapping and computer-misuse laws. The Coalition Against Stalkerware supports victims and tracks legal cases. Parental monitoring of a minor's device is a separate case with its own legal conditions. This is not legal advice; consult a professional if needed.
Does a factory reset remove stalkerware?
Usually — completely. Two conditions apply: don't restore a backup from the period when the app may have been installed (it can return from the backup), and change all account passwords immediately after the reset — otherwise the person who was watching may regain access to your accounts.
What if the surveillance is connected to domestic violence?
Your safety is the priority. Don't take technical action — deleting the app, changing settings — from the compromised device while you're still in an unsafe situation. Seek help from a trusted device. Safety first, evidence second.
