Identify exactly what you are installing
Before checking whether software is safe, establish what the software is supposed to be.
An application can look familiar and still be unsafe. Before installing an app, APK, desktop program, browser extension, update or remote-access tool, verify where it came from, who published it, why you need it and what access it requests. Do not let a message, logo or urgent warning make the installation decision for you.
Your phone or computer may provide access to email, banking, payments, messaging, cloud storage, identity information and recovery methods. Software that is unsafe, unnecessary or given excessive permissions can create a path into those resources.
The goal is not to distrust every application. The goal is to verify important software before giving it access.
These checks apply to mobile apps, APKs, desktop programs, browser extensions, updates, plugins and remote-access tools.
Before checking whether software is safe, establish what the software is supposed to be.
Where you obtained the software is one of the first things to check.
A copied name, logo or familiar-looking screen does not establish who made the software.
A legitimate application should have a clear reason for existing and a clear reason for you to use it.
An application should not receive sensitive access merely because the installation screen asks for it.
Unexpected installation requests deserve more scrutiny than software you deliberately sought out.
A request to bypass a security control changes the risk of the installation.
Start with software that can access money, identity information, communications, authentication or powerful device functions.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
Ask who published it, where you got it, why you need it and what access it will receive before proceeding.
The most dangerous installation decisions often happen when a person is rushed, frightened, offered a reward or given a convincing explanation.
A message says your bank has released a security update and attaches an APK. Do not install it because the message uses the bank's logo. Open the bank's official website or official app-store listing yourself and check whether the update exists and how the bank distributes it.
A recruiter says you must install an APK before an interview. Verify the employer and recruitment process independently. Check the employer's official website for the vacancy and confirm whether the test or application is actually part of the process. An attractive job opportunity does not justify bypassing normal software checks.
A pop-up says your phone is infected and tells you to install an urgent security application. Do not let the warning make the decision for you. Close the prompt if appropriate and check the device's official security and update settings yourself.
A simple utility asks for access to messages, contacts, microphone, files and accessibility features. The permissions do not automatically prove the app is malicious, but the mismatch is a reason to pause. Check the publisher and purpose and do not grant access that you cannot justify.
An unexpected caller says they are from your bank and need remote access to fix your account. Do not install the software or grant remote control. End the interaction and contact the bank through an official channel you find independently.
A message says you must install an application to receive a government grant or intervention payment. Do not treat government branding as proof. Find the relevant government organisation's official website and verify the programme and application process there.
A delivery message says an application is required to release a package. Instead of using the supplied link, find the delivery company through its official website and confirm whether the application exists and whether the message is genuine.
A website offers a modified version of paid software for free. The promise of unlocked features is not evidence of safety. Use the legitimate publisher or an authorised distribution channel instead of installing a modified copy.
After installing an unexpected APK, you notice unusual permissions, pop-ups or account activity. Do not assume uninstalling it alone has solved the problem. Stop interacting with it, preserve useful evidence, review affected accounts and sessions, secure exposed credentials and use official recovery procedures.
Permission requests should be evaluated against the application's actual purpose.
Ask whether the app genuinely needs to read messages or notifications. Be especially cautious when the application is unrelated to communication or authentication.
Consider whether the application's function requires access to your contacts, photos or documents. If not, do not grant broad access simply to make installation easier.
Some applications genuinely need these capabilities. Check whether the requested access matches the feature you intend to use and whether it can be limited while the app is not in use.
Accessibility features can provide powerful interaction with a device. Legitimate accessibility tools may need them, but an unrelated app asking for this access deserves careful verification before approval.
Remote-access software can be legitimate, but unexpected requests to grant remote control should be independently verified before installation or use.
Treat requests to disable warnings, antivirus protection or other security controls as a reason to pause and verify the software's purpose through an official source.
1. WHO? Who developed or published the software?
2. WHERE? Where did I get it?
3. WHY? Why do I need it?
4. WHAT? What access does it request?
5. EXPECTED? Did I actually initiate this installation?
6. INDEPENDENT? Can I confirm it through the organisation's official website, official app store or another trusted channel?
7. SAFE TO PROCEED? Do the source, purpose, publisher and permissions support installation?
If important answers are unclear, stop. Do not let urgency make the decision for you.
Do not keep using suspicious software while you investigate it, and do not assume that uninstalling it automatically reverses everything it may have accessed.
Do not enter passwords, OTPs, recovery codes, banking details or other secrets into suspicious software.
Keep relevant messages, file names, screenshots and account alerts where appropriate before making changes that could destroy useful evidence.
Check what access the application received and remove unnecessary access through trusted device settings where appropriate.
Review banking, email, messaging and other important accounts for unusual activity and unfamiliar sessions.
Change credentials that may have been exposed and use official recovery and security controls rather than instructions from the suspicious software or its sender.
Keep checking affected accounts and the device after the immediate response. Some consequences may not appear immediately.
Someone may claim they can help remove the suspicious application and then ask for your password, verification code, recovery phrase, payment or remote access.
Verify the supposed helper separately. Open the relevant organisation's official website or app yourself, use a phone number you already trust, or use another independently published contact channel.
The person offering help is not the proof. The independently verified channel is what you use to establish whether the help is genuine.
Logos, names and screenshots can be copied. Verify the publisher and source.
A trusted person can unknowingly forward a malicious file, and a compromised account can send messages that look familiar.
Check for the update through the device, official app store or application's official update mechanism.
A job, grant, payment or delivery deadline does not prove that the supplied application is legitimate.
Permission requests should make sense for the application's purpose. Unnecessary access should not be granted automatically.
If compromise is possible, review permissions, sessions, credentials and affected accounts as well.
Do not install simply because someone says you must act now.
Know the exact application, publisher and purpose.
Find the official or independently verified distribution channel.
Compare developer details with the legitimate organisation.
Verify why the software is needed and whether the request is genuine.
Check permissions and security settings before granting access.
Proceed only when the evidence supports the installation.
After installation, review permissions and remove software you no longer need.
A safe installation decision is not based on how professional the app looks. It is based on evidence you can verify independently.
The goal is simple: know what you are installing before you give it access to your device, accounts, information or money.
Verify the source, publisher, purpose and permissions before giving software access to your device.
VERIFY BEFORE YOU TRUST.