Most of the threats we write about involve a stranger, a distant attacker, a malicious website, a nation-state exploit. This one is different, and harder, because the person installing it is usually someone you know. A partner. An ex. A family member. An employer. Stalkerware is surveillance software installed by someone close enough to hold your phone for a minute, and that intimacy is exactly what makes it so damaging.
A brief, important note before anything else: if you think a device is being monitored and you are in a situation involving an abusive partner, be careful. Removing the software can alert the person watching and escalate the danger. It is worth reading to the end for the safer approach and the resources that exist to help. If you are in immediate danger, contact a domestic-violence hotline or local emergency services first.
What stalkerware actually is
Stalkerware is a real, profitable industry, sometimes called stalkerware-as-a-service. For thirty to seventy dollars a month, anyone can buy a subscription, with customer support and affiliate programs, that hands them a web dashboard showing another person’s messages, location, call logs, photos, browsing, and keystrokes in near real time. The apps market themselves with euphemisms, “parental control,” “employee monitoring,” “phone tracking”, but research from the Coalition Against Stalkerware finds the overwhelming majority of installations are used for intimate-partner surveillance. One security vendor detected it on more than 31,000 devices in a single year, counting only its own customers, so the real figure is far higher.
It is also, mostly, legal, sold openly by companies based in jurisdictions with weak privacy laws. The person who installs it on your phone is the one committing the wrong, but the tools themselves sit in a gray market that keeps them cheap and available.
How it gets on your phone
There are two doors, and neither is the movie-hacker kind.
The first is physical access. “Hey, can I see your phone for a second.” Someone who can get your unlocked device in their hands for a few minutes installs the app, hides its icon, and hands it back. That is the whole attack. It requires knowing your PIN or catching the phone unlocked, which is precisely why it is almost always someone close to you rather than a remote intruder. And to be clear, because the industry likes to blur this: needing to unlock your phone to install monitoring on it is not your consent. The Coalition Against Stalkerware says so explicitly.
The second door is more unsettling, and it is the one you should sit with. You install it yourself, because someone you trust recommended it. A partner suggests a “couples location app,” a “family safety tool,” a shared account that is really a surveillance account. The software does exactly what it was sold to do, and you invited it in, because the person asking was someone you had no reason to doubt. This is the quiet reason “only install what you actually chose, from a source you trust” is a genuine security rule and not paranoia. Any app another person pushes onto your device could be monitoring in disguise.
It is not always an app
Stalking through technology is broader than installed spyware, and it helps to know the other shapes it takes.
Before phones routinely randomized their wireless identifiers, anyone with inexpensive gear could track a device by its MAC address, the unique identifier it broadcast over WiFi and Bluetooth, logging when “your” device arrived somewhere and when it left. That let a stalker map your comings and goings without ever touching your phone. Modern hardened phones randomize those identifiers by default, which kills the casual version of this, though a determined and well-funded stalker can still make it harder for you. It is a real reason MAC randomization matters, not a technicality.
The modern physical-tracking tool is the Bluetooth tracker, an AirTag or a Tile slipped into a bag, a coat lining, or a car. If you suspect one, the built-in unwanted-tracker alerts on modern phones and a simple Bluetooth scanner app can help you find it.
How to tell, and how to act safely
Common signs of stalkerware are a phone that runs hot when idle, drains its battery unusually fast, or shows unexplained data usage. On Android, it typically hides by abusing two powerful permissions, Accessibility Services and device administrator access, and by removing its own icon, so those permission lists are where to look. No single scanner catches everything; an EFF-backed test in 2025 found the built-in Play Protect detected only about half of known stalkerware, so a clean scan does not fully clear a device.
Here is the part that matters most, and it is about safety, not technology. If you suspect an abusive person installed it, do not simply delete it. Removal can tip them off that you are aware, and in domestic-violence situations that can escalate the danger, research links this software to real physical harm. The safer path is to plan first. The Coalition Against Stalkerware at stopstalkerware.org, the Electronic Frontier Foundation, and domestic-violence support organizations offer guidance built for exactly this situation, and if evidence may matter legally, a professional digital-forensics examination both finds custom stalkerware that scanners miss and preserves proof. Get support in place before you change anything on the device.
How a hardened phone raises the bar
A secure phone cannot undo a relationship where someone has your PIN and your trust, and we will not pretend otherwise. What it can do is make every version of this attack harder.
It makes casual installation harder. Controlled, curated app installation rather than a phone that will sideload anything handed to it means fewer easy ways to drop in a monitoring app. Verified boot means system-level tampering is detected rather than silent. And on a hardened OS you can actually see and control the Accessibility and device-administrator permissions that stalkerware depends on, so an app quietly grabbing that level of access stands out instead of hiding.
It makes tracking harder. MAC randomization by default defeats the comings-and-goings tracking, and the minimal footprint means less telemetry leaking your movements in the first place.
It lets you compartmentalize. With separate profiles, if someone insists you install a “shared” app, you can wall it off in its own profile where it cannot see your real life, and keep a normal-looking profile separate from a private one.
And it sharpens the one defense that actually decides these cases: physical control. Guard your PIN. Do not hand over an unlocked phone. Be deliberate about what you install and who asked you to. And think carefully about biometrics, because a face or a fingerprint can be used on your phone by someone sitting next to you far more easily than a passcode you keep in your head, a point we made about coerced unlocks and it applies just as much here.
The uncomfortable takeaway
The most dangerous surveillance on a phone often is not malware at all. It is a normal, legal app, installed by someone you trusted, doing precisely what it was designed to do, aimed at you. You cannot patch your way out of that, and no antivirus fully addresses it, because the vulnerability being exploited is the relationship.
Which is why the real defense is control of your own device: your PIN, your installs, your profiles, your hardware. A phone that you genuinely control is one that the people closest to you cannot quietly turn against you. That is a large part of what we build, and why.
If you want a device set up to resist this, or help thinking through a situation, email hello@spicycorp.com, or book a call. And if you are dealing with an abusive situation right now, please start with stopstalkerware.org or a domestic-violence hotline, your safety comes before your phone.
SovereignOS is a hardened, de-Googled phone, set up the way we would build one we had to rely on ourselves. One-time price, no subscription, no account required.
See SovereignOSRecent Posts
- Your Phone, Laptop, and TV Are One Profile. Here’s How They Got Linked.
- Your Advertising ID Is a Tracking Number. Here’s How to Actually Kill It.
- Surveillance Capitalism in Plain English (You’re Not the Product, Your Future Is)
- Does iPhone Lockdown Mode Actually Work? (Yes, and Here’s Where It Stops.)
- Your Data Just Leaked. Here’s the First 48 Hours.
Recent Comments
Post Widget
Why Your VPN Isn’t Hiding Your IMEI
Should You Trust Signal?
Social Media Widget
Customer service
Real people, ready to help. Reach our team anytime at hello@spicycorp.com.
Fast Free Shipping
Get free shipping on orders of $150 or more (within the US)
Returns & Exchanges
We offer free returns and exchanges within 30 days of purchase.