Contents
Part of the safety hub: Are APK Files Safe? · Pair with trusted download sources.
Why Scan Before You Install
Once installed and granted permissions, a malicious APK can read messages, overlay banking screens, or persist through reboots. Scanning the file first costs thirty seconds and catches most commodity malware and repacks.
Scan With Google Play Protect
- Play Store → profile → Play Protect → enable scanning and harmful-app detection.
- Open your downloaded APK: Play Protect evaluates it pre-install automatically.
- After install, it keeps scanning periodically.
- Limitation: strongest on known families — pair with a second opinion below.
Scan With VirusTotal (Upload the File)
- Go to virustotal.com → upload the
.apk. - Read the ratio: 0–2 low-reputation flags on a mod can be heuristics; 5+ detections across major vendors means delete it.
- Check Details: package name, signature, and permissions should match the official app.
- Re-scan after updates — each version is a new file with a new verdict.
Warning Signs an APK Might Be Malicious
- Multiple VirusTotal detections from major vendors.
- Package name differs slightly from the official app.
- Signature does not match the developer’s certificate.
- File size far off the official release of the same version.
- Password-locked archives or “disable antivirus” instructions.
- Permissions wildly beyond the app’s function (permission red flags).
Key Takeaways
- Scan the file before the installer ever runs.
- Play Protect for on-device checks, VirusTotal for 60+ engine verdicts.
- Multiple major-vendor detections mean delete it.
Frequently Asked Questions
Is VirusTotal free?
Yes for casual use — upload files and get results from 60+ antivirus engines free, no account needed.
What if my antivirus flags a false positive on a modded app?
Treat every detection as guilty until proven innocent. Only proceed if the hash matches a source you independently trust — otherwise delete it.