Quick answer: You can usually spot a fake app before you install it by checking five things: the developer’s name (it should match the real company exactly), the download and review count (real popular apps have millions, not hundreds), the review quality (fakes have bursts of generic five-star reviews and angry one-stars), the listing text and screenshots (typos and blurry logos are red flags), and the permissions it requests. When in doubt, go to the company’s official website and tap their app link — that always lands you on the real one.
Fake and copycat apps slip past the official stores more often than people realize. Some are harmless knockoffs; others are built to steal logins, drain your wallet with hidden subscriptions, or quietly spy on you. At InFurpose, we think the smartest habit is a 30-second check before you tap “Install,” because once a malicious app is on your phone, cleaning up is a lot harder than avoiding it. Here’s exactly what to look at.
Written by Samuel Smith — consumer-technology writer and digital-privacy researcher at InFurpose.
1. Check the developer name — this is the biggest tell
From experience: A friend of mine downloaded what they thought was the right app, but it had a blank-looking icon and started asking for permissions that made no sense for what it was supposed to do. I helped them find it in the phone’s app settings, uninstall it, and run a security scan afterward. Since then I tell people to check the developer name, download count, recent reviews, and permissions before installing anything.

The fastest way to catch a fake is to look at who publishes it. Right under the app title you’ll see the developer or company name. For a real app, it matches the company exactly — “Instagram” is published by Instagram/Meta, not “Insta Gram Studios” or “App Dev Team 2024.” Scammers rely on you not checking this. If the developer name looks slightly off, is a random string, or publishes dozens of unrelated apps, back out.
2. Look at download numbers and age
Hugely popular apps have enormous download counts — a real banking or social app has millions or tens of millions of installs. A “PayPal” clone with 5,000 downloads is a fake. On Google Play, the install count is shown directly; on the App Store, a very low ratings count is the equivalent signal. Also check the release or “updated” date: a brand-new listing impersonating a famous, long-established app is a warning sign.
3. Read the reviews critically
Fakes often have a telltale review pattern: a cluster of short, generic five-star reviews (“Great app!!”) posted around the same time, mixed with furious one-star reviews from people who got scammed (“this stole my money,” “asked for my password”). Real apps have a natural spread of detailed feedback over time. Sort by most recent and most critical — the one-star reviews frequently call out exactly what the fake is doing.
4. Inspect the listing: logos, screenshots, and description
Scammers rush their listings. Watch for a blurry or slightly-wrong logo, screenshots that look pixelated or mismatched, broken English, spelling and grammar mistakes, and vague descriptions that never quite explain what the app does. Legitimate companies invest in clean, consistent branding. Anything sloppy in the store listing is a sign of a sloppy — and possibly malicious — developer.
5. Scrutinize the permissions it asks for
Before and after installing, check what the app wants access to. A flashlight or wallpaper app has no business requesting your contacts, messages, microphone, accessibility services, or location. Permission overreach is a classic malware signature. On iPhone, review permissions in Settings → Privacy & Security; on Android, Settings → Apps → the app → Permissions. Our full Android privacy settings guide walks through locking these down. If an app demands “Accessibility” or “Device admin” access without a clear reason, that’s a major red flag — those permissions can let an app control your screen.
The safest way to find the real app
When you’re unsure, don’t search the store and guess. Go to the company’s official website and tap their “Download on the App Store” or “Get it on Google Play” button — it links directly to the genuine listing. And stick to the official stores: sideloading apps from random websites or third-party stores strips away the (imperfect but real) vetting Apple and Google provide.
When fake apps are actually spyware
Some of the most dangerous fakes disguise themselves as ordinary tools — a “system update,” a battery saver, or a calendar — while secretly monitoring the phone. This overlaps with stalkerware, apps installed to track someone without their consent, often by an abusive partner or family member. If you suspect an app was installed on your phone by someone else to watch you, trust your instincts and get help from people trained in this: the National Domestic Violence Hotline (1-800-799-7233, or text START to 88788) and the National Network to End Domestic Violence (NNEDV) and its Safety Net project offer guidance on checking a device safely, because in some situations removing a tracking app can alert the person who installed it. Make a safety plan first if you’re in danger.
What to do if you already installed a fake app
- Delete it immediately — uninstall from your home screen or app settings.
- Change passwords for anything you logged into through the app, starting with email and banking.
- Check subscriptions and charges in your App Store/Google Play account and your bank, and cancel anything you don’t recognize.
- Run a security scan and review app permissions for anything else that looks off.
- Report the fake to Apple or Google so they can pull it and protect others.
The bottom line
Spotting a fake app comes down to a quick pre-install check: verify the developer name, sanity-check downloads and reviews, look for sloppy branding, and question any app asking for permissions it doesn’t need. When unsure, reach the real app through the company’s official website. That 30-second habit stops the vast majority of fake-app scams before they start.
Frequently asked questions
Are apps in the official App Store and Google Play always safe?
No. Apple and Google vet apps, but fakes and malicious apps still slip through, especially copycats of popular brands. The official stores are far safer than third-party sources, but you should still check the developer name, reviews, and permissions before installing.
What is the quickest way to tell if an app is fake?
Check the developer name under the app title — it should exactly match the real company. Combine that with the download count (real popular apps have millions) and the review pattern. If the developer looks off or the numbers are tiny for a “famous” app, it’s almost certainly fake.
Can a fake app steal my information even if I don’t log in?
Potentially, yes. Some fake apps request excessive permissions — contacts, messages, microphone, or accessibility access — and can harvest data or display scam prompts without a login. That’s why reviewing permissions and deleting anything suspicious matters even if you never entered a password.
Is it safe to download apps from outside the official store?
It’s riskier. Sideloading from random websites or third-party stores skips the official vetting and is a common way malware spreads. Stick to the App Store and Google Play, and reach the genuine listing through the company’s official website when in doubt.
How do I check an app’s permissions after installing it?
On iPhone, open Settings → Privacy & Security to see which apps have access to things like your location, microphone, and contacts. On Android, go to Settings → Apps → the app → Permissions. Revoke anything an app doesn’t genuinely need to function.
What should I do if a fake app charged me money?
Cancel the subscription in your App Store or Google Play account, then contact the store to dispute the charge — both have refund request processes. Also watch your bank statement for further charges and report the app so it gets removed. Change any passwords you entered into it.
For more ways to keep your phone clean and private, explore InFurpose’s guides, including our Android privacy settings guide and our plain-English explainer on stalkerware.
Samuel Smith is a consumer-technology writer and digital-privacy researcher at InFurpose who has spent years testing phone-security tools and spotting fake and malicious apps before they reach a phone.