Before you install: Open the download page from a domain you have already verified. On Android, leave Google Play Protect on and review every permission request. A file forwarded in chat is not a safe installation source.
Check the source
- Start from the platform's current verified domain, not a shortened or forwarded link.
- Compare the domain character by character. Watch for extra hyphens, letters or unfamiliar endings.
- Confirm the page uses HTTPS, while remembering that HTTPS alone does not prove ownership or safety.
- Do not trust a file only because the icon or name looks familiar.
Review permissions
| Permission | Question to ask |
|---|---|
| SMS or notifications | Is this needed for login messages, and can it expose OTP content? |
| Contacts | Why would the app need your address book? |
| Accessibility or screen control | Could this let the app read or control other apps? |
| Storage or photos | Is the request limited to uploading a file you selected? |
Updates and broken access
If an old app stops working, do not search random APK mirrors. Return to the current official domain, confirm whether a new version exists and keep your recovery details available before replacing the app.
If you already installed a suspicious file
- Stop using the app if the phone behaves unexpectedly.
- Check accessibility and device-admin settings before removing the app.
- Change important passwords from a different trusted device.
- Contact the wallet or bank through its own app or official website if financial information may have been exposed.
Sources checked
Google explains that Play Protect checks apps from Google Play and other sources and can warn about harmful apps. The Philippine National Privacy Commission also warns that SMS links can lead to convincing fake sites or malware. These sources support the device-safety steps above; they do not verify any specific APK.