Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Check an app before trusting it with your device

Separate the source of the app, the permissions it requests and the person directing you to install it.

Mobile device and banking app usersAbout 6 minutes of reading + 3 questions
Start with the example Already installed it or granted access?

What you will learn

  • Check who published an app and where it came from.
  • Recognise a risky permission or remote-access request.
  • Respond if an unknown person has already accessed the device.

Practice example

“Support” wants you to install an app

Unexpected call

Unexpected call

Install this screen-sharing app. Then open mobile banking so we can stop a suspicious payment together.
Fictional situation for practice.
Show the example explanation
The caller directs the installation
Do not install an app because an unverified person tells you to.
Screen viewing or control is requested
This access can expose information and permit actions on the device.
Banking is opened during the session
Do not sign in while another person can view or control the device.

How does an app become a risk?

A fake app can copy the name and appearance of a bank, delivery firm or familiar service. Another scenario uses a genuine remote-support app: the risk is not necessarily the software itself, but granting an unknown person the ability to view or control your device.

Pause when someone guides you through an installation, accessibility settings, screen sharing or a mobile-banking sign-in during a call.

Four checks before installation

  1. Find the app through the bank or service provider’s official site and use an authorised app store.
  2. Check the exact publisher name, update history and whether the official site links to that app.
  3. Compare permissions with purpose. A calculator does not need contacts, text messages or accessibility control.
  4. Do not rely only on download counts, ratings or a logo. They are signals, not guarantees.

Permissions that deserve extra care

Access to text messages, notifications, microphone, camera, contacts, installing other apps, drawing over apps or accessibility functions should have a clear reason. Reject a request that is not needed for the feature you use.

Do not approve screen sharing or control for someone whose identity you have not verified independently. Never enter a banking PIN, password or code while such a session is active.

If you installed it or granted access

  1. End the call and disconnect the device from the network if remote access is active.
  2. If you opened banking, exposed card information or approved a payment, call the bank immediately using its official number.
  3. From another trusted device, change exposed passwords and end unknown sessions. Start with email if it recovers other accounts.
  4. For a work device, notify IT or security and do not erase evidence yourself. For a personal device, follow the device recovery steps; uninstalling alone does not prove the device is clean.
  5. Preserve the app name, link, caller number, time and screenshots you already have. Do not reopen the suspicious link for evidence.

Check your knowledge · 3 of 5

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript. Without JavaScript, the full bank of 5 questions is shown.

An app is in an official store and has many ratings. Is it fully verified?

Why does this matter? Store controls and ratings help, but cannot guarantee every app is safe or genuine.

  1. Yes, no other check is needed.

    Store review reduces risk but does not detect every problem.

  2. No; I check the publisher, official link, permissions and purpose.Correct answer

    Several independent signals reduce the chance of installing an imitation.

  3. Yes, if the icon matches the brand.

    Names and icons can be copied.

Unknown 'support' asks to see your screen while you open banking. What do you do?

Why does this matter? Screen viewing or control can expose sensitive information and affect what you approve.

  1. End the call and verify the issue directly with the bank.Correct answer

    Independent bank contact removes the unknown person from the process.

  2. Continue but cover the PIN with my hand.

    Screen sharing may expose much more than the PIN.

  3. Allow access for only five minutes.

    A short session can still be enough for misuse.

You granted remote access and signed in to mobile banking. What is the priority?

Why does this matter? Financial access may have been exposed and needs urgent bank assessment while further control is stopped.

  1. Only delete the app icon.

    Removing an icon does not prove access is gone or protect the bank account.

  2. Wait for the phone to show a warning.

    No warning does not mean the device or session is safe.

  3. Disconnect and contact the bank immediately using another trusted device or phone.Correct answer

    This stops further access and lets the bank assess the account.

A message supposedly from your bank asks you to install an APK outside the app store. What do you do?

Why does this matter? Installing from a message bypasses the normal route to the app and may deliver an imitation.

  1. Install it because the file uses the bank's name.

    A filename is easy to change and does not verify the publisher.

  2. Open the official store or bank website independently of the message.Correct answer

    An independent route lets you locate and verify the official app.

  3. Forward the file to somebody else to test.

    Forwarding may expose another person.

A flashlight app requests SMS and accessibility access. What do you do?

Why does this matter? Those permissions do not fit the basic function and may expose codes or enable interface control.

  1. Deny them and remove the app if it cannot justify them.Correct answer

    Permissions should have a clear relationship to the app's function.

  2. Approve them because the app is free.

    Price does not establish safety or a need for access.

  3. Approve them only while using mobile banking.

    Granting access during banking increases rather than reduces the risk.

No registration. Your answers are not sent; the result is just for you.

Check the source, publisher and permissions

An official store reduces risk but is not a guarantee. Never grant remote access at an unexpected caller's request.

Recover an infected device

References

Sources and further reading

Guidance follows the Serbian National CERT publication on safe use of mobile applications. It notes that authorised stores reduce risk but do not guarantee an app is harmless.

Content last reviewed