Installing an APK? Seven checks before you tap Install
Plenty of legitimate apps are shared as APK files in India. These checks help you tell a real one from a fake, and explain why Android sometimes blocks the install.

Downloading an app as an APK file, rather than from the Play Store, is common in India. Some companies distribute their apps that way, some apps are not listed in the Play Store, and some people simply receive a file from a friend. The problem is that fraudsters use exactly the same route.
Google's own analysis found that more than 95% of installs of major fraud malware families came from apps downloaded straight from the internet. That is why Android is getting stricter about sideloading. Here is how to protect yourself.
1. Get the file from the source, not a forward
The safest APK is the one you download from the company's official website, typed into the browser yourself. Treat any APK that arrives on WhatsApp, Telegram or SMS as suspect, even from someone you know. Their phone may already be infected, and forwarding the file is often what the malware does next.
2. Check the website address carefully
Fake sites copy logos easily but not domains. Look for small changes: an extra letter, a hyphen, a different ending such as .top or .xyz in place of the real one. If you found the site through an advertisement or a message rather than a search, double-check it.
3. Compare the version and size
A real app's website usually states the latest version number and roughly how large the file is. If the page says 35 MB and your download is 3 MB, something is wrong. After installing, you can see the version under Settings › Apps › [app name].
4. Read the permissions before you agree
Ask whether each permission makes sense for what the app does. A game does not need to read your SMS. A torch app does not need your contacts. Be especially wary of these:
- Read or receive SMS: can capture one-time passwords from your bank.
- Notification access: can read OTPs and messages as they arrive.
- Accessibility service: can see your screen and tap buttons for you. It exists for people with disabilities and is the favourite tool of banking malware.
These are the same permissions Google targets in India (see point 7).
5. Let Play Protect scan it
Play Protect is built into Android phones that have the Play Store. Open the Play Store, tap your profile picture, then Play Protect, and make sure scanning is turned on. When you install an APK, it is checked automatically. If Play Protect warns you, do not tap "Install anyway" unless you are certain where the file came from.
6. Switch "Install unknown apps" off again
Android asks you to allow a specific app, such as Chrome or your file manager, to install other apps. After you have installed what you needed, go back to Settings › Apps › Special app access › Install unknown apps and switch that permission off again. The exact menu names differ a little between phone brands.
7. Understand why some installs are blocked
Since late 2024, Google has run an "enhanced fraud protection" pilot in India. When you try to install an app downloaded directly from the internet, Play Protect checks which permissions it asks for. If it requests SMS access, notification listening or accessibility, all commonly abused to steal OTPs, the install can be blocked automatically. Apps from the Play Store and other app stores are not affected.
Google is also rolling out developer verification, which will require apps installed on certified Android phones to come from a developer whose identity Google has checked. It becomes mandatory first in Brazil, Indonesia, Singapore and Thailand from September 2026, with more countries following in 2027. India's date has not been announced.
If you already installed something suspicious
Turn on flight mode, uninstall the app from Settings › Apps, run a Play Protect scan and change the passwords and UPI PIN of any banking app you used since. If money has left your account, call 1930, India's cybercrime helpline, and your bank straight away.
