How to Avoid Fake APKs and Phishing Pages
Red flags for fake game app downloads and phishing pages that impersonate real offers, and what to do if you spot one.
View →General mobile-safety checks to run before installing any app from outside an official app store, including game apps.
Installing an app from outside an official app store — sometimes necessary for games not listed there — carries more risk than an app-store install, since you skip the store’s own review process. This guide covers general checks worth running first, for any app, not just games.
Only download from a link on the official destination page you arrived at intentionally — not from a link in an unsolicited message, comment, or pop-up. If in doubt, navigate to the destination independently rather than clicking a forwarded link.
Look closely at the web address before downloading anything. Scam pages often use a domain that looks almost right — an extra word, a swapped letter, or a different top-level domain (.top instead of .com, for example) than the one you expect.
A legitimate Android app installer is typically an .apk file of a plausible size for the app it claims to be. A file that’s unexpectedly tiny (a few hundred KB) for a full game, or has an unusual extension, is a warning sign.
Android shows a permissions summary during installation. Be cautious of a simple card or multiplier game requesting access to contacts, SMS, call logs, or device admin rights — those are not typically needed for this type of app. See our Android permissions guide for what’s reasonable.
If your device has Google Play Protect or another on-device scanner, keep it enabled — it can flag known-bad files even for apps installed outside the Play Store.
Countdown timers, “limited slots,” or messages pushing you to install “right now” are pressure tactics, not verification signals. A genuine offer will still be there after you’ve taken a minute to check it.
Stop the install and do not proceed. Uninstall immediately if you already installed something and now have doubts. See our guide on avoiding fake APKs and phishing pages for more specific red flags.
It carries more risk than an app-store install, since the store's own review process is skipped. The checks in this guide reduce — but do not eliminate — that risk.
Only use links published on the official destination page you were sent to from a trusted starting point, check the domain carefully, and avoid links from unsolicited messages. See our phishing guide for more detail.