Spyware and Ransomware: When Someone Spies On or Locks Your Device
Updated 2026-08-20
Spyware and ransomware are two different kinds of malicious software (malware) that end up on a phone or computer the same ways, but do very different damage once they're there.
Spyware secretly monitors what you do: your messages, calls, location, photos, even your camera or microphone, sending that information to whoever installed it, often without you ever knowing it's there.
Ransomware locks your files or entire device and demands payment (a "ransom") to unlock them, usually with a countdown or threat to delete everything if you don't pay in time.
How they usually get onto a device
- Fake or modified apps installed from outside the official Play Store/App Store, or "cracked" paid apps offered for free.
- Links in phishing messages that download malware instead of showing the page you expected. See the Phishing guide for how these links are disguised.
- Malicious attachments in email or WhatsApp, especially files ending in
.apk,.exe, or ones asking you to "enable" something unusual to open them. - Someone with physical access to your phone installing hidden spyware directly, sometimes disguised as a "parental" or "monitoring" app. This is a common tactic in abusive relationships.
- Fake software updates or pop-ups claiming your phone needs an urgent security update, that actually install malware instead.
Warning signs your device may be infected
- Battery draining much faster than usual, or the device running hot when idle.
- Data usage spiking without an obvious reason.
- Unfamiliar apps you don't remember installing.
- The device becoming noticeably slower, or apps crashing more than usual.
- Pop-ups, ads, or unexpected messages appearing on their own.
- For ransomware specifically: files suddenly unreadable, renamed with strange extensions, or a message demanding payment to unlock your device.
How to protect yourself
- Only install apps from the official Play Store or App Store. Avoid "APK" files shared directly through WhatsApp or unofficial websites.
- Check app permissions before installing. A simple flashlight or game app has no legitimate reason to request access to your contacts, messages, or camera.
- Keep your phone's operating system and apps updated. Updates often patch the exact weaknesses malware relies on.
- Don't open attachments or click links from unexpected messages, even ones that appear to come from someone you know. Their account may itself be compromised.
- Back up important files regularly to a place not permanently connected to your device (cloud storage, or a drive you disconnect afterward). This is the single best protection against ransomware, since you can restore your files without paying anyone.
- Set a strong screen lock (PIN, pattern, or fingerprint) so no one can quietly install anything if they get brief physical access to your phone.
If you think you're infected
- Disconnect the device from the internet (turn off Wi-Fi and mobile data) to stop data from being sent out or spreading further.
- Do not pay a ransomware demand. Payment doesn't guarantee your files are returned, and it funds further attacks.
- Back up any files you can still access, then have a trusted technician remove the malware, or factory-reset the device as a last resort once your data is safely backed up elsewhere.
- Change your important passwords from a separate, clean device, since spyware may have already captured what you typed.
- Report the incident to the Uganda Police Cyber Crime Unit, particularly if spyware was installed by someone you know without your consent. This can be a form of harassment or abuse, not just a technical problem.