EFF teamed up with AV Comparatives to see how well anti-virus apps detect stalkerware on Android phones.

https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps

@evacide so... one would install malware (which AV software has been for a while now) to fight Stalkerware? 
@evacide sadly no row with just windows defender for comparison though.
@agowa338 @evacide Is there a Windows Defender for Android now?😮
Microsoft Defender: Antivirus - Apps on Google Play

Antivirus and malware protection. Online security for all of your devices.

@evacide oh my god, there are people who think google would attempt to PREVENT stalking?

I mean, I suppose maybe a little, from an anti-competition standpoint, but

@evacide

JFC Google get your shit together.

@evacide
Google worst at 53% yet they insist that registration & signing of ALL Android Developers and no unsigned app install is for safety. Also that their Playstore is safe?
Google is about control & spying, not safety. I'm amazed how well McAfee did.
evacide (@[email protected])

@tehstu As I point out in the blog post that I linked to, this is because several of the stalkerware apps include instructions to disable Google Play Protect as part of the installation process.

Hachyderm.io
@evacide malwarebytes requires Google Play Services
@evacide what's the vector for this kind of malware? Is all of it side loaded or is some coming from the Play Store?
@Spirit It is all side-loaded, as described in the paper.
@evacide nice work! Very interesting and thorough article. In the prevention appendix, it mentions "running a trusted security solution." Was it evaluated how effective these apps were at blocking installation or not being workedaround? My gut feeling would be that a strong pin/pw/bio would be the most effective method to mitigate that vector. Thanks!
@dacmot It is extremely common for people in abusive relationships to be coerced into giving their partners the pin or password to their phones.
@evacide ah, right. Not an easy situation to prevent or get out of.
@evacide I have one more question if you don't mind. Do security focused custom Android like GrapheneOS offer additional protection against stalkerware compared to stock from Samsung, Google, and others?
@dacmot I haven't tried to test stalkerware on GrapheneOS, but this is not the threat model that GrapheneOS was built for.
@dacmot @evacide The relatively low noise level of the sort of graphene setups that people who install graphene would typically use would probably help a forensic analyst tell that something isn't right, just because the stalkerware needs to phone home sooner or later; but Graphene definitely assumes that you are the admin of your phone and mostly concerned about feds that might cellebrite you; but are supposed to keep it within 8th amendment rules. Almost the opposite threat model.

@dacmot @evacide One can create non-owner profiles for daily usage and then disable installation of apps in that profile. This reliably stops attackers with brief access to an unlocked profile without additional exploits.

This mixes well with the relatively recent addition of two-factor fingerprint screen unlocking, where the main password can be a long, high-entropy password, but still having a shorter, more convenient PIN plus fingerprint.

As well as the earlier feature of being able to install apps from the owner profile inside other profiles (need to briefly enable app installation for that profile, then disable it again afterwards).

@evacide
Nice. Interesting in so many ways.
@evacide Im not going to lie malwarebytes free version saved my ass so many times when I worked for a Windows server hosting company.
@evacide Google SaaS - Stalkerware as a Service

@evacide

I am not surprised that Malwarebytes did well.

@evacide This might be naive, are any free software?

I confess I have only read the web blog, not the PDF

@evacide
I don't know if this is simply my poor opinion of AV companies or what, but the results of some of these companies are surprisingly good.