44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi
44.5 Cleanup and Response – If You Believe the Phone Is Compromised
Order matters (defence playbook):
- From a different clean device (laptop / other phone you trust): change Google / Apple ID / email / bank passwords; enable MFA
- Revoke sessions / app passwords / "logged-in devices" on those accounts
- Contact bank if UPI / cards involved; watch SMS OTP traffic; follow bank fraud process
- On the suspect phone (if still usable): disconnect Wi-Fi / mobile data; note unknown apps / profiles
- Company phone → tell IT / MDM admin before you wipe (Sahyadri policy)
- Factory reset as a strong last step after account hygiene – then reinstall only from stores; restore from a backup made before infection if possible, else clean setup
- India awareness: CERT-In / cybercrime.gov.in / helpline 1930 themes for fraud (verify current portals); do not post OTP in "recovery" Telegram groups
Never: install random "antivirus cleaner.apk" from a forward; never send the phone to a stranger "unlocker".
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Keeps cloud session after phone wipe | Password + revoke sessions from clean device first |
| Re-infects via poisoned backup / same APK | Clean setup; no sideload; new backup after hardening |
| Social-engineers "bank officer" OTP | Staff never share OTP; official channels only |
Ravindra Bagale's Tip
Wipe pehle password change – nahi tar Red still cloud madhe basto. Interview ek line: "I remediate identities from a clean device, then reset the handset." Samjla ka?
Lab
Paper IR table for Raja-Rani Traders: step | who (Raja / IT Amir) | tool (account page / MDM). 8 rows. Role-play call to "bank" – practice refusing OTP share.
Real incident: Pegasus / NSO spyware reporting (Citizen Lab / Amnesty)
Investigative reporting by Citizen Lab, Amnesty International Security Lab, and media partners has documented alleged use of NSO Group Pegasus mercenary spyware against journalists, human-rights defenders, and other high-risk individuals in multiple countries (details and victim sets vary by report – verify primary sources; say "reported"). Amnesty published forensic methodology and indicators; toolkits such as Mobile Verification Toolkit (MVT) were released to help researchers look for known traces in device backups – specialist territory, not a student "scan your friend" toy. Blue lesson for this chapter: keep OS/apps updated; treat weird profiles seriously; Lockdown Mode / vendor guidance for elevated-risk users; escalate to trusted specialists / CERT – never buy stalkerware "to check". Source: Amnesty Security Lab forensic methodology reporting; Citizen Lab Pegasus publications; Apple Lockdown Mode context (verify).