Google is expanding an Android security feature that uses on-device artificial intelligence to watch how apps behave in real time and raise an alarm the moment one starts acting like spyware. The system, called Live Threat Detection, no longer relies solely on recognizing known malware by signature. Instead, it looks for the behaviors that malicious apps exhibit, such as quietly forwarding text messages or hiding their own icon, and flags them as they happen.
Watching behavior instead of matching signatures
Traditional mobile malware defenses work largely by comparison, checking an app against a catalog of known-bad code. That approach struggles against new or modified threats that have not yet been cataloged. Live Threat Detection takes a different tack: it uses on-device AI to analyze what an app actually does after it is installed, then alerts the user if the app starts behaving suspiciously.
Running that analysis on the device rather than in the cloud is a deliberate design choice. It keeps the behavioral data local, which is important given that the very information being examined, such as message activity and app permissions, is sensitive. It also means the detection can operate continuously and respond quickly, rather than waiting to send telemetry off the phone and receive a verdict back.
SMS forwarding and hidden icons as red flags
The 2026 expansion adds new warnings tuned to specific spyware tactics. If an app suddenly begins forwarding a user’s SMS messages, the system treats that as a suspicious pattern and issues an alert. According to Google’s security blog, Live Threat Detection is also gaining warnings for accessibility overlay abuse, another common spyware technique.
Silent SMS forwarding is a hallmark of surveillance and fraud tooling, because text messages often carry one-time passcodes and account-recovery links. An app that quietly relays those messages can hand an attacker the keys to a victim’s other accounts. Flagging that behavior as it starts, rather than after damage is done, is aimed squarely at the window in which a malicious app is most dangerous.
Dynamic signal monitoring and pushed-down rules
A companion capability, dynamic signal monitoring, broadens the net further. It allows Android to warn users about apps that change or hide their icon and then launch from the background, or that abuse accessibility permissions to control the device. Crucially, the system can push down new detection rules dynamically, meaning Google can update what counts as suspicious without waiting for a full operating-system release.
That ability to update rules on the fly matters because threat behaviors evolve quickly. An attacker who learns which patterns are being flagged can try to adjust, and a defense that can only change with major OS updates would always lag behind. By distributing new rules directly to devices, Google is trying to shorten the gap between a new spyware technique appearing and the platform learning to recognize it.
Rolling out on Android 17
The enhanced protections are tied to the latest platform generation. Dynamic signal monitoring is being enabled on Android 17 devices, with the protections rolling out in the second half of the year. Coverage from TechRepublic placed the expanded spyware defenses within a wider 2026 wave of Android security updates targeting scams and theft.
Anchoring the rollout to Android 17 has a familiar tradeoff. Newer devices and those that receive prompt updates gain the strongest protection first, while older phones may wait longer or, depending on their update status, miss some features entirely. The behavioral, rule-based nature of the system is designed to reach devices through updates rather than hardware changes, which broadens its potential footprint over time even if it does not arrive everywhere at once.
Layered defenses beyond spyware detection
Live Threat Detection sits inside a broader set of 2026 Android security measures rather than standing alone. Chrome now evaluates an APK for known malware and can block the download outright if it detects a threat, adding a checkpoint before a malicious app is ever installed. Android has also begun automatically hiding one-time passwords from text messages for three hours from most apps, closing off a common avenue for code theft.
Together these measures address different stages of an attack. Blocking a malicious download stops a threat at the door; hiding one-time passwords limits what a hostile app can steal even if it slips through; and behavioral monitoring catches an app that turns malicious after installation. Layering defenses this way reflects a recognition that no single control catches every threat, and that spyware in particular often behaves normally at first before shifting to surveillance.
The privacy tradeoffs of an always-watching system
A defense that continuously observes app behavior inevitably raises questions about how much the operating system itself is monitoring. Google’s answer is that the analysis happens on the device, keeping behavioral data off its servers, an architecture meant to reconcile aggressive threat detection with user privacy. The same design that makes the system fast also keeps the sensitive inputs local.
The larger significance is a shift in how mobile platforms think about malicious software. Rather than treating security as a periodic scan that checks apps against a known-bad list, Android is moving toward a model of constant behavioral vigilance, where the platform assumes any app could turn hostile and watches accordingly. For users, that means protection that keys on what an app does rather than what it is called, an approach better suited to spyware that is built to slip past static defenses and reveal its true purpose only after it is already installed.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The FTC is warning about a scam quietly draining thousands from victims
- The NSA is again telling phone owners to switch off one location setting
- A handful of car transmissions are so tough mechanics say they almost never fail
- A handful of SUVs keep hitting 300,000 miles, and they share one engine trait