How to Tell a Real Signal APK From a Fake One

Published: October 7, 2026 · Updated: October 8, 2026

Short answer: A real Signal APK comes only from signal.org/android/apk, carries the package name org.thoughtcrime.securesms, and its signing certificate matches the SHA-256 fingerprint Signal publishes on that page. A fake fails at least one of those checks. Any file from a mirror site, a Telegram forward, or a "Pro/Plus" edition is fake until proven otherwise. Usually it is just fake.

Fake Signal APKs are one of the most common ways people get malware on their Android phones. The trick works because it is simple: attackers take the real Signal app (or just something that looks like it), add spyware or adware, and host it on a site that looks almost legitimate. The app icon is right, the name is right, and the chat screen looks right. Everything feels normal while your messages, contacts, and account quietly go somewhere they should not.

The good news is that telling real from fake is not a matter of instinct. Android's signature system gives you hard proof, and Signal publishes everything you need to check. You do not need special skills. You need the right file and five minutes.

Get the official Signal APK

from Signal's official site — file hosted by Signal, not by us

Comparison of a real Signal APK from signal.org with a matching signature versus a fake APK from a random site with a mismatched signature

The three checks that matter

Three-step diagram of the checks that identify a genuine versus fake Signal APK
Three checks, two minutes, near-zero fake risk.

You do not need to be a developer to verify an APK. Three checks catch virtually every fake:

  1. Where did the file come from?

    The real file comes from signal.org/android/apk. Anything downloaded from anywhere else is suspect by default.

  2. What is the package name?

    The real app's package name is org.thoughtcrime.securesms. A fake cannot keep this name and still pretend to be a different app. Many fakes use slightly different package names instead, and checking yours takes seconds.

  3. Does the signature match?

    Signal publishes the SHA-256 fingerprint of its signing certificate on its download page. A file signed by Signal's key matches; a repackaged fake signed by the attacker's key does not. This is the check that cannot be faked.

If all three line up, the file is genuine. If any one fails, treat the file as hostile. There is no "close enough" with signatures.

Where fake Signal APKs come from

Knowing where fakes live helps you avoid them in the first place. These are the usual suspects:

Notice what is not on this list: Signal's own download page and the Google Play Store's real Signal listing. Those are the only two places a genuine Signal app comes from.

Check 1: is the source the official download page?

This is the simplest check and the one that prevents nearly every problem. The official page is signal.org/android/apk: type it yourself or use a bookmark, rather than clicking links from videos, messages, or search ads.

Lookalike domains are the main trap here. Scammers register names that look right at a glance: signal-download, signalapp-official, signall-messenger, signal with a different ending. A quick habit that kills most of these: read the domain from right to left. The part just before the first single slash is the real domain. If it is not exactly signal.org, you are not on Signal's site.

Also check the connection: the address bar should show https://. Signal's site uses HTTPS, which means the page you see is really from Signal's servers and was not modified on the network. An HTTP download page (or a page with certificate warnings) is a hard stop. Do not download from it.

Check 2: does the package name match?

Every Android app has a package name: a unique ID that Android uses to tell apps apart. Signal's is org.thoughtcrime.securesms. (The unusual name is a leftover from Signal's history: the app began life as TextSecure, made by Open Whisper Systems.)

Why this matters: Android will not let two apps with the same package name be installed side by side. A fake that keeps Signal's real package name would have to replace your real Signal. That is why many fakes use a slightly different package name, like org.thoughtcrime.securesms.pro or something entirely different. If the installed app's package name is not exactly org.thoughtcrime.securesms, it is not Signal.

How to check it: open the app's page in Android Settings (Settings → Apps → Signal → look at the app info screen), or use any open-source APK info app from a trusted source to inspect the file before installing. Compare letter by letter. Scammers count on you skimming.

Check 3: does the signature fingerprint match?

This is the decisive check. When Signal builds the APK, it signs it with Signal's private key. Signal publishes the SHA-256 fingerprint of that signing certificate on its download page. Any copy of the app signed by the real key shows that exact fingerprint; a repackaged fake signed by the attacker's key shows a different one.

The attacker cannot fake this. Producing the matching fingerprint requires Signal's private key. "Steal Signal's signing key" is a different universe of attack from "repackage an APK on a mirror site." Repackaging, the actual method behind nearly all fake APKs, always breaks the signature match.

To verify, use the apksigner tool from the Android SDK Build Tools with the command Signal's page recommends, and compare the printed certificate digest with the fingerprint on the page, character by character. Our full walkthrough covers this step by step: verify the Signal APK's SHA-256 fingerprint. If you only do one technical check, make it this one.

One thing to keep straight: the website build and the Play Store build use different signing keys, so a Play-installed Signal shows a different fingerprint than the website APK. That is expected. Compare website-build files against the fingerprint on the download page, not against your Play-installed copy.

Check 4: does the filename look right?

The official website build follows a consistent naming pattern:

Signal-Android-website-prod-universal-release-8.29.3.apk

The version number changes with releases. 8.29.3 is the current website build, but the structure stays the same: Signal-Android-website-prod-universal-release- followed by the version and .apk.

This check is the weakest of the four, because a filename is trivial to fake. A file named exactly right can still be a fake, and a file with a renamed copy of the real download is still real. Treat the filename as a smell test, not proof: Signal-Pro-v9.99-mod-unlocked.apk is obviously bogus, but a correct-looking name proves nothing on its own. The signature check is what proves it.

A real case: the fake "Signal Encryption Plugin"

In 2025, the security company ESET reported two spyware campaigns, called ProSpy and ToSpy, that spread through fake websites impersonating Signal and ToTok. The ProSpy campaign is the textbook example of why this page exists, so it is worth knowing exactly how it worked.

The campaign was reported by ESET researcher Lukáš Štefanko and covered by The Hacker News, TechRadar, and Hackread. It targeted users in the UAE, but the method works anywhere: a trusted brand name, a plausible-sounding "plugin," and a manual install outside any store.

Red-flag checklist

Checklist graphic of red flags that identify a fake Signal APK
Any single red flag is enough to walk away.

Run through this list for any Signal download that did not come straight from Signal's page. One hit is suspicious; two is a verdict.

Red flagWhat it usually means
The site also offers "Pro," "Plus," or "Premium" editionsThose editions do not exist. The site is distributing fakes (see the Pro APK scam).
The download URL is not signal.orgMirror, re-host, or lookalike domain. The file cannot be trusted without a signature check, and usually fails it.
The page asks you to disable Play Protect or your antivirusLegitimate downloads never ask this. It is the single most blatant sign of malware distribution.
The installer asks for a "Signal password" or paymentSignal is free and has no account password. This is phishing or a subscription trap.
The version number is higher than the official current buildScammers invent future versions ("v10.2 Pro") to look newer than the real app. Check the real version first.
Aggressive popups, countdown timers, or "your download will expire"Pressure tactics to make you install before you think. Real downloads do not expire.
The file arrived as a forwarded message or email attachmentForwarded APKs are a classic malware vector. Get a fresh copy from the source instead.
The app icon looks slightly off: wrong shade, stretched, blurryRepackaged fakes often reuse low-quality copied artwork. Subtle, but worth a glance.

Permission red flags

Signal is a messenger, so it legitimately asks for things a messenger needs: contacts (to find your friends), microphone and camera (for calls), notifications, and storage or media access (for sending photos). Permissions become a red flag when they do not match what a messenger does.

Watch for these in particular:

A good habit: when any app asks for a permission, ask yourself what feature needs it. If you cannot name the feature, deny the permission. Android lets you grant permissions later when the feature actually needs them.

Why fake Signal APKs exist

Nobody repackages Signal for fun: there is money in it, several kinds:

Understanding the motive helps you understand the disguise. The fake has to look and feel like Signal long enough for you to keep it installed. So it usually is Signal, with extra code stitched in. That is exactly why surface inspection ("it looks like Signal") is worthless and the signature check is everything: the stitched-in code changes the signature, always.

What to do if you already installed a fake

Do not panic, but act quickly and in this order:

  1. Disconnect and uninstall

    Turn off Wi-Fi and mobile data to cut the app's connection, then uninstall the app. If it resists uninstallation (a sign of device-admin abuse), revoke its device administrator rights in Settings → Security first, then uninstall.

  2. Assume your Signal account is exposed

    If you registered your number in the fake app, treat the verification code and any chats as compromised. Reinstall the real Signal from signal.org/android/apk and re-register. This moves your account to the genuine app.

  3. Change passwords for important accounts

    Email first, then banking and anything tied to SMS two-factor codes, since a malicious app may have intercepted SMS. Do this from a clean device if you can.

  4. Check for leftovers

    Look in Settings → Apps for anything you do not recognize that appeared around the same time, and check Settings → Security → Device admin apps for entries you did not approve.

  5. Run a reputable mobile security scan

    A scan from a well-known security vendor can catch known variants and leftover payloads. It is a cleanup aid, not a verdict, but useful here.

Then report it: submit the fake's URL through Google Safe Browsing's phishing report form (safebrowsing.google.com/safebrowsing/report_phish/), so browsers and search engines warn other people about it too.

Frequently asked questions

How can I tell if my installed Signal is the real one?

Check the package name (org.thoughtcrime.securesms) in Settings → Apps, confirm you downloaded it from signal.org or the real Play Store listing, and verify the signature fingerprint against the one on Signal's download page. If all three check out, it is real.

Is a fake Signal APK dangerous if I never open it?

An installed-but-never-opened fake is much less dangerous, since its malicious code has not run, but some malware registers background services at install. Uninstall it and do not rely on "I never opened it" as safety.

Can antivirus detect a fake Signal APK?

Sometimes. Antivirus catches known fake variants, but a fresh repackaging may not be in any database yet. A clean scan is reassuring but not proof. The signature check is proof.

Are APK mirror sites ever safe for Signal?

Even honest mirrors add risk: you are trusting the mirror's file handling, and you lose the direct chain from Signal to you. For Signal specifically there is never a reason to use one. The official download is free and direct.

Someone sent me a Signal APK on WhatsApp. Is it safe?

No, not without verification. Forwarded files are a classic malware vector, and the sender may not know the file is tampered. Download a fresh copy from signal.org and verify its signature.

Does the real Signal APK ask for accessibility access?

No. The genuine Signal app does not request Accessibility Services or device administrator rights. Either request from a "Signal" app is a strong malware indicator.

Related guides