I recently connected my Galaxy A16 to a friend's Wi-Fi setup, which uses separate routers or networks for personal devices, guests, and IoT equipment. As soon as my phone connected, mobile data paused briefly, and I saw prompts that appeared to involve setting up or sideloading carrier-related apps and Android components. Some unfamiliar apps also seemed to appear, and my notifications were temporarily blocked except for notifications from those apps.
I normally keep track of the apps installed on my phone, avoid automatic Play Store updates, and have previously removed carrier software. Developer options may also be enabled, and the network owner is familiar with Android debugging tools. I am concerned that the phone may have been compromised and want to understand whether a router could intercept traffic or cause malicious software to be installed. Without physical access to the router, what evidence or tests could help determine whether the network itself is malicious?
4 Answers
A router can be configured to intercept or manipulate network traffic, especially unencrypted traffic, and a malicious network could use fake login pages or DNS tricks. However, simply connecting to Wi-Fi generally cannot silently install arbitrary Android apps. Android normally requires user approval, an enabled installation source, an exploit, or a compromised device-management or system component. The brief pause in mobile data is also normal when the phone switches from cellular data to Wi-Fi, and connecting to a familiar network can trigger delayed app or system updates.
To test the network without accessing the router, use your phone only after backing up important data, then compare its behavior on cellular data and on a different trusted Wi-Fi network. You can inspect the assigned DNS servers, certificate warnings, captive-portal behavior, and whether a VPN or unusual certificate appears. A packet capture from a device you control can show suspicious DNS or unencrypted connections, but modern HTTPS prevents the router from simply reading or changing most protected traffic.
If you genuinely believe unknown apps were installed or security settings changed, the safest response is to disconnect from that Wi-Fi, remove unfamiliar apps and profiles, update Android, change important passwords from a trusted device, and consider a factory reset. Before resetting, save screenshots and app/package information as evidence. A router cannot normally force a legitimate Galaxy phone to install arbitrary applications just because it joined the network, so the phone itself, an approved installation source, or a misleading setup prompt should also be investigated.
The most useful evidence would be the exact wording of every prompt, screenshots, the names and package details of the unfamiliar apps, and their installation times. Check Settings for the app's install source, enabled accessibility services, device-admin apps, VPN profiles, certificates, notification access, and whether installation from unknown sources is allowed. Turn off any unnecessary developer options, USB debugging, and unknown app-install permissions. Avoid interacting with suspicious prompts until you know what generated them.

A list of app names alone may be misleading because some Android and carrier components are updated separately from the main operating-system update. Check the package name, version, publisher, permissions, and install source rather than relying only on the displayed label.