I recently connected my Galaxy A16 to a friend's Wi-Fi setup, which uses separate routers or networks for personal devices, guests, and IoT equipment. When the phone connected, mobile data paused briefly, and I was prompted to complete what appeared to be a device setup or sideloading process involving Google Play services and carrier-related apps. I also noticed unfamiliar apps and changes to notifications that I don't remember approving.
I normally keep track of the apps installed on my phone and have disabled automatic Play Store updates. Developer mode may be enabled, and the network owner is familiar with Android debugging tools. I'm concerned that the router may be intercepting traffic or attempting to install malicious applications. Is that technically possible, and how can I determine whether the problem came from the router, the phone, or a normal Android update without having physical access to the router?
3 Answers
Start with the exact wording and screenshots of every prompt rather than relying on a summary. On the phone, check Settings for the list of installed apps and sort by recently installed or recently updated. Review Google Play Protect, Accessibility services, Device admin apps, VPN settings, notification access, and the permissions for unfamiliar apps. Also check the settings for installing unknown apps and disable that permission for every app that does not genuinely need it. If you enabled debugging or changed developer settings, return them to their defaults and turn off USB debugging and wireless debugging.
A router can be configured to intercept or redirect network traffic, especially unencrypted traffic or DNS requests. However, a router generally cannot silently install arbitrary Android apps by itself. Modern Android normally requires user approval for unknown-source installations, and properly signed HTTPS connections make it difficult for a network device to impersonate Google services. Briefly losing mobile data while the phone switches to Wi-Fi is normal, and connecting to an unmetered network can trigger delayed system, carrier, or Play services updates.
Developer mode is enabled, so I’m wondering whether that created an additional way for the network or another device to affect the phone. I’m mainly trying to find evidence that the router itself is malicious.
To investigate the network without accessing the router, compare the phone’s behavior on several trusted connections, such as your own home network and a mobile hotspot. Check the Wi-Fi network’s DNS server, gateway, certificate warnings, VPN configuration, and captive-portal behavior. A packet capture can reveal unusual DNS redirects or unencrypted connections, but encrypted HTTPS traffic should not be readable just because you joined the Wi-Fi. The strongest evidence would be the same suspicious behavior occurring only on that network and a capture showing redirects or certificate errors.
A clean phone connected to a different network is a useful control test. If the prompts disappear elsewhere, inspect the original network and avoid reconnecting until you understand what caused them. If the prompts continue across networks, the phone or one of its accounts is the more likely source.

If unfamiliar apps keep appearing, back up only essential personal data, record the evidence, and perform a factory reset using the phone’s official recovery process. Afterward, update Android, change important passwords from a trusted device, and reinstall apps manually instead of restoring every app automatically.