Android users are being warned about malicious apps that can replace a phone’s normal home screen after a Mahjong-themed game reportedly took control of a customer’s device.
The customer had installed dozens of Mahjong apps before noticing that the familiar interface had been replaced by one of the games. The application involved was later removed from the Google Play Store, but the case shows how an ordinary-looking download can misuse Android’s default-app settings.
The behaviour may feel like a home-screen virus. In reality, the unwanted app has usually persuaded the user to select it as the default Home application, giving it control over the screen that appears after the phone is unlocked or the Home button is pressed.
Why launcher access creates a serious security risk
The application that controls an Android home screen is commonly known as a launcher. It manages app icons, folders, widgets and access to the app drawer.
Legitimate third-party launchers can provide custom layouts, accessibility features or improved performance on older devices. A puzzle game, calculator, wallpaper app or basic utility has no practical reason to replace the manufacturer’s launcher.
Once selected as the default Home app, malicious software gains persistent access to one of the most frequently viewed parts of the phone. It can display intrusive advertising, imitate trusted interfaces or make removal unnecessarily difficult.
Any app that is not clearly presented as a launcher should therefore be rejected if it asks to become the default home screen.
How a malicious home-screen app can be abused
One possible use is ad fraud. An unwanted launcher may place advertisements across the interface or run a click-generating component in the background, creating revenue without genuine user interaction.
Overlay attacks present a more direct danger. Malware can wait for a banking, email or social media app to open and then place a convincing imitation login page over the real screen. Credentials entered into the fake form, including autofilled details, may be captured.
Other mobile malware campaigns have tried to collect phone numbers, one-time passcodes and stored payment-card information after convincing victims to change their default launcher.
Some unwanted apps can also draw elements over Android settings or cover the buttons needed to uninstall them. This may leave users believing that the phone has been permanently locked into the replacement interface.
Unexpected changes are not always caused by malware. A carrier disruption can make a functioning phone appear unusable, as customers experienced during the T-Mobile outage that left devices showing SOS or No Service. Checking whether the problem affects the interface, mobile signal or both can prevent unnecessary resets.
How to restore the original Android home screen
Open Settings, choose Apps, select Default apps and then open Home app. The exact wording may vary depending on the phone manufacturer and Android version.
Select the device’s original launcher or another recognised home application. After the normal interface returns, find the suspicious game or utility under Settings > Apps and uninstall it.
If the application blocks normal removal, restart the phone in Safe Mode. On many Android devices, this can be done by opening the power menu and pressing and holding the on-screen Power off option until the Safe Mode prompt appears.
On many Samsung phones, restart the device and hold the volume-down button while it boots. A Safe Mode label should appear near the bottom of the screen or in the notification panel.
Third-party apps and widgets are temporarily disabled in Safe Mode, preventing the malicious launcher from covering settings or interfering with the uninstall process. Remove the offending app and restart the phone normally.
Checks to make before installing Android apps
Users should compare every permission request with the app’s advertised purpose. A game may need internet access for online features, but it should not need to control the home screen, read authentication messages or access payment information.
Review the developer’s identity, recent complaints, update history and Data safety section before installing unfamiliar software. A high download count should not replace careful scrutiny of permissions.
Device reliability matters as well as software security. Excessive temperature can trigger slow performance, paused charging and unexpected shutdowns, so these steps for preventing smartphone overheating during a heatwave can help users distinguish a thermal problem from suspicious app behaviour.
Google recommends keeping Play Protect enabled because it scans installed applications, checks new downloads and may warn users about potentially harmful software. The official Google Play Protect safety guide explains how to confirm that scanning is active.
The clearest warning sign remains simple: unless an app was deliberately installed as a custom launcher, it should never need permission to become the phone’s default Home application.














