Free lesson · Skill · 6 min

Fake apps and remote access

Lesson 8 of 10 in AI Fraud Awareness Foundations

The one idea

The most efficient scam does not steal your password — it convinces you to hand over your whole screen. The caller from "the bank security team" asks you to install a "protection app" (actually AnyDesk, TeamViewer, or similar remote-access software) or to share your screen "so we can verify together". From that moment they watch every balance, every PIN you type, every OTP that arrives.

Compare:

"He was from the fraud department and the app was to protect my account while they reversed the fraud." — the app was the fraud.

versus

"The bank does not install apps on my phone through a phone call. I am hanging up." — attack over.

Why it works and the one rule

Remote-access tools are legitimate software (IT departments use them daily), so app stores host them and phones trust them. The attack is not technical — it is the story that gets one installed during a panic. So the rule is not "never use screen sharing"; it is: never install anything, and never share a screen, at the request of someone who called you. Banking apps come from one place only — the official app store listing you searched for yourself — and no bank installs "security software" by phone.

If one is already installed from such a call: disconnect from the internet, uninstall it, change banking passwords from a DIFFERENT device, and call the bank.

Try it now

Check your phone right now for remote-access apps you do not remember installing (AnyDesk, TeamViewer, RustDesk, AirDroid). Then write your one-line rule where you will find it in a panic: "Nobody who phones me gets an app installed or a screen shared. Ever."

Your win today

Your screen is your vault. Nothing gets installed and nothing gets shared at the request of an incoming caller.

Turn the idea into a reflex

Members practice this against a real AI assistant, get feedback on the prompt, then review it before the idea fades.

Practice this lesson free