A real-time malware scanner
About this app
Hypatia is the worlds first FOSS malware scanner for Android. It is powered by ClamAV style signature databases.
Features
• Near zero battery impact: you'll never notice any impact on battery at all
• Extremely fast: it can scan small files (1MB) in 20ms, and even large files (40MB) in 1000ms.
• Memory efficient: with the default databases enabled it uses under 120MB.
• Regular scan: allowing selection of /system, internal storage, external storage, and installed apps
• Realtime scanner: can detect malware in realtime on write/rename in internal storage
• Completely offline: Internet is only used to download signature databases, files will never ever leave your device
• Persistence: will automatically restart on boot/update
• Tiny codebase: coming in at under 1000 sloc, it can be audited by even someone with basic programming experience
• Minimal dependencies: the app only uses libraries when necessary
• Signature databases can be enabled/disabled at the users demand
Licensed under AGPL-3.0-or-later, by Divested Computing Group.
What's New in v3.14
Imported from the F-Droid repository index.
- Translation updates thanks to the following contributors:
- - Arabic: abdelbasset jabrane, ABDO GM
- - Chinese (Simplified): Crit, 大王叫我来巡山
- - Chinese (Traditional Han script): 張可揚
- - Croatian: lukapiplica
- - Estonian: Priit Jõerüüt
Version history
Dec 9, 2024 · 0.5 MB · Android API 16–32 · code 314
Imported from the F-Droid repository index.
- Translation updates thanks to the following contributors:
- - Arabic: abdelbasset jabrane, ABDO GM
- - Chinese (Simplified): Crit, 大王叫我来巡山
- - Chinese (Traditional Han script): 張可揚
- - Croatian: lukapiplica
- - Estonian: Priit Jõerüüt
SHA-256 7262cf1f76a04c91f187b958658aa588d7a313534f5522daa5a9d159297b21da
May 30, 2024 · 0.5 MB · Android API 16–32 · code 312
Imported from the F-Droid repository index.
- * Many optimizations to the link scanner feature
SHA-256 8994bc0b10ef8089835486524966fe9ddfd971265c6ff92183f756cdc5fecc0c
May 30, 2024 · 0.5 MB · Android API 16–32 · code 311
Imported from the F-Droid repository index.
- * Ability to scan screen content for malicious links
SHA-256 51e1fabb01fa9dc74bd70cef87a611667d11eba75d5f92538095d339a4c3e794
Will it run on your device?
73%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be us.spotco.malwarescanner is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 3.12 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Hypatia first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Hypatia, and a listing is removed when the evidence for it stops holding up.
Get Hypatia
Every source we list for us.spotco.malwarescanner is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
7262cf1f76a04c91f187b958658aa588d7a313534f5522daa5a9d159297b21da
Signing certificate
793660516b62ae8deba66d5e5e4244e0931749ab9f48575b501244ceea858a84
Permissions Required
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
Report a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.