Downloading an APK for an unofficial Telegram client takes a few seconds. Knowing what’s actually inside that file is a different matter. Most people simply trust the website they downloaded it from, or the app’s general reputation. That’s not quite enough — even well-known projects occasionally end up with fake copies on third-party sites, and for lesser-known clients there’s often no way to verify the file’s origin beyond trusting whatever description is posted alongside it.
The good news is that checking an APK before installing it is something you can do yourself, for free, without any special skills.
Why check an APK even if the website looks trustworthy
A polished website design doesn’t say anything about how safe a file is. A clean layout, a detailed feature list, even a section of user reviews — none of that takes much effort or money to put together. A modified APK with unwanted code baked in can look and behave exactly like a normal app, right up until it asks for permissions it doesn’t need or starts sending data somewhere it shouldn’t.
So checking the file isn’t about distrusting a specific developer — it’s just basic hygiene for any APK that doesn’t come from Google Play.
Method 1 — Scan it with VirusTotal
VirusTotal is a free service that scans a file with dozens of antivirus engines at once and gives you a combined result.
How to upload an APK to VirusTotal:
- Download the file to your phone or computer, but don’t open or install it yet.
- Go to virustotal.com and select the “File” tab.
- Upload the APK — for a typical file size, the scan takes under a minute.
How to read the results. VirusTotal shows how many antivirus engines out of the total flagged the file — for example, “2/70”. One or two flags from lesser-known engines are often false positives in practice (this is particularly common with modified apps, since they alter system files differently from “standard” apps, and some antivirus engines react to the modification itself rather than to an actual threat). Several flags from major, well-known antivirus engines, on the other hand, is a real reason to skip the file.
Method 2 — Google Play Protect’s built-in scan
Even if an APK didn’t come from Google Play, most Android devices have Google Play Protect enabled, and it can scan the file right before installation. This usually happens automatically, but it’s worth confirming it’s turned on: Google Play → profile icon → Play Protect → settings.
This doesn’t replace a proper VirusTotal check, but it adds one more independent layer of verification.
What to look for in the APK itself
Beyond the antivirus scan, a few practical details are worth checking:
- File size. If the APK is noticeably smaller or larger than the official app, or than the same client listed on other sites, that’s worth a closer look.
- Requested permissions. If a messaging app asks for access unrelated to messaging, it’s worth figuring out why.
- Developer signature. Most clients keep a consistent signature across versions. If a third-party site offers a file with a different signature than what’s listed in the developer’s official GitHub repository, for example, look for the file elsewhere.
What to do if the scan flags a threat
If VirusTotal or Play Protect flags the file as a threat, don’t install it — even if it’s already downloaded and looks like it works fine. Delete it and look for the APK from a different source, ideally the developer’s own website or repository.
The bottom line
Checking an APK before installing it takes a couple of minutes but closes off most of the risk that comes with third-party Telegram clients. A quick pre-install checklist:
- File scanned with VirusTotal
- Google Play Protect is on and didn’t flag anything
- File size matches what’s expected
- Requested permissions make sense for a messaging app
- File downloaded from a source the client’s own developer points to