Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

No single scan can prove an Android APK is safe. Static analysis can flag suspicious code and app structure without running the app; dynamic analysis can observe behavior during execution; services such as Google Play Protect combine multiple kinds of evidence. Scandroid describes itself as a static APK triage tool, so its results are one signal—not a guarantee of what an app will do on every device.

What APK malware detection actually checks

An Android app package (APK) contains an app’s code and resources. Scanners look for evidence that may indicate harmful behavior, but evidence needs context: a permission or API call can be suspicious without proving malicious intent. Google describes potentially harmful applications (PHAs) as apps that can put users, their data, or devices at risk. The potential impact can depend on the device and Android version, and the category includes threats such as trojans, phishing, spyware, ransomware, and backdoors.

Google’s Play developer policy also uses a broad definition of malware, covering code that could put users, their data, or devices at risk, including PHAs, binaries, and framework modifications. These definitions focus on risk and behavior, not on one telltale file or permission.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Static and dynamic analysis reveal different evidence

Approach What it does What it can reveal What it can miss
Static analysis Inspects the APK and extracted properties without executing the app. Suspicious permissions, code or API patterns, embedded indicators, and app structure. Behavior that depends on runtime conditions, device state, or actions that cannot be observed from the file alone.
Dynamic analysis Runs the app in an environment and observes its behavior. Actions that occur during the run, including some behavior that is difficult to infer from the package alone. Behavior not triggered by the actions, device state, network access, or time available in that run; obfuscation can also complicate analysis.

The methods complement one another. Google’s technical explanation notes that obfuscation can hinder static analysis, while static analysis can help identify cloaking attempts that evade dynamic analysis. A sandbox run is an observation of a particular execution, not proof that every possible behavior has been exercised.

Why layered detection is more useful than one score

Google says Play Protect combines machine learning, static and dynamic analysis, signatures, third-party reports, and behavioral signals. Its examples include unexpected interactions with other apps, unauthorized data access or sharing, aggressive installation behavior, malicious websites, and attempts to bypass security features. Multiple signals can provide a stronger basis for triage than a permission list or classifier score alone. That does not mean every scanner uses the same evidence, or that any detection system catches every threat.

Detection figures also need their context. Google’s 2018 Android Developers Blog post said its machine-learning models identified 60.3% of PHAs detected in 2017, across more than 2 billion Android devices. That is a historical figure about Google’s models and the detections covered by that report—not a current, universal detection rate. In 2024, Google reported 200 billion Android app scans daily and said Play Protect helped keep more than 3 billion users safe. Those are Google-reported scale figures, not an independent accuracy test.

Does Play Protect scan APKs you download?

Google says Play Protect scans devices for evidence of potentially harmful applications. Its on-device guidance lets users check when the device was last scanned and see scanned apps. If Google does not have enough information about an app, users may be asked to allow app data to be sent to Google for analysis. That consent request is not evidence that every APK is uploaded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Play Protect’s combination of signals is useful context when evaluating an app, but a clean result should not be treated as a guarantee. Keep Android updated and prefer an app from a reputable store or the developer’s verified distribution channel. Do not install an APK you already suspect is malicious just to see what it does.

What Scandroid says it checks

Scandroid’s website describes a browser-based APK upload and analysis service that performs static analysis with an ensemble machine-learning engine. It says its pipeline extracts static features from manifests, permissions, API calls, and intent filters. That can support triage of the package, but static inspection alone cannot establish every runtime action or condition-dependent behavior.

Scandroid advertises more than 500 extracted static features, a three-layer ensemble, and 98.4% accuracy on the Drebin benchmark. These are Scandroid’s claims, not independently reproduced results. The reviewed materials do not provide the test split details, measurement date, or evidence that the benchmark result predicts current detection performance in the field. The figure should not be read as a promise that the service will correctly classify 98.4% of APKs a user encounters.

The developer documentation describes a POST /v1/scan endpoint that accepts an APK file and an API key; its example response includes a classification and risk score. That shows an upload-based API workflow, not an on-device scan. The available API description does not establish file-retention or privacy-handling details, so organizations should confirm those terms before uploading sensitive or proprietary APKs. API availability and product terms can change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scandroid also makes claims about resistance to obfuscation and adversarial attacks. Without independent, reproducible evaluation, those should be treated as vendor statements rather than established performance. The supportable description is narrower: Scandroid presents itself as a static APK triage tool.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to judge a scanner result

When comparing a scanner or interpreting a report, ask what the result actually covers rather than relying on one accuracy percentage.

  • Coverage: Does it inspect the file statically, observe runtime behavior, or combine both?
  • Evidence: Does it use signatures, permissions, code or API patterns, behavior, reputation, or third-party reports?
  • Evaluation: Is the dataset and its date identified? Are training and test samples separated? Are false positives reported, and has the result been independently reproduced?
  • Operational limits: Which Android versions, network conditions, sandbox actions, and user-consent requirements apply? Was the behavior of concern actually triggered?
  • Privacy and workflow: Does the APK leave the device? What are the retention and access controls, and how much evidence does the report provide?

These questions distinguish what a scanner observes from what its score appears to promise. A benign classification is evidence to weigh alongside the app’s source and context; it is not a safety certificate.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.