Google Play trojan policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Apps with an apparently harmless feature hiding harmful behavior.
A trojan classification means benign-looking functionality is paired with an unwanted harmful component. The harmful part can be unrelated to the feature users installed the app for.
What to check
Compare advertised functionality with every background operation. Inspect newly added SDKs, downloaded modules, premium messaging, data collection, and remote activation paths.
Check whether the notice names a second malware category. That category often identifies the harmful action hidden behind the ordinary app experience.
How to address the rejection
Remove the harmful component and determine how it entered your build. Rebuild from verified dependencies, then test the release artifact after initialization and remote configuration complete.
Demonstrating that the visible game or utility works doesn’t answer a trojan finding. Your response needs to address the hidden behavior itself: which component caused it, what it did, and how the corrected artifact prevents it. If you believe the detection is incorrect, explain the flagged component’s real operation with reproducible evidence.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Trojan Checked 22 September 2026