Google Play trojan policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps with an apparently harmless feature hiding harmful behavior.

A trojan classification means benign-looking functionality is paired with an unwanted harmful component. The harmful part can be unrelated to the feature users installed the app for.

What to check

Compare advertised functionality with every background operation. Inspect newly added SDKs, downloaded modules, premium messaging, data collection, and remote activation paths.

Check whether the notice names a second malware category. That category often identifies the harmful action hidden behind the ordinary app experience.

How to address the rejection

Remove the harmful component and determine how it entered your build. Rebuild from verified dependencies, then test the release artifact after initialization and remote configuration complete.

Demonstrating that the visible game or utility works doesn’t answer a trojan finding. Your response needs to address the hidden behavior itself: which component caused it, what it did, and how the corrected artifact prevents it. If you believe the detection is incorrect, explain the flagged component’s real operation with reproducible evidence.

Messages this guide can help with

Trojan; Trojan policy violation; Trojan rejection; Trojan denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access