Here’s an interesting article I came across the other day. It’s about Android malware apps and botnets, of which there are many: http://www.androidpolice.com/2017/04/26/security-firm-check-point-says-millions-infected-botnet-malware-via-play-store/
The privacy option Disable device administrator removes any devices administrators from the cloned app, so that an app which you don’t know or don’t trust will not be able to request device admin access in the first place. I especially recommend this option when you download an APK file from the internet.
