Downloads found in YouTube descriptions or unverified third-party sites are frequently used to spread info-stealing malware: Disclaimer - TechTutorialGuide

: Modern browsers and email clients often scan .apk files for known malware. Compressing them into a .zip can sometimes hide the malicious payload from basic automated scanners.

Distributing an APK inside a file is a common tactic used to bypass security screenings: