This isn't a problem on Android, at least from what I can see. IMO at the small scale the benefits of the play store (payment processing, discoverability, bandwidth, hosting) outweigh anything you could gain by offering your apk for direct download somewhere else.
Plus, even if you try to deploy malware you still need to get through the regular permission dialogs and other bits of Android security. I have no idea how easy/hard this is but I would be surprised if iOS performs substantially worse here.
Plus, even if you try to deploy malware you still need to get through the regular permission dialogs and other bits of Android security. I have no idea how easy/hard this is but I would be surprised if iOS performs substantially worse here.