TBH, I wouldn't even bother to try and hide malware ...
The amount of shite that network/operator supplied devices come with pre-installed (uninstallable and in some cases undisable-able) you could smuggle a forest of malware past the average user.
"What's this app for ?"
"What's that app for ?"
Oh look, there's an app with the operators logo. What's that for ?"
In years to come, one of the sever ages of man will be when he gets fed up of network/operator locks and cruft, and buys a plain unlocked phone as standard.