Through screenshots (and photographs, if needed) of the actual malware running on example devices, or in sandbox environments, or both, and what Play store install pages they're sending people to. I'd certainly hope that there's some team of people at Google doing exactly this already.
Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.
Suppose they send you to one of 20 hardcoded applications in the playstore, only one of which is theirs and the other 19 are innocent third parties being used as cover. Do you ban all 20?
Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.