Monitoring threat trends on a global scale can be beneficial, showing, for example prevalent threats, how vulnerable the Android ecosystem is and if it is getting safer. This approach can, however, sometimes be misleading.When comparing global data for 2018, a gradual drop in the overall numbers of detections can be seen. However, does this really prove that the Android ecosystem is becoming safer?When we move from a global perspective to a more local one and dive into the regional distribution of threats, a different picture emerges. We chose three big regions to illustrate our findings: Europe, North America, Russia, and Australia. Worldwide, the data clearly shows a significant drop of less sophisticated malware strains, such as downloaders and rooters. This is either because the threats are no longer effective on new Android versions, or because the market value for these types of strains has decreased. These types of threats used to be the biggest categories of threats. But, they are also the ones that are the easiest to prevent and track down on a system level, which is precisely what Google aims to do. Especially in the aforementioned regions, we have observed a rise in technically advanced and covert malware such as bankers, fake apps and even targeted attacks.Studying local data allows us to better pinpoint threats and their distribution in specific regions. We saw again that threats differ by region. Just looking at threats on a global scale can be misleading and can cause oversight of regionally diverse threats.In our presentation, we will compare data from last year, show how this can help us predict new malware strains, but more importantly, discuss how we can use it to prevent and detect these threats. We will give examples of how we cluster detections, demonstrate how to recognize threats and provide guidelines on how to successfully prevent devices from getting infected in the first place.