Found this interesting, Android malware families with their capabilities. https://forensics.spreitzenbarth.de/android-malware/
Usually common sense will. Mainly using fewer apps that are widely known, not trying any new apps with small number of downloads, especially nothing from outside Playstore. Using an adblock to block ads from apps and browsers (Adgaurd is a must for me and the only security app I use). Most important, imo, is utilizing the App permissions feature in Android 6.0+ You may also use a firewall app (there are plenty for free in store) to allow/disable internet connection for apps that should not need it. (as well as disabling ads in those apps)
Right most of that is known I do make sure I disable internet connection for apps that do not need it.