Pokemon Go is meant to be all fun and games. Someone has taken advantage of what is currently the most popular game on the planet and has released a modified version of the APK. The infected APK includes a malicious remote access tool called DroidJack. This gives access to your complete phone to a would be hijacker. The game did not release globally therefore it would have been very tempting to try and search for an APK to sideload. This is where many people have left their phones susceptible to the attack.
The best way to keep your phone from being infected with DroidJack is to simply wait until the app is available in the Play Store in your region. It is a very risky practice to side load apps and you should only ever sideload apps that come from a trusted source.
via ProofPoint