The amount of mobile malicious code is increasing faster every year and a serious security threat is posed by this. Hence,
malware detection has become a critical topic in the field of computer security. This paper proposes a method to detect
variants of known malware families in Android devices using simplify Dalvik instructions. This method is based on the
sequence of instructions. A method is described in this paper to give the simplified description of each instruction and
group them with n-gram patterns, which are set to be the malicious features. The result of the experiment shows that
features extracted by this method are easy to be recognized, thus an effective way to detect variants of known malware
families is provided.