A new dropper-as-a-service (DaaS) named 'SecuriDropper' has emerged, using a method that bypasses Android 13's 'Restricted Settings' to install malware on devices and grant them access to the Accessibility Services.
TL;DR - You have to install a malicious app that pretends to be something else, then the app will try trick you into installing another APK (to which you have to specifically agree), and then your phone gets malware.