The biggest risk is malware. Unlike the Google Play Store, which has automated systems to scan for viruses, third-party APK sites are largely unregulated. Hackers often take a legitimate app, inject malicious code (spyware, ransomware, or keyloggers), and repackage it as a "Premium APK."
For a hands-on look at how to use the drag-and-drop and smart selection features in Touch Notes:
If you have a dedicated testing device (no personal data) and want to analyze the threat: