logo

Attackers Using Hugging Face Hosting to Deliver Android RAT Payload

ID: cdba45c7-4d05-5780-914f-ab3ac8d07927

STIX ID: report--cdba45c7-4d05-5780-914f-ab3ac8d07927

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A social-engineering Android campaign distributes a fake security app (TrustBastion, later rebranded to Premium Club) that uses Hugging Face repositories to deliver a second-stage RAT. The malware requests Accessibility permissions to monitor users, capture credentials and screens, maintain persistent remote connections, and exfiltrate data; attackers employ server-side polymorphism with frequent repository commits to evade detection and sustain the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.