Hugging Face Repositories Abused in New Android Malware Campaign
ID: 3fab60cd-1f86-5587-9bfd-88ccc035cd25
STIX ID: report--3fab60cd-1f86-5587-9bfd-88ccc035cd25
Feed Name: TechRepublic Security
Bitdefender researchers discovered a large-scale Android RAT campaign that used Hugging Face as a hosting and delivery mechanism: victims are tricked into sideloading a fake security app (e.g., TrustBastion) which then pulls a second-stage payload from Hugging Face. The attackers used server-side polymorphism to churn out thousands of slightly different payloads to evade detection, and the RAT requests Accessibility Services to record screens, capture lock-screen credentials, and present fraudulent authentication interfaces to steal app credentials; Hugging Face removed the malicious datasets after notification but operators quickly pivoted to new repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
