logo

Hugging Face Repositories Hijacked For Android RAT Delivery, Bypassing Traditional Defenses

ID: 0ae1997a-0381-5c37-ae15-fc1d52a798f2

STIX ID: report--0ae1997a-0381-5c37-ae15-fc1d52a798f2

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Varshini

...
...

The report details an active Android RAT campaign (TrustBastion / "Premium Club") that lures users to install a dropper app which fetches polymorphic APKs hosted on Hugging Face; the malware requests Accessibility Services to capture screens, show fake login interfaces (Alipay/WeChat), exfiltrate data to C2 154.198.48.57:5000, and maintain persistence. Attackers use rapid server-side polymorphism (thousands of commits and new APKs every 15 minutes) to evade hash-based detection; Bitdefender observed the campaign, coordinated takedowns, and published IoCs including MD5 hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.