logo

AI Hub Hijacked: Polymorphic Android RAT Abuses Hugging Face to Steal Data

ID: 66d4b4fb-9678-5f83-af4b-8282b7e13806

STIX ID: report--66d4b4fb-9678-5f83-af4b-8282b7e13806

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Bitdefender researchers uncovered an Android Remote Access Trojan campaign that leverages Hugging Face repositories to host rapidly polymorphic APK payloads delivered by fake apps (TrustBastion / Premium Club). The dropper uses social engineering to prompt users to grant Accessibility permissions, enabling the RAT to record screens, overlay fake login windows, and steal credentials; malicious datasets were removed after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.