logo

Hugging Face abused to spread thousands of Android malware variants

ID: a0ea63e4-1e58-5981-b4d5-21759a2fe9d6

STIX ID: report--a0ea63e4-1e58-5981-b4d5-21759a2fe9d6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A widespread Android malware campaign used Hugging Face as a trusted repository to distribute thousands of polymorphic APK variants via a dropper called TrustBastion; the payload is a remote access tool that abuses Accessibility Services to display phishing overlays, capture screenshots, steal credentials (e.g., Alipay, WeChat), and maintain persistent C2 communications, with researchers providing IOCs and Hugging Face removing the malicious datasets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.