logo

Android RAT Uses Hugging Face to Host Malware

ID: c96c64fc-9b0d-5caa-85f9-a5092fde9eb7

STIX ID: report--c96c64fc-9b0d-5caa-85f9-a5092fde9eb7

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-22

...
...

Bitdefender reported an active Android RAT campaign branded TrustBastion that uses Hugging Face repositories to host polymorphic APK payloads. The attack chain uses a dropper that redirects to Hugging Face, prompts victims to install faux updates, and then enables Accessibility and screen-capture permissions to harvest credentials (including from payment apps) and exfiltrate data; the operation is automated, persistent, and has multiple thousands of commits and likely thousands of victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.