Android RAT Uses Hugging Face to Host Malware
ID: c96c64fc-9b0d-5caa-85f9-a5092fde9eb7
STIX ID: report--c96c64fc-9b0d-5caa-85f9-a5092fde9eb7
Feed Name: Infosecurity Magazine (News)
Bitdefender reported an active Android RAT campaign branded TrustBastion that uses Hugging Face repositories to host polymorphic APK payloads. The attack chain uses a dropper that redirects to Hugging Face, prompts victims to install faux updates, and then enables Accessibility and screen-capture permissions to harvest credentials (including from payment apps) and exfiltrate data; the operation is automated, persistent, and has multiple thousands of commits and likely thousands of victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
