Malware & Threats

Hugging Face Abused to Deploy Android RAT

Android users were lured to applications that served a malicious payload hosted in a Hugging Face repository.

Hugging Face hack

The Hugging Face infrastructure has been abused for the delivery of an Android remote access trojan (RAT), Bitdefender reports.

The attack chain starts with an ad or a prompt to download and install a security application claiming to provide multiple useful features.

The application, called TrustBastion, acts as a dropper and immediately after launch prompts the user to fetch an update, displaying legitimate-looking Google Play and Android system update dialogs.

Once the user agrees, the dropper connects to an encrypted endpoint hosted at trustbastion[.]com, which serves an HTML page that points to a Hugging Face repository, and then downloads a malicious payload from the online platform’s datasets.

According to Bitdefender, the Hugging Face repository used in the attack was roughly a month-old when taken offline and had over 6,000 commits. New payloads were being generated roughly every 15 minutes, the cybersecurity firm says.

“The repository eventually went offline, but only for the entire operation to move to another link, with the project using different icons and some minor adjustments. The code remained the same,” Bitdefender explains.

Advertisement. Scroll to continue reading.

After installation, the malicious payload requested broad permissions, pretending to be a security feature, and guided the user to enable Accessibility Services to monitor their actions.

It also requested permissions to record the screen, perform screen casting, and display overlays, enabling it to observe, capture, and modify on-screen content in real time.

Once permissions are enabled, the malware can control infected devices and exfiltrate screen content to the command-and-control (C&C) server.

“The malware also displays fraudulent authentication interfaces designed to harvest sensitive credentials. It tries to impersonate popular financial and payment services, including Alipay and WeChat,” Bitdefender says.

Additionally, the malware could capture lock screen information and authentication actions, and was seen maintaining persistent communication with the C&C and downloading webviews to mimic legitimate functionality.

“This infrastructure is used to receive commands, transmit stolen data and deliver updated configuration information to infected devices. The same infrastructure also facilitates payload redirection by serving Hugging Face download links to the initial dropper,” Bitdefender says.

Soon after the repository hosting TrustBastion disappeared at the end of December, another repository emerged, hosting Premium Club, a seemingly different app that has the same underlying code. Hugging Face took down the datasets serving the malware, Bitdefender says.

Related: Kimwolf Android Botnet Grows Through Residential Proxy Networks

Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

Related: New Albiriox Android Malware Developed by Russian Cybercriminals

Related: Landfall Android Spyware Targeted Samsung Phones via Zero-Day

Related Content

Artificial Intelligence

Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.

Malware & Threats

Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access.

Supply Chain Security

Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.

Malware & Threats

 Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.

Endpoint Security

Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack...

Malware & Threats

At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.

Malware & Threats

The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.

Malware & Threats

CRPx0 is a complex, stealthy malware campaign that targets macOS and Windows systems, and appears to have Linux capabilities in development.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version