Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Hugging Face Abused to Deploy Android RAT
    Cybersecurity

    Hugging Face Abused to Deploy Android RAT

    adminBy adminJanuary 31, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hugging Face hack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Hugging Face infrastructure has been abused for the delivery of an Android remote access trojan (RAT), Bitdefender reports.

    The attack chain starts with an ad or a prompt to download and install a security application claiming to provide multiple useful features.

    The application, called TrustBastion, acts as a dropper and immediately after launch prompts the user to fetch an update, displaying legitimate-looking Google Play and Android system update dialogs.

    Once the user agrees, the dropper connects to an encrypted endpoint hosted at trustbastion[.]com, which serves an HTML page that points to a Hugging Face repository, and then downloads a malicious payload from the online platform’s datasets.

    According to Bitdefender, the Hugging Face repository used in the attack was roughly a month-old when taken offline and had over 6,000 commits. New payloads were being generated roughly every 15 minutes, the cybersecurity firm says.

    “The repository eventually went offline, but only for the entire operation to move to another link, with the project using different icons and some minor adjustments. The code remained the same,” Bitdefender explains.

    Advertisement. Scroll to continue reading.

    After installation, the malicious payload requested broad permissions, pretending to be a security feature, and guided the user to enable Accessibility Services to monitor their actions.

    It also requested permissions to record the screen, perform screen casting, and display overlays, enabling it to observe, capture, and modify on-screen content in real time.

    Once permissions are enabled, the malware can control infected devices and exfiltrate screen content to the command-and-control (C&C) server.

    “The malware also displays fraudulent authentication interfaces designed to harvest sensitive credentials. It tries to impersonate popular financial and payment services, including Alipay and WeChat,” Bitdefender says.

    Additionally, the malware could capture lock screen information and authentication actions, and was seen maintaining persistent communication with the C&C and downloading webviews to mimic legitimate functionality.

    “This infrastructure is used to receive commands, transmit stolen data and deliver updated configuration information to infected devices. The same infrastructure also facilitates payload redirection by serving Hugging Face download links to the initial dropper,” Bitdefender says.

    Soon after the repository hosting TrustBastion disappeared at the end of December, another repository emerged, hosting Premium Club, a seemingly different app that has the same underlying code. Hugging Face took down the datasets serving the malware, Bitdefender says.

    Related: Kimwolf Android Botnet Grows Through Residential Proxy Networks

    Related: New $150 Cellik RAT Grants Android Control, Trojanizes Google Play Apps

    Related: New Albiriox Android Malware Developed by Russian Cybercriminals

    Related: Landfall Android Spyware Targeted Samsung Phones via Zero-Day

    abused Android Deploy Face Hugging RAT
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWordPress Announces AI Agent Skill For Speeding Up Development
    Next Article Today is your last chance to get the Xreal One Pro at its pre-tariff price before it rises again on Feb 1st!
    admin
    • Website

    Related Posts

    Social media bans might steer kids into riskier corners of the internet

    April 19, 2026

    Vercel confirms breach as hackers claim to be selling stolen data

    April 19, 2026

    Google TV Home (Android TV) 1.0.900391771 APK Download by Google LLC

    April 19, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Here’s How Netflix Plans to Add TikTok-Style Videos to Its Mobile App

    April 19, 2026

    Social media bans might steer kids into riskier corners of the internet

    April 19, 2026

    eSIM was supposed to replace SIM cards, but carriers turned it into a trap

    April 19, 2026

    Vercel confirms breach as hackers claim to be selling stolen data

    April 19, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,402)
    • Privacy & Online Earning (172)
    • SEO & Digital Marketing (850)
    • Tech Tools & Mobile / Apps (1,679)
    • WiFi / Internet & Networking (232)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Here’s How Netflix Plans to Add TikTok-Style Videos to Its Mobile App

    April 19, 2026

    Social media bans might steer kids into riskier corners of the internet

    April 19, 2026

    eSIM was supposed to replace SIM cards, but carriers turned it into a trap

    April 19, 2026
    Most Popular
    • Here’s How Netflix Plans to Add TikTok-Style Videos to Its Mobile App
    • Social media bans might steer kids into riskier corners of the internet
    • eSIM was supposed to replace SIM cards, but carriers turned it into a trap
    • Vercel confirms breach as hackers claim to be selling stolen data
    • I used a simple Linux command to watch what apps do to my files in real time
    • Google TV Home (Android TV) 1.0.900391771 APK Download by Google LLC
    • The “most stylish” Galaxy Watch 8 Classic is 31% off at Amazon right now
    • Apple AirTag tracking can be misled by replayed Bluetooth signals
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.