TrustBastion Android RAT distributes malicious APKs through Hugging Face repositories
Malware Activity
Summary
Hide ▲
Show ▼
The TrustBastion Android RAT now uses Hugging Face repositories to distribute malicious APKs, making the operation harder to flag while broadening risk for Android users. The infection starts with scareware popups and a fake Google Play or Android system update flow. After installation, the payload abuses Accessibility Services, screen recording, screen casting, and overlays to watch device activity and steal credentials. The repository also shows rapid payload churn and the operation appears to have infected thousands of victims.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware Activity
H score69
First: 11.05.2026 10:05
Last: 11.05.2026 10:05
Sources 1
About this happening:
A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Open-OSS/privacy-filter Hugging Face infostealer activity
Malware ActivityAbout this happening: A malicious Hugging Face repository called Open-OSS/privacy-filter impersonated OpenAI's Privacy Filter and delivered a Rust-based information stealer to Windows...
Sefirah infostealer delivered through a malicious Hugging Face repository
Malware Activity
H score16
First: 09.05.2026 17:26
Last: 09.05.2026 17:26
Sources 1
About this happening:
A malicious Hugging Face repository impersonated OpenAI’s Privacy Filter and delivered sefirah, a Rust-based infostealer, to Windows users, creating credential...
Sefirah infostealer delivered through a malicious Hugging Face repository
Malware ActivityAbout this happening: A malicious Hugging Face repository impersonated OpenAI’s Privacy Filter and delivered sefirah, a Rust-based infostealer, to Windows users, creating credential...
CloudZ RAT Pheno Microsoft Phone Link credential-theft activity
Malware Activity
H score24
First: 05.05.2026 13:03
Last: 05.05.2026 13:03
Sources 1
About this happening:
The CloudZ RAT is now using the Pheno plugin to hijack Microsoft Phone Link sessions and steal SMS-based OTPs and other sensitive codes, increasing the risk of acc...
CloudZ RAT Pheno Microsoft Phone Link credential-theft activity
Malware ActivityAbout this happening: The CloudZ RAT is now using the Pheno plugin to hijack Microsoft Phone Link sessions and steal SMS-based OTPs and other sensitive codes, increasing the risk of acc...
NGate malware trojanized HandyPay NFC-stealing variant
Malware Activity
H score34
First: 21.04.2026 12:00
Last: 21.04.2026 12:00
Sources 1
About this happening:
A new NGate variant is stealing NFC payment data from Android users in Brazil, raising the risk of unauthorized purchases and ATM cash withdrawals. The malware...
NGate malware trojanized HandyPay NFC-stealing variant
Malware ActivityAbout this happening: A new NGate variant is stealing NFC payment data from Android users in Brazil, raising the risk of unauthorized purchases and ATM cash withdrawals. The malware...
Timeline
-
02.02.2026 12:30 2 articles · 5mo ago
Bitdefender discloses TrustBastion distribution via Hugging Face
Initial DisclosureBitdefender disclosed that the TrustBastion Android RAT used Hugging Face repositories to host and distribute malicious APKs, with victims first seeing scareware popups and fake Google Play and Android system update dialogs before a redirect from trustbastion[.]com delivered the payload. The malware then abused Accessibility Services, screen recording, screen casting, and overlay permissions to monitor device activity, steal credentials from apps such as Alipay and WeChat, and capture lockscreen verification information. Bitdefender also said the repository had more than 6000 commits, was generating new payloads roughly every 15 minutes, and that the campaign appears to have infected thousands of victims.
Show sources
- Android RAT Uses Hugging Face to Host Malware — www.infosecurity-magazine.com — 02.02.2026 12:30
- Android RAT Uses Hugging Face to Host Malware — www.infosecurity-magazine.com — 02.02.2026 12:30