A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services, according to a recent report by Bleeping Computer.The campaign begins with users being tricked into installing a dropper app named TrustBastion, which masquerades as a security tool. This app then prompts users for a mandatory update, which redirects to a Hugging Face dataset repository hosting the malicious APK. The final payload is downloaded via Hugging Face's content distribution network. To evade detection, the threat actor employs server-side polymorphism, generating new payload variants every 15 minutes. The malware exploits Android's Accessibility Services to capture screenshots, steal credentials through fake login interfaces for services like Alipay and WeChat, and exfiltrate data to its command-and-control server. It also attempts to steal lock screen codes and block uninstallation.This incident highlights the evolving tactics of threat actors who leverage trusted platforms like Hugging Face for malicious purposes. It underscores the importance of user vigilance in downloading applications and reviewing requested permissions.Source: Bleeping Computer




