A particularly sophisticated Android malware campaign highlights the new risks posed by the misuse of trusted cloud platforms. According to researchers Bitdefender, cybercriminals have abused Hugging Face — one of the most popular AI tool hosting platforms — to distribute thousands of variants of malicious Android apps.

The campaign's main goal was to steal login credentials from financial services and digital payment, turning victims' devices into fully controlled spying tools.
Why Hugging Face was chosen
Hugging Face is a central hub for AI developers and researchers, hosting machine learning models, datasets, and applications related to NLP and generative AI. Its reputation as a legitimate and secure platform makes it detection mechanisms malicious activity.
See also: 175,000 publicly exposed Ollama AI servers in 130 countries
It is precisely this reliability that appears to have been exploited by attackers, who in the past have used similar cloud platforms to host malicious content without immediately arousing suspicion.
The beginning of the attack: Scareware and deception
The infection begins when users are convinced to install a dropper app called TrustBastion. The app uses scareware-style ads, which falsely warn that the device is infected or being monitored.
TrustBastion is presented as a cybersecurity tool, promising protection against scams, phishing attacks, malicious SMS and dangerous applications. The user interface is designed to inspire trust and mimic well-known security applications.

Fake updates and malicious APKs from CDN
Immediately after installation, a mandatory “update” notification appears, with graphics similar to those of Google Play. However, instead of a legitimate update, the application communicates with a server associated with the domain trustbastion[.]com.
See also: Sicarii ransomware: Locks data and “throws away the keys”
The server redirects the victim to the Hugging Face dataset repository, from where the final malicious APK is downloaded via the platform's official CDN — a technique that makes it significantly more difficult to detect by antivirus and network filters.
Thousands of variations to avoid detection
To keep a low profile, the campaign uses server-side polymorphism. According to Bitdefender, new variants of the malicious payload were created every 15 minutes.
At the time of the research, the repository at Hugging Face was active for 29 days, but contained over 6,000 modifications, which shows the intensity and automation of the operation.
When the original repository was removed, the activity resurfaced with a new name — “Premium Club” — and different icons, but retaining the same malicious core.
Full control of the device via Accessibility Services
The final payload is a powerful tool remote access (RAT) that abuses Accessibility Services . The malware presents the access request as necessary for security reasons, ultimately gaining extensive privileges.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Among other things, it can:
- displays screen overlays
- records the screen in real time
- blocks uninstallation
- records user actions
- steals the device lock code
At the same time, it displays fake login screens that mimic services like Alipay and WeChat, extracting banking information and credentials.
See also: ShinyHunters: New vishing campaign with hundreds of targets

Constant communication with attackers
The malware maintains a permanent connection to a command and control (C2) server, through which stolen data, new commands are received, and operating settings are updated. In addition, the C2 promotes fake content to make the application appear functional and legitimate.
Safety response and recommendations
Bitdefender has updated Hugging Face, which immediately removed the malicious datasets, and published indicators of compromise (IOCs) to identify the threat.
Experts warn that Android users should avoid apps from third-party stores or manual APK installations and carefully review the permissions each app requests.
The case clearly demonstrates that even highly trusted platforms can be turned into tools for cybercrime, confirming that security in the era of the cloud and artificial intelligence is now everyone's shared responsibility.
Source: www.bleepingcomputer.com
