
Attackers Abuse Hugging Face to Deliver Polymorphic Android RATs That Evade Traditional Defenses
Threat actors are increasingly exploiting trusted developer platforms as malware distribution infrastructure. In a newly uncovered campaign, attackers hijacked Hugging Face repositories to host and deliver Android Remote Access Trojans (RATs)—bypassing conventional detection mechanisms and abusing Android Accessibility Services to gain deep device control.
The campaign demonstrates a dangerous convergence of social engineering, cloud trust abuse, and server-side polymorphism, allowing malware to spread at scale while evading hash-based defenses.
🎯 Initial Lure: Fake Security Apps
The operation targets Android users through a malicious dropper application named TrustBastion, promoted via deceptive advertisements claiming to:
Detect scams
Identify phishing attempts
Protect devices from malware
Once installed manually, the app presents users with a fake update prompt designed to closely resemble legitimate Google Play dialogs. Accepting the update initiates the real compromise.
🔗 Two-Stage Infection Chain Using Hugging Face
Stage One: Trusted Redirection
The dropper contacts attacker-controlled infrastructure (trustbastion[.]com), which immediately redirects victims to Hugging Face-hosted datasets containing malicious APK files.
Payloads are delivered via Hugging Face’s CDN, allowing attackers to:
Leverage a trusted domain
Bypass basic URL reputation checks
Avoid scrutiny typically applied to unknown hosting providers
Stage Two: Server-Side Polymorphism
Attackers generate new APK payloads every 15 minutes, preserving behavior while continuously changing file hashes.
Researchers observed:
Over 6,000 repository commits in under a month
Constant mutation that defeats signature-based antivirus tools
Successful evasion of static scanners despite basic malware checks
This approach turns Hugging Face into an unintentional malware-as-a-service delivery layer.
🕵️ Advanced Surveillance via Accessibility Abuse
Once installed, the Android RAT requests Accessibility Services under the guise of “Phone Security.”
Granting this permission enables:
Screen recording and real-time monitoring
Overlay attacks to capture credentials
Remote interaction with apps and system UI
The malware deploys fake login interfaces impersonating platforms like Alipay and WeChat, harvesting credentials and sensitive lock-screen data.
Data is exfiltrated to a centralized command-and-control server, which also handles:
Live command execution
Configuration updates
Persistence keep-alive signals
Even after takedown, the attackers rapidly re-emerged under a new brand name (“Premium Club”) using the same codebase with modified icons and metadata.
🧠 Why This Campaign Matters
This operation highlights a critical shift in attacker strategy:
Trusted platforms are now part of the attack surface.
Key risks include:
Abuse of reputable ML and developer platforms
Cloud-hosted malware delivery
Polymorphic payloads that invalidate hash-based defenses
Accessibility Services as a persistent high-risk permission
Bitdefender confirmed detection only through behavioral analysis, underscoring the limits of static and signature-driven security models.
🛡️ The Elliptic Systems Perspective
At Elliptic Systems, we consistently see attackers moving “up the trust stack” — hiding inside platforms defenders hesitate to block.
To reduce risk, organizations and users should:
Treat “security” apps outside official stores as high-risk
Restrict and audit Accessibility Service permissions
Deploy behavior-based mobile security solutions
Monitor trusted cloud platforms for abnormal activity patterns
👉 Schedule a Mobile & Cloud Threat Assessment
⚠️ Final Takeaway
This campaign proves that malware no longer needs shady infrastructure.
By abusing Hugging Face’s reputation, attackers delivered powerful Android RATs at scale — silently, rapidly, and repeatedly.
Defending against modern mobile threats requires:
Behavioral visibility
Permission discipline
A healthy skepticism of “trusted” platforms
Elliptic Systems — Securing What Attackers Hide Behind Trust.
