Bleepingcomputer
Hugging Face Misused for Android Malware and RAT Campaigns
First seen 30 Jan 2026, 02:44 UTC
•



+8
•37.6
Export
Article Content
Browse articles
A new Android malware campaign has exploited the Hugging Face platform to distribute thousands of APK variants that collect credentials for financial services. Researchers from Bitdefender have identified this campaign as utilizing remote access trojans (RAT) and social engineering techniques, leveraging Hugging Face's reputation as a trusted hosting service to deliver malicious payloads at scale.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Google Fixes 107 Security Flaws in Android Update
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Apple Alerts Users of Targeted Mercenary Spyware Attacks in 110 Countries