Hugging Face Misused for Android Malware and RAT Campaigns

Hugging Face Misused for Android Malware and RAT Campaigns

First seen 30 Jan 2026, 02:44 UTC ClickondetroitBitdefenderBleepingcomputerTechzine.EuCsoonline+8 37.6

Article Content

Browse articles
ThreatCluster

A new Android malware campaign has exploited the Hugging Face platform to distribute thousands of APK variants that collect credentials for financial services. Researchers from Bitdefender have identified this campaign as utilizing remote access trojans (RAT) and social engineering techniques, leveraging Hugging Face's reputation as a trusted hosting service to deliver malicious payloads at scale.