Categorie: Notizie

Hugging Face Used to Spread Android Malware

The Hugging Face platform, recognized as a fundamental pillar for the scientific community devoted to artificial intelligence and machine learning, has become the involuntary vector of a sophisticated malware campaign.

Although the platform is renowned for hosting language models, datasets and innovative applications in a collaborative and secure environment, recent investigations have revealed how malicious actors have begun to exploit its trusted infrastructure to distribute harmful payloads aimed at Android devices.

Android Malware Now Also Spreads via Hugging Face

The alert was raised by researchers at Bitdefender, who identified a sophisticated operation that leverages the impeccable reputation of Hugging Face to bypass security checks.

The attackers’ modus operandi starts far from the AI platform, through the distribution of a deceptive application named “TrustBastion“.

This software, classified as a dropper, paradoxically presents itself as a security tool, using aggressive and intimidating advertisements that warn the user of alleged infections on their device.

Playing on fear, the app convinces the victim to install what is presented as a critical update, graphically simulating the trusted Google Play Store interface to mask its true intentions.

It is at this crucial stage that the abuse of the platform comes into play. Instead of downloading the malicious code from unknown servers and potentially already listed on defense systems’ blacklists, the dropper contacts a repository hosted directly on Hugging Face.

This strategy provides criminals with a tactical advantage: data traffic coming from such a reputable and legitimate domain rarely triggers alarms from firewalls or network monitoring software.

To make detection and removal even harder, the malware developers have implemented a highly dynamic server-side polymorphism mechanism.

This technique generates a new virus variant roughly every fifteen minutes, making each download unique in terms of fingerprinting and effectively defying detections based on traditional static signatures. At the time of analysis, the repository contained thousands of variants accumulated in just a few weeks.

What can the new malware do?

Once infiltrated into the system, the malware reveals its predatory nature by exploiting Android Accessibility Services.

Obtaining these permissions through deceit, the software gains near-total control over the device: it can overlay windows on legitimate apps, record the device’s screen activity, and exfiltrate sensitive credentials.

The primary objective appears to be the theft of financial data, with a particular focus on widely used payment services such as Alipay and WeChat, as well as attempting to capture screen unlock codes.

The threat is persistent and resilient, as the malware code is programmed to monitor and actively block any uninstall attempts by the user.

Is Google Play Protect the solution?

Despite the report to Hugging Face leading to the removal of the incriminated datasets, the operators behind the campaign have demonstrated a notable ability to reorganize, reappearing later under new names, such as “Premium Club“, while keeping the underlying malicious code unchanged.

In response to these findings, Google has clarified its position, stating that no application containing this malware is present on the official Play Store.

A Mountain View spokesperson also confirmed that Google Play Protect is capable of recognizing and neutralizing these threats, protecting users even when installations come from external sources, reiterating the importance of avoiding downloads from unverified third-party stores.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

Do you still have a Nokia N8 in the drawer? It’s time to bring it back to life

Most users have long since archived the Symbian era, relegating those devices to forgotten boxes…

1 settimana ago

Honor Magic 9 Lite will make you forget about the charger, thanks to its colossal battery

The Chinese manufacturer has now shifted toward high-performance batteries, thanks to silicon-carbon technology. In just…

1 settimana ago

POCO X8 Pro and X8 Pro Max in first leaked images: launch is imminent

In the past few hours, an event was held in India to present the new…

1 settimana ago

Apple Takes a Step Back, No AI Coach in the Health App

The Cupertino giant has decided to pull the brakes on one of its most ambitious…

1 settimana ago

How much will POCO X8 Pro and X8 Pro Max cost in Europe: spoiler from the official site

The Lei Jun house hints at the price of the new smartphones in the POCO…

1 settimana ago

Apple is about to turn 50, Tim Cook announces an event: what to expect

On April 1, 1976, Steve Jobs, Steve Wozniak and Ronald Wayne founded what would become…

1 settimana ago