Back Issues This Week → Current Issue → Popular →

All issuesVolume 334, Issue 4IT Vendor NewsBitdefender

Android Trojan Campaign Uses Hugging Face Hosting For RAT Payload Delivery

Bitdefender, Thursday, January 29th, 2026

What makes this campaign particularly interesting is the attackers' use of Hugging Face to host malicious payloads, and the scale at which new samples are deployed.

Hugging Face is a widely used online hosting service that provides a home to machine learning models and gives users a place to host their open-source models, datasets, and other development tools that researchers and developers usually need.

Unfortunately, the space Hugging Face offers can also be used by cybercriminals for malicious purposes as the platform doesn't seem to have meaningful filters that govern what people can upload. They say all uploads are scanned with ClamAV, which is an open-source antivirus engine.

more →  ·  More from Bitdefender →