Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityphishing-campaign-intelligenceremote-access-implantfinancial-sector-threat

Android Malware and Spyware Campaigns Using Trusted Platforms and Social Engineering Lures

Updated 3mo agoFirst seen Jan 30, 20266 sources

Two separate Android-focused threat operations were reported, both relying on social engineering to drive manual installation of malicious apps. Bitdefender documented a campaign that abuses Hugging Face as a trusted hosting/CDN distribution point for an Android credential-stealing payload targeting popular financial and payment services. Victims are lured into installing a dropper app named TrustBastion via scareware-style ads; after installation it displays a fake Google Play “mandatory update” flow, then contacts infrastructure associated with trustbastion[.]com which redirects to a Hugging Face dataset repository hosting the final APK. The actor used server-side polymorphism to generate new payload variants roughly every 15 minutes, resulting in thousands of variants and rapid repository churn (reported as >6,000 commits over ~29 days); after takedown, the operation reportedly resurfaced under a new name (“Premium Club”) with refreshed branding.

ESET separately identified an Android spyware campaign tracked as GhostChat that uses romance-scam tactics to target individuals in Pakistan. The malicious app is disguised as a chat/dating service but primarily functions as a surveillance tool; it presents “locked” female profiles with passcodes (hardcoded in the app) to create a sense of exclusivity, then routes victims into WhatsApp chats tied to Pakistani numbers likely controlled by the operator. The app was distributed via unofficial sources (not Google Play) and is blocked by Google Play Protect by default; ESET also linked the same actor to a broader surveillance effort including a ClickFix compromise chain and a WhatsApp device-linking attack, using websites impersonating Pakistani government organizations as lures.

Share:
Android Malware and Spyware Campaigns Using Trusted Platforms and Social Engineering Lures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 29, 20265mo ago

Hugging Face removes malicious Android malware datasets

After being notified by Bitdefender, Hugging Face removed the malicious datasets used by the TrustBastion/Premium Club Android malware campaign. Despite the takedown, researchers said the operators continued attempting to re-establish their hosting infrastructure.

Bitdefender discloses Hugging Face-hosted Android RAT campaign

Bitdefender reported a large-scale Android malware campaign abusing Hugging Face as a trusted hosting platform to distribute polymorphic RAT payloads aimed at stealing credentials, especially in the Asia-Pacific region. The malware used fake update prompts, Accessibility Services abuse, phishing overlays for apps such as Alipay and WeChat, and lock-screen credential theft.

ESET links GhostChat to broader surveillance operations

ESET assessed that the same threat actor behind GhostChat also conducted related operations including ClickFix-based desktop compromises and a WhatsApp device-linking attack dubbed GhostPairing. These campaigns used websites impersonating Pakistani government organizations and QR-code lures, including a fake channel claiming ties to Pakistan's Ministry of Defence.

ESET uncovers GhostChat Android spyware campaign targeting Pakistan

ESET researchers reported an Android spyware campaign in Pakistan in which victims are lured through romance-scam social engineering into manually installing a malicious app called GhostChat from unofficial sources. The spyware routes chats through WhatsApp, monitors device activity, and exfiltrates images, documents, and other sensitive data to a command-and-control server.

Dec 31, 20256mo ago

TrustBastion repository disappears and campaign rebrands as Premium Club

After the TrustBastion repository was removed in late December 2025, the same Android malware operation resurfaced under the new app or repository name "Premium Club" while reusing the same codebase and tactics. Reports indicate the attackers continued rebuilding infrastructure after takedowns.

Nov 30, 20257mo ago

TrustBastion malware repository operates on Hugging Face

Bitdefender observed a Hugging Face dataset repository used to deliver Android RAT payloads that was about 29 days old and had accumulated more than 6,000 commits, with new polymorphic APK variants generated roughly every 15 minutes. The campaign used a fake security app called TrustBastion and scareware-style lures to push victims toward sideloading malware.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
AndroidWechat
Organizations
7 linked
Alibaba CloudHugging FaceBitdefenderGoogleWeChatTencentRescana
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Android Malware and Spyware Campaigns Using Trusted Platforms and Social Engineering Lures | Mallory