MENU

suburb

  • Loading ...
  • Loading ...

Child Care

Latest News Child Care

Are you looking for a holiday? Get special deals.

 

Android malware hidden in fake antivirus app

15 Feb 2026 By foxnews

Android malware hidden in fake antivirus app

If you use an Android phone, this deserves your attention. Right now, cybersecurity researchers warn that hackers are using Hugging Face, a popular platform for sharing artificial intelligence (AI) tools, to spread dangerous Android malware. At first, the threat appears harmless because it is disguised as a fake antivirus app. Then, once you install it, criminals gain direct access to your device. Because of this, the threat stands out as especially troubling. It combines two things people already trust: security apps and AI platforms.

Sign up for my FREE CyberGuy Report

Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter.

MALICIOUS GOOGLE CHROME EXTENSIONS HIJACK ACCOUNTS

For anyone unfamiliar, Hugging Face is an open platform where developers share AI, NLP and machine learning models. It is widely used by researchers and startups and has become a central hub for AI experimentation. That openness is also what attackers exploited. Because Hugging Face allows public repositories and supports many file types, criminals were able to host malicious code in plain sight.

The malware first appeared in an Android app called TrustBastion. On the surface, it looks like a helpful security tool. It promises virus protection, phishing defense and malware blocking. In reality, it does the opposite. 

Once installed, TrustBastion immediately claims your phone is infected. It then pressures you to install an update. That update delivers the malicious code. This tactic is known as scareware. It relies on panic and urgency to push users into tapping before thinking.

FAKE ERROR POPUPS ARE SPREADING MALWARE FAST

According to Bitdefender, a global cybersecurity company, the campaign centers on a fake Android security app called TrustBastion. Victims were likely shown ads or warnings claiming their device was infected and were instructed to manually install the app.

The attackers hosted TrustBastion's APK files directly on Hugging Face, placing them inside public datasets that appeared legitimate at first glance. Once installed, the app immediately prompted users to install a required "update," which delivered the actual malware.

After researchers reported the malicious repository, it was taken down. However, Bitdefender observed that nearly identical repositories quickly reappeared, with small cosmetic changes but the same malicious behavior. That rapid re-creation made the campaign harder to fully shut down.

This Trojan is not minor or annoying. It is invasive. Bitdefender says the malware can:

Take screenshots of your device

Show fake login screens for financial services

Capture your lock screen PIN

Once collected, that data is sent to a third-party server. From there, attackers can move quickly to drain accounts or lock you out of your own phone.

Google says users who stick to official app stores are protected. A Google spokesperson told CyberGuy, "Based on our current detection, no apps containing this malware are found on Google Play." 

The spokesperson added that "Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services." They also noted that "Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."

BROWSER EXTENSION MALWARE INFECTED 8.8M USERS IN DARKSPECTRE ATTACK

This threat is a reminder that small choices matter. Here is what you should do right now:

Only download apps from reputable sources like Google Play Store or the Samsung Galaxy Store. These platforms have moderation and scanning in place.

Look closely at ratings, download counts and recent comments. Fake security apps often have vague reviews or sudden rating spikes.

Even careful users can have personal data exposed. A data removal service helps remove your phone number, email and other details from data broker sites that criminals rely on. That reduces follow-up scams, fake security alerts and account takeover attempts.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren't cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It's what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com

Scan your device regularly with Play Protect and back it up with strong antivirus software for added protection. Google Play Protect, which is built-in malware protection for Android devices, automatically removes known malware. However, it is important to note that Google Play Protect may not be enough. Historically, it hasn't been 100% effective at removing all known malware from Android devices.

The best way to protect yourself against malicious links that install malware and potentially access your private information is to have strong antivirus software installed on all your devices. This protection can also help you detect phishing emails and ransomware, keeping your personal information and digital assets safe.

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Avoid installing apps from websites outside the app store. These apps bypass security checks, so always verify the publisher name and URL.

Your phone security depends on it. Enable two-step verification (2FA) first, then use a strong, unique password stored in a password manager to prevent account takeovers.

Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com

Be cautious with accessibility permissions. Malware often abuses them to take control of your device.

Malware can hide inside fake updates. Be cautious of urgent fixes that push you outside the app store.

This attack shows how quickly trust can be weaponized. A platform designed to advance AI research was repurposed as a delivery system for malware. A fake antivirus app became the threat it claimed to stop. Staying safe no longer means avoiding sketchy-looking apps. It means questioning even those apps that appear helpful and professional.

Have you seen something on your phone that made you question its security? Let us know your thoughts by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report 

Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide - free when you join my CYBERGUY.COM newsletter. 

Copyright 2026 CyberGuy.com.  All rights reserved.

More News

Booking.com
Health tech breach exposes 3.4M patient records
Health tech breach exposes 3.4M patient records
NYC schools track bathroom time with digital hall passes
NYC schools track bathroom time with digital hall passes
Fox News AI Newsletter: Palantir CTO warns US has only 'eight days of weapons' in hypothetical China battle
Fox News AI Newsletter: Palantir CTO warns US has only 'eight days of weapons' in hypothetical China battle
Americans warned of potential attacks at vacation destination as border crossing exit fee doubles
Americans warned of potential attacks at vacation destination as border crossing exit fee doubles
Cannonball 'very likely' fired in 1836 Battle of the Alamo found buried near church
Cannonball 'very likely' fired in 1836 Battle of the Alamo found buried near church
Abandoned bear cub, 'under arrest for cuteness,' grabbed by state troopers from interstate highway
Abandoned bear cub, 'under arrest for cuteness,' grabbed by state troopers from interstate highway
Illegal immigrant, accomplice get 5 years for murder in sweetheart deal with progressive Virginia DA
Illegal immigrant, accomplice get 5 years for murder in sweetheart deal with progressive Virginia DA
Homan vows immigration mission 'won't skip a beat' as Bondi exits DOJ
Homan vows immigration mission 'won't skip a beat' as Bondi exits DOJ
Walmart employee fatally stabbed in random attack by man who allegedly believed victim was a 'demon': police
Walmart employee fatally stabbed in random attack by man who allegedly believed victim was a 'demon': police
Common drinking habit may quietly triple risk of advanced liver condition
Common drinking habit may quietly triple risk of advanced liver condition
Former Syracuse basketball player to be deported after spending weeks in ICE custody
Former Syracuse basketball player to be deported after spending weeks in ICE custody
Iran, proxy militias threaten US universities in Lebanon as Americans urged to flee now
Iran, proxy militias threaten US universities in Lebanon as Americans urged to flee now
Save Women's Sports activists thank Pam Bondi for Title IX enforcement after her departure from DOJ
Save Women's Sports activists thank Pam Bondi for Title IX enforcement after her departure from DOJ
Flight passengers are paying strangers to stand in long TSA lines as chaos drags on
Flight passengers are paying strangers to stand in long TSA lines as chaos drags on
Dementia may be signaled by common condition years before symptoms
Dementia may be signaled by common condition years before symptoms
Jamie Lee Curtis blasts Hollywood 'fakery,' says plastic surgery made her feel 'fraudulent'
Jamie Lee Curtis blasts Hollywood 'fakery,' says plastic surgery made her feel 'fraudulent'
Parents of MacDill bomb suspects are illegal immigrants, DHS warns of birthright citizenship dangers
Parents of MacDill bomb suspects are illegal immigrants, DHS warns of birthright citizenship dangers
Truth about Arizona girl found alive decades after vanishing leaves investigator 'dumbfounded': report
Truth about Arizona girl found alive decades after vanishing leaves investigator 'dumbfounded': report
Newsom office called out for skipping Biden in post missing Obama as past president with 'functioning brain'
Newsom office called out for skipping Biden in post missing Obama as past president with 'functioning brain'
Dem Senator warns of NFL Draft security risks amid Iran war in letter to DHS
Dem Senator warns of NFL Draft security risks amid Iran war in letter to DHS
Latest News

copyright © 2026 Child Care.   All rights reserved.

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z