01/06/2026
Do you use an Android phone for work? 📱
Security researchers have uncovered a new piece of Android malware that can track almost everything you do on it.
And I don’t mean basic tracking.
We’re talking:
👉 PIN entries
👉 Login credentials
👉 Messages
👉 Banking app activity
The clever (and worrying) part is how it spreads 🦠
The app is called TrustBastion.
It pretends to be a security tool. Victims see pop-ups or adverts claiming their phone is infected with malware or scam messages.
The “solution”? Install this app to clean things up.
That fear tactic works more often than you’d think 😱
At first glance, the app looks harmless. But it’s what’s known as a dropper.
That means the app itself doesn’t contain the malicious code straight away. Instead, it downloads it after installation.
Once installed, it shows a fake “update” screen that looks very similar to official Android or Google Play messages.
If you agree, a manipulated APK file (that’s the installation package format Android uses) is downloaded in the background.
But the download doesn’t come from some obviously shady server. It comes from Hugging Face, a well-known developer and AI platform with a strong reputation.
The infrastructure looks legitimate, so many security tools don’t immediately flag it as suspicious. The attackers hide behind a trusted name.
After installation, the malware requests extensive permissions and pretends to be a system component called “Phone Security”.
It then asks for Accessibility permissions.
Accessibility features are designed to help users with disabilities. But when misused, they give apps the ability to read what’s on your screen, log what you type, and overlay content on top of other apps.
That means this malware can:
⚠️ Capture PIN codes and unlock patterns
⚠️ Overlay fake login screens on top of real banking apps
⚠️ Intercept payment details and messages
The stolen data is sent back to the attackers’ servers, and the malware can even receive updates or new instructions.
To make detection harder, the criminals are using something called server-side polymorphism.
That means they generate slightly modified versions of the malware every 15 minutes.
Within a month, researchers found more than 6,000 variants.
Traditional antivirus tools often look for known “signatures”. If the file keeps changing slightly, it’s harder to block.
So, what should you take from this?
First: Only install apps from the Google Play Store.
Second: Be extremely cautious of apps that claim to clean or secure your phone while asking for deep system permissions.
Third: Only enable Accessibility access if you fully understand why the app needs it.
And don’t assume that because something’s hosted on a reputable platform, it’s automatically safe.
If your business lets staff access email, banking or cloud systems from their phones, mobile security is vital.
🤔 When was the last time you reviewed what apps are installed on your company devices?