The infection chain starts with a seemingly innocent Android app called TrustBastion. The accompanying screen closely mimics the appearance of Google Play and Android system updates, which increases its credibility. When the user agrees, the app contacts a server that does not deliver malware and instead redirects to a dataset repository on Hugging Face. Analysis of the repository used shows that the attackers are applying server-side polymorphism on a large scale. Malware pretends to be a system componentAfter the second phase is installed, the malware masquerades as a system or security component.