Technology
Android malware hidden in fake antivirus app
NEWYou can now listen to Fox News articles!
If you use an Android phone, this deserves your attention.
Cybersecurity researchers warn that hackers are using Hugging Face, a popular platform for sharing artificial intelligence (AI) tools, to spread dangerous Android malware.
At first, the threat appears harmless because it is disguised as a fake antivirus app. Then, once you install it, criminals gain direct access to your device. Because of this, the threat stands out as especially troubling. It combines two things people already trust — security apps and AI platforms.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
MALICIOUS GOOGLE CHROME EXTENSIONS HIJACK ACCOUNTS
Researchers say hackers hid Android malware inside a fake antivirus app that looked legitimate at first glance. (Kurt “CyberGuy” Knutsson)
What Hugging Face is and why it matters
For anyone unfamiliar, Hugging Face is an open platform where developers share AI, NLP and machine learning models. It is widely used by researchers and startups and has become a central hub for AI experimentation. That openness is also what attackers exploited. Because Hugging Face allows public repositories and supports many file types, criminals were able to host malicious code in plain sight.
The fake antivirus app behind the attack
The malware first appeared in an Android app called TrustBastion. On the surface, it looks like a helpful security tool. It promises virus protection, phishing defense and malware blocking. In reality, it does the opposite.
Once installed, TrustBastion immediately claims your phone is infected. It then pressures you to install an update. That update delivers the malicious code. This tactic is known as scareware. It relies on panic and urgency to push users into tapping before thinking.
FAKE ERROR POPUPS ARE SPREADING MALWARE FAST
The fake TrustBastion app mimics a legitimate Google Play update screen to trick users into installing malware. (Bitdefender)
How the malware spreads and adapts
According to Bitdefender, a global cybersecurity company, the campaign centers on a fake Android security app called TrustBastion. Victims were likely shown ads or warnings claiming their device was infected and were instructed to manually install the app.
The attackers hosted TrustBastion’s APK files directly on Hugging Face, placing them inside public datasets that appeared legitimate at first glance. Once installed, the app immediately prompted users to install a required “update,” which delivered the actual malware.
After researchers reported the malicious repository, it was taken down. However, Bitdefender observed that nearly identical repositories quickly reappeared, with small cosmetic changes but the same malicious behavior. That rapid re-creation made the campaign harder to fully shut down.
What this Android malware can actually do
This Trojan is not minor or annoying. It is invasive. Bitdefender says the malware can:
Take screenshots of your device
Show fake login screens for financial services
Capture your lock screen PIN
Once collected, that data is sent to a third-party server. From there, attackers can move quickly to drain accounts or lock you out of your own phone.
What Google says about the threat
Google says users who stick to official app stores are protected. A Google spokesperson told CyberGuy, “Based on our current detection, no apps containing this malware are found on Google Play.
“Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services.
“Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play.”
BROWSER EXTENSION MALWARE INFECTED 8.8M USERS IN DARKSPECTRE ATTACK
Once installed, the malware could capture screenshots, fake login details and even your lock screen PIN. (Kurt “CyberGuy” Knutsson)
How to stay safe from Hugging Face Android malware
This threat is a reminder that small choices matter. Here is what you should do right now:
1) Stick to trusted app stores
Only download apps from reputable sources like Google Play Store or the Samsung Galaxy Store. These platforms have moderation and scanning in place.
2) Read reviews before installing
Look closely at ratings, download counts and recent comments. Fake security apps often have vague reviews or sudden rating spikes.
3) Use a data removal service
Even careful users can have personal data exposed. A data removal service helps remove your phone number, email and other details from data broker sites that criminals rely on. That reduces follow-up scams, fake security alerts and account takeover attempts.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy.
These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com
4) Run Play Protect and use strong antivirus software
Scan your device regularly with Play Protect and back it up with strong antivirus software for added protection. Google Play Protect, which is built-in malware protection for Android devices, automatically removes known malware. However, it is important to note that Google Play Protect may not be enough. Historically, it hasn’t been 100% effective at removing all known malware from Android devices.
The best way to protect yourself against malicious links that install malware and potentially access your private information is to have strong antivirus software installed on all your devices. This protection can also help you detect phishing emails and ransomware, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com
5) Avoid sideloading APK files
Avoid installing apps from websites outside the app store. These apps bypass security checks, so always verify the publisher name and URL.
6) Lock down your Google account
Your phone security depends on it. Enable two-step verification (2FA) first, then use a strong, unique password stored in a password manager to prevent account takeovers.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
7) Be cautious with permissions
Be cautious with accessibility permissions. Malware often abuses them to take control of your device.
8) Watch app updates closely
Malware can hide inside fake updates. Be cautious of urgent fixes that push you outside the app store.
Kurt’s key takeaways
This attack shows how quickly trust can be weaponized. A platform designed to advance AI research was repurposed as a delivery system for malware. A fake antivirus app became the threat it claimed to stop. Staying safe no longer means avoiding sketchy-looking apps. It means questioning even those apps that appear helpful and professional.
Have you seen something on your phone that made you question its security? Let us know your thoughts by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Google Chrome is coming to Arm-powered Linux devices later this year
Why Arm + Linux now? In a blog post, Google only says that it “addresses the growing demand for a browsing experience that combines the benefits of the open-source Chromium project with the Google ecosystem of apps and features.” What we’re left wondering is whether Google’s talking about existing demand, or demand yet to come.
There’s certainly a growing demand for Linux. Some Verge editors have begun to ditch Windows with varying degrees of success. But those are our x86 desktops — there isn’t a lot of consumer-facing Linux on Arm chips, unless you count all the Linux-based Android phones out there. You can buy Linux on laptops from Dell, Lenovo, Framework, and such, but again, they use x86 chips. (And if you’re not a consumer, there’s already Chromium.)
But three of the companies that actually build Arm processors — Qualcomm, Nvidia, and Mediatek — may look to Linux as they try to compete with the Windows/Intel/AMD incumbents. Qualcomm told me in January that it sees “a lot of interest on other operating systems” beyond Windows for its PC-grade Arm chips. Nvidia could reveal its N1 and N1X processors for Arm laptops as soon as next week at its GTC 2026 developer conference.
While those Nvidia laptops might get announced with Windows, it wouldn’t be surprising if they targeted Linux too, once the basics like Chrome are sorted out. Google’s blog post specifically namedrops Nvidia’s DGX Spark as a target for Chrome — those $4,000+ beefy micro AI desktops, sold by a wide array of the company’s partners, also run Linux on Arm. Google says it’s putting Chrome into Nvidia’s package manager to make installation easier; everyone else will have to go to chrome.com/download when the browser arrives in Q2.
Technology
Tax scams through the years and what to know this year
NEWYou can now listen to Fox News articles!
Tax scams rarely stay the same for long. Each filing season brings new tactics designed to trick taxpayers into revealing personal information or claiming refunds they are not entitled to receive. In recent years, fraud tied to unemployment systems, stimulus payments and identity theft caught many taxpayers by surprise. Some people did not discover the problem until their legitimate tax return was rejected, or unexpected tax forms arrived in the mail.
Two years later, promoters marketed confusing credits such as the Employee Retention Credit to businesses that did not qualify, collecting fees to file improper claims. By 2025, misleading guidance spread widely on social media, encouraging taxpayers to misuse forms like 4136 or modify wage information through consumer tax software.
Each of these scams relies on confusion around tax rules and filing systems. Understanding how they work can help you spot red flags before submitting your return this year.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
IRS WARNS TAXPAYERS OF NEW MAILING REFUND SCAM
Tax scams have evolved from unemployment fraud to social media “tax hacks,” with the IRS warning of new threats for the 2026 filing season. (Michael Bocchieri/Getty Images)
2021 tax scams: Unemployment fraud and stimulus payment theft
In 2021, identity theft linked to unemployment programs created widespread tax problems. Criminals used stolen Social Security numbers to file benefit claims through state systems. Because unemployment income is taxable, Form 1099-G notices were sent to victims for payments they never received. The IRS advised taxpayers not to report fraudulent income and to contact the issuing state agency to correct the records.
Stimulus payments were also targeted. Scammers filed early tax returns using stolen personal data to claim Recovery Rebate Credits or redirect refunds. When legitimate filers later submitted their returns, some were rejected because a return tied to their Social Security number had already been processed. Federal agencies, including the FBI, warned of high levels of unemployment fraud during this period. The IRS also encouraged taxpayers to sign up for an Identity Protection PIN, which adds an extra layer of verification when filing.
Worried your SSN may have been stolen? Many tax fraud cases begin with data pulled from breaches. You can run a free scan with our top Identity Theft Protection pick to check whether your information appears in known data-leak records. The scan looks for matches tied to your email address and shows the results in real time. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com.
2023 tax scam warning: Ghost preparers filing fraudulent returns
The IRS later flagged a rise in returns prepared by so-called ghost preparers. These individuals charge fees to prepare tax returns but refuse to sign them or include a valid Preparer Tax Identification Number. Under federal tax rules, anyone paid to prepare a return must sign it. When a preparer does not, the taxpayer, not the preparer, remains responsible for the filing.
In many flagged cases, ghost preparers inflated tax credits, fabricated income figures or altered withholding amounts to generate larger refunds. Some charged fees based on the size of the refund, which created an incentive to push questionable claims rather than follow tax rules.
2025 tax scams: Social media tax ‘hacks’ and improper filings
By 2025, misleading tax advice began circulating widely on short-form video platforms and social media. Some posts encouraged people to file Form 4136 to claim a fuel tax credit for gasoline used in personal vehicles. The IRS says this credit applies only to certain business and off-highway uses, not everyday driving. Filing the form improperly can trigger an IRS review.
Other posts instructed taxpayers to modify wage or withholding numbers inside consumer tax software to inflate refund amounts. The IRS has repeatedly warned that taxpayers remain responsible for the accuracy of their returns, regardless of where the advice originated. Filing incorrect income information or claiming unsupported credits can delay refunds and potentially lead to penalties.
ELON MUSK ALLEGES $50B IN FRAUD AT TREASURY AFTER JUDGE BLOCKS DOGE AUDIT
Identity theft and fraudulent tax filings remain top concerns for the Internal Revenue Service as criminals exploit confusion around credits and filing rules. (Andrew Harrer/Bloomberg via Getty Images)
2026 IRS warning: Tax scams expected this filing season
The IRS recently released its 2026 “Dirty Dozen” list of tax scams it expects to circulate during the filing season. Phishing and text message scams remain among the most common threats. Scammers often impersonate the IRS or tax software companies and claim there is a refund issue or account problem in an attempt to collect Social Security numbers, bank details or login credentials.
The agency emphasizes that it does not initiate contact through email, text messages or social media to request sensitive information. The 2026 list also includes ghost preparers and misleading tax advice shared online, including content that pushes improper credit claims. Identity theft refund fraud remains part of the enforcement picture, with criminals filing returns using stolen data before legitimate taxpayers do.
How to protect yourself from tax scams
A few simple habits can reduce your risk during filing season.
1) Monitor your personal data and credit activity
Identity theft refund fraud remains a major concern. Criminals sometimes file tax returns using stolen personal information before the legitimate taxpayer submits theirs. Because many tax fraud cases begin with personal data exposed in breaches, keeping track of where your information appears online can help you catch warning signs earlier.
Identity theft services scan known data breach records for matches tied to your email address, Social Security number and other identifiers.
These services also monitor credit files across the three major U.S. credit bureaus and alert you to new accounts, hard inquiries or other changes to your credit report. If suspicious activity appears, members receive real-time alerts as soon as it is detected.
See my tips and best picks on Best Identity Theft Protection at Cyberguy.com.
2) Work only with legitimate tax preparers
Anyone paid to prepare a tax return must sign it and include a valid Preparer Tax Identification Number. Avoid preparers who promise unusually large refunds or refuse to sign your return.
3) Ignore unexpected IRS messages
The IRS does not contact taxpayers through email, text messages or social media to request personal information. Messages claiming to be from the IRS asking for sensitive data are usually scams.
AVERAGE TAX REFUND TOPS $3,700 MIDWAY THROUGH FILING SEASON, TREASURY SAYS
From stimulus payment theft to ghost preparers, taxpayers face shifting fraud tactics each year during tax season. (John Moore/Getty Images)
4) File your return early
Identity thieves often attempt to file fraudulent tax returns before the real taxpayer does. Filing earlier in the season can reduce that risk.
5) Consider an IRS Identity Protection PIN
This six-digit code adds an extra layer of security to your tax return. Without it, criminals cannot file a return using your Social Security number.
What to do if someone files a tax return in your name
If the IRS rejects your return because one has already been filed using your Social Security number, you may need to complete IRS Form 14039, Identity Theft Affidavit. The IRS may also require identity verification before processing your return. In some cases, affected taxpayers must submit a paper return while the agency investigates the suspected fraud.
Kurt’s key takeaways
Tax scams change every year, but the pattern stays the same. Criminals look for confusion around tax rules, new programs or trending online advice and use that uncertainty to push fraudulent claims or steal personal information. The best protection is slowing down before you file. Verify tax advice through trusted sources such as the IRS, work only with legitimate tax preparers and keep a close eye on your personal data and credit activity. A little caution during filing season can help prevent months of headaches if your return gets flagged for fraud.
Have you ever received a suspicious tax message, questionable filing advice online or discovered a tax return filed in your name? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Gemini’s task automation is here and it’s wild
A couple of weeks ago, Google and Samsung announced a big Gemini development coming to their newest devices: task automation. Starting with food delivery and rideshare apps, Gemini would be able to use certain apps on your behalf in a virtual window to take care of things like ordering dinner or getting a car to the airport — all based on simple prompts. You know, all the stuff that we’ve been promised for years AI assistants will be able to do. That feature wasn’t live when I first started testing the S26 Ultra, but it just arrived in beta as part of an update. And boy is it weird watching your phone use itself!
The first prompt I gave it was pretty simple: order an Uber to the airport. Gemini asked for clarification to determine which airport (a good question to ask!), then it went through a couple of steps on its own: adding the destination and opting to skip the step where you specify your airline, which doesn’t really matter at my local airport since it’s all in one terminal. As promised, the system stopped before the final step and prompted me to review the details before putting in the request for a car.
A vague and slightly more complicated request to order a coffee and a croissant required a little more input from me — and a lot of time on Gemini’s part scrolling through Starbucks’ hot drink options — but sure enough, it found the flat white on the menu. It also confronted a crucial decision: order the chocolate croissant warmed, or straight out of the pastry case? Without my input, it specified (correctly) that the pastry should be warmed. Pretty impressive for an assistant that just a year ago would argue with me over the details of a flight on my calendar.
I’ve got much more testing to do with this automation feature and I plan to spend the next few days throwing it some curveballs. Still, it’s impressive to see this feature out in the wild working as intended — so far, at least.
Photography by Allison Johnson / The Verge
-
Detroit, MI1 week agoU.S. Postal Service could run out of money within a year
-
Miami, FL1 week agoCity of Miami celebrates reopening of Flagler Street as part of beautification project
-
Pennsylvania1 week agoPa. man found guilty of raping teen girl who he took to Mexico
-
Sports1 week agoKeith Olbermann under fire for calling Lou Holtz a ‘scumbag’ after legendary coach’s death
-
Michigan4 days agoOperation BBQ Relief helping with Southwest Michigan tornado recovery
-
Oklahoma5 days ago
OSSAA unveils Class 6A-2A basketball state tournament brackets, schedule
-
Southeast3 days ago‘90 Day Fiancé’ alum’s boyfriend on trial for attempted murder over wild ‘Boca Bash’ accusations
-
Virginia1 week agoGiants will hold 2026 training camp in West Virginia