Yes, a WiFi Hotspot is a proxy which has the means to perform many acts including malicious ones. Be it an android phone acting as a WiFi hotspot or a router or any other devices.
- Passive
Snoops on your traffic, data credentials like passwords etc.
- Active
Redirect you to malicious links resulting you in downloading malware
or pushing malware to your device.
There are known trojan that can perform malicious acts via a hotspot and there are countless more unknown (it's a guaranteed).
It is the unknown that we are unsafe from. So the best thing is to connect only to a WiFi hotspot that you know and are familiar with.
Last but not least, do you want to apply the two second rule here? Drop a donut on the ground, pick it up in less than two seconds; ok cool. No bacteria, I can eat it.
In this case, just connecting for that split second and then disconnecting does not mean you're safe. Data similarly can be ex filtrated in that few seconds.
Better safe than sorry, recent years of leaks show just how vulnerable we are in security and privacy.
Some research here
- Commercial Surveillance Tools Being Used as Mobile Malware
- Xsser mRAT Targets iOS and Android for Man-in-Middle Attacks
- Smartphone infections double, hotspots are also a trouble area