Skip to main content

“HummingBad,” a new Android malware, has infected more than 10 million devices

Mobile Malware
Image used with permission by copyright holder
There is a new form of Android malware on the loose, and it is wreaking havoc. According to a detailed report from mobile security firm Check Point, HummingBad, a sophisticated bit of malicious code that emerged in February, has already managed to infect more than 10 million Android devices across the globe.

It is not your everyday, run-of-the-mill malware. HummingBad is the product of what Check Point describes as a group of “highly organized … Chinese cyber criminals that is working alongside multimillion-dollar Beijing analytics company Yingmob. It has serious developer muscle behind it: the HummingBad division, which bears the innocuous title “Development Team for Overseas Platform,” staffs 25 developers split into “four separate groups,” each responsible for maintaining the malware’s individual components. And Yingmob shares resources, including servers and the software certificates necessary to perform app installations, with HummingBad.

HummingBad infects primarily through “drive-by download,” or by installing itself on devices that visit infected webpages and sites. Its code, which is obfuscated by encryption, attempts to install itself on a given device persistently by multiple means.

The first, a “silent operation” that occurs in the background, is triggered every time the device boots up and its screen turns on. Hummingbird then checks to see if the device’s user account is “rooted” — i.e., has administrative privileges that can bypass security checks — and, if it is, it grants itself unfettered access to files and folders. Failing that, the malware attempts to root the device itself by running “multiple exploits” until it finds one that works.

But HummingBad has a Plan B, too: social engineering. The app pops open a window about an imminent “system update, which, in reality, is malicious code. If an unwitting victim permits the bogus “upgrade,” HummingBad connects to a remote server to download and launch additional applications. One nasty possibility? A keylogger that could “capture credentials and even bypass encrypted email containers used by enterprises,” wrote Check Point.

The driving force behind HummingBad’s development is profit, Check Point reported. Yingmob is currently generating $300,000 per month — $4 million per year — in fraudulent ad revenue. But the group, if it chose, could decide to pursue a far more nefarious purpose: the sale of personal data on infected devices.

HummingBad has gained its largest footholds in Asian markets. More than 1.6 million of the infected devices reside in China and another 1.35 million in India. That compares to 288,800 in the US. Collectively, Yingmob’s suite of malware now reaches 85 million phones and tablets and is now autonomously installing more than 50,000 apps a day, according to Checkpoint.

Google has yet to issue guidance regarding the detection and removal of HummingBad. We will update this story if it does.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
A new Google Pixel Tablet is coming, but it’s not what you think
Google Pixel Tablet on its charging dock.

It's been almost a year since the Google Pixel Tablet went up for preorder, leading many Android tablet fans to wonder when the inevitable Pixel Tablet 2 will arrive. A new rumor suggests that Google could release a new Pixel Tablet as early as next month, but it's probably not what you were expecting or hoping for.

According to @MysteryLupin on X (formerly Twitter), Google is planning to "relaunch" the Pixel Tablet without the charging/speaker dock included in the box. As you'll likely recall, the speaker dock is the Pixel Tablet's standout feature. You can use the Pixel Tablet on its own as a traditional Android tablet when you want, and when you're done, you throw it on the dock to transform it into a smart display. The idea of Google selling the Pixel Tablet without its claim to fame is an interesting one.

Read more
Anker sale: up to 40% off portable chargers, cable, and more
The iPhone 15 Pro Max being charged by the Anker MagGo Power Bank.

If you've been looking to pick up a new charging cable, charger, or all-in-one charging station for your Android phone or iPhone, then you'll be happy to know that Anker is having a rather large Earth-Day sale that you can take advantage of. There are a ton of discounts that you can take advantage of, too, with up to 40% off in some cases. I that wasn't enough, you can even snag yourself some free gifts, for example, one of the best accessories for a Galaxy S24 is the Anker Nano Power Bank if you spend more than $90,  or even an Anker 621 Magnetic Battery if you spend over $120. Either way, there are a lot of options, and while we've shared some of our favorite deals below, it's also worth taking a look at everything Anker has to offer by pressing the button below.

What you should buy during Anker's Sale
One of the most basic things you may need for any device is a charging cable, and Anker has a couple of great options for that. If you're on an older iPhone with a lightning cable, you can grab Anker's Anker 641 USB-C to Lightning Cable that's 6 feet long using the coupon WSPEV2KENJP2. On the other hand, if you need a USB-C to connect and charge your devices, you can grab the 6-foot Anker 543 USB-C to USB-C Cable using the code WSPEV2EHDR0C.

Read more
I keep forgetting about the Apple Watch Series 9’s coolest feature
Apps on the Apple Watch Series 9's screen.

I’m just going to come out and say it: I love the Apple Watch Series 9. A couple of weeks ago, I returned to wearing it every day after an extended period of not doing so. And you know what? I was surprised by how much I’d missed it.

But one thing has bothered me this time around: There's a feature I haven't been using. Not because it’s bad, but because I tend to forget it's there.
Effortless to own and wear

Read more