Skip to main content

“HummingBad,” a new Android malware, has infected more than 10 million devices

Mobile Malware
Image used with permission by copyright holder
There is a new form of Android malware on the loose, and it is wreaking havoc. According to a detailed report from mobile security firm Check Point, HummingBad, a sophisticated bit of malicious code that emerged in February, has already managed to infect more than 10 million Android devices across the globe.

It is not your everyday, run-of-the-mill malware. HummingBad is the product of what Check Point describes as a group of “highly organized … Chinese cyber criminals that is working alongside multimillion-dollar Beijing analytics company Yingmob. It has serious developer muscle behind it: the HummingBad division, which bears the innocuous title “Development Team for Overseas Platform,” staffs 25 developers split into “four separate groups,” each responsible for maintaining the malware’s individual components. And Yingmob shares resources, including servers and the software certificates necessary to perform app installations, with HummingBad.

Recommended Videos

HummingBad infects primarily through “drive-by download,” or by installing itself on devices that visit infected webpages and sites. Its code, which is obfuscated by encryption, attempts to install itself on a given device persistently by multiple means.

The first, a “silent operation” that occurs in the background, is triggered every time the device boots up and its screen turns on. Hummingbird then checks to see if the device’s user account is “rooted” — i.e., has administrative privileges that can bypass security checks — and, if it is, it grants itself unfettered access to files and folders. Failing that, the malware attempts to root the device itself by running “multiple exploits” until it finds one that works.

But HummingBad has a Plan B, too: social engineering. The app pops open a window about an imminent “system update, which, in reality, is malicious code. If an unwitting victim permits the bogus “upgrade,” HummingBad connects to a remote server to download and launch additional applications. One nasty possibility? A keylogger that could “capture credentials and even bypass encrypted email containers used by enterprises,” wrote Check Point.

The driving force behind HummingBad’s development is profit, Check Point reported. Yingmob is currently generating $300,000 per month — $4 million per year — in fraudulent ad revenue. But the group, if it chose, could decide to pursue a far more nefarious purpose: the sale of personal data on infected devices.

HummingBad has gained its largest footholds in Asian markets. More than 1.6 million of the infected devices reside in China and another 1.35 million in India. That compares to 288,800 in the US. Collectively, Yingmob’s suite of malware now reaches 85 million phones and tablets and is now autonomously installing more than 50,000 apps a day, according to Checkpoint.

Google has yet to issue guidance regarding the detection and removal of HummingBad. We will update this story if it does.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The best phones in 2024: our 15 favorite smartphones right now
The Pixel 9 and OnePlus 12 held at angles.

Navigating the sea of smartphones in 2024 can feel like a daunting task. With many excellent options from both Apple and Android brands, pinpointing the perfect device for your needs might seem overwhelming. But don't worry; we're here to simplify your search.

We've meticulously curated a list of the top-performing smartphones available, considering everything from raw processing power and camera capabilities to battery life, display quality, and overall design. Whether you prioritize a blazing-fast processor for demanding tasks, a cutting-edge camera system to capture life's moments, or a long-lasting battery to keep you connected throughout the day, we're confident you'll find your ideal match on our list.

Read more
Early Black Friday Apple Watch deals 2024 — Better than Prime Day?
A person wearing the Apple Watch Series 10.

Update 10/23/24: This starts our coverage of the Apple Watches for the upcoming Black Friday, and we're already seeing breakout deals, especially on the Ultra model available below.

Black Friday is weeks away, starting officially on November 29 this year, but we don't have to wait until then for great deals to start. At present, we're looking at Apple Watch deals that have hit the major sites earlier than usual. This means that you can go ahead and get one of the best smartwatches (and, by extension, best fitness trackers) at a discounted price before the holiday even begins. Sometimes early deals, like the ones on this page, are even better than the deals we see during the event itself, as deals that are "too good" can get bought up or "corrected" by companies as time goes along. So, feel free to shop these early smartwatch deals covering one of your favorite Apple products. From the very latest to older models and from 'SE' to 'Ultra,' you'll find every good deal available on Apple Watches here.
Apple Watch SE 2 [GPS 40mm] — $189 $249 24% off

Read more
Early Black Friday smartwatch deals 2024: Apple, Samsung, Garmin
Digital Trends Best Cyber Monday Smartwatch Deals

Black Friday and Cyber Monday are some of the best periods to snag yourself a new smartwatch, especially if you've been waiting a while before upgrading. While the actual sales day might be a little while off, there are already a lot of great early Black Friday deals that you can take advantage of, including on some of the best smartwatches on the market. To that end, we've collected some of our favorite early deals for you below, although it's also worth keeping an eye on our larger smartwatch deals roundup as well.
Garmin Forerunner 55 -- $170 $220 15% off

While most smartwatches focus on the smartwatch part, the Garmin Forerunner 55 is made for runners who want to keep track of their overall fitness and their runs. It comes with GPS tracking in the three major systems, has a whole suite of sensors such as heart rate and Vo2 Max, and comes with a very solid $30 discount off the $200 price tag.

Read more