Skip to main content

“HummingBad,” a new Android malware, has infected more than 10 million devices

Mobile Malware
Image used with permission by copyright holder
There is a new form of Android malware on the loose, and it is wreaking havoc. According to a detailed report from mobile security firm Check Point, HummingBad, a sophisticated bit of malicious code that emerged in February, has already managed to infect more than 10 million Android devices across the globe.

It is not your everyday, run-of-the-mill malware. HummingBad is the product of what Check Point describes as a group of “highly organized … Chinese cyber criminals that is working alongside multimillion-dollar Beijing analytics company Yingmob. It has serious developer muscle behind it: the HummingBad division, which bears the innocuous title “Development Team for Overseas Platform,” staffs 25 developers split into “four separate groups,” each responsible for maintaining the malware’s individual components. And Yingmob shares resources, including servers and the software certificates necessary to perform app installations, with HummingBad.

HummingBad infects primarily through “drive-by download,” or by installing itself on devices that visit infected webpages and sites. Its code, which is obfuscated by encryption, attempts to install itself on a given device persistently by multiple means.

The first, a “silent operation” that occurs in the background, is triggered every time the device boots up and its screen turns on. Hummingbird then checks to see if the device’s user account is “rooted” — i.e., has administrative privileges that can bypass security checks — and, if it is, it grants itself unfettered access to files and folders. Failing that, the malware attempts to root the device itself by running “multiple exploits” until it finds one that works.

But HummingBad has a Plan B, too: social engineering. The app pops open a window about an imminent “system update, which, in reality, is malicious code. If an unwitting victim permits the bogus “upgrade,” HummingBad connects to a remote server to download and launch additional applications. One nasty possibility? A keylogger that could “capture credentials and even bypass encrypted email containers used by enterprises,” wrote Check Point.

The driving force behind HummingBad’s development is profit, Check Point reported. Yingmob is currently generating $300,000 per month — $4 million per year — in fraudulent ad revenue. But the group, if it chose, could decide to pursue a far more nefarious purpose: the sale of personal data on infected devices.

HummingBad has gained its largest footholds in Asian markets. More than 1.6 million of the infected devices reside in China and another 1.35 million in India. That compares to 288,800 in the US. Collectively, Yingmob’s suite of malware now reaches 85 million phones and tablets and is now autonomously installing more than 50,000 apps a day, according to Checkpoint.

Google has yet to issue guidance regarding the detection and removal of HummingBad. We will update this story if it does.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
An Apple insider just revealed how iOS 18’s AI features will work
An iPhone 15 Pro Max laying face-down outside, showing the Natural Titanium color.

As Apple’s Worldwide Developers Conference (WWDC) inches closer, the chatter around the company’s AI work has taken a feverish turn. In a year when smartphone and computing brands have focused solely on AI niceties, Apple has been uncharacteristically silent around the AI hype — eliciting concern about the brand missing the train.

However, a new report has given us a closer look at how Apple's AI dreams may come to fruition with its iOS 18 update later this year.
New details on Apple's AI plans

Read more
Best Samsung Galaxy S22 deals: Save big on unlocked models
The back of the Galaxy S22 and Galaxy S22 Plus.

For a couple of years now the Samsung Galaxy S22 has made for some of the best phone deals you can shop. This includes both the Galaxy S22 and its big brother in the lineup, the Samsung Galaxy S22+. These phones have been out for a little while now, and they’re getting more and more difficult to find brand new. We’ve managed to find a few deals available on both the Galaxy S22 and the Galaxy S22+, however, and there are several ways to save on refurbished models out there. We’ve rounded up all of the best Samsung Galaxy S22 deals taking place at a number of different retailers, so read onward for all of the details on how to save.
Samsung Galaxy S22 deals at Samsung

Samsung isn’t currently carrying very many older models of the Samsung Galaxy S phone. You’ll find some newer models like the recently released Samsung Galaxy S24 there, but if you’re looking for something from the S22 model lineup all you’ll find is a Galaxy S22 renewed model. It’s offering some great savings, however, as you can claim it for just $679 with up to $300 in trade-in savings.

Read more
Best Apple Watch deals: Series 9 and Ultra 2 discounted
Someone wearing an Apple Watch Ultra 2, showing the Modular Ultra watch face.

The Apple Watch has become one of the best smartwatches on the market. And while Apple deals are traditionally somewhat difficult to come by, the Apple Watch has always been a good Apple product to turn to for some savings. That’s certainly the case right now, as some of the best smartwatch deals are on various Apple Watch models, and several models are offering substantial savings. From the Apple Watch Ultra 2 to older Apple Watch models that come in at relatively low prices, we’ve tracked down all of the best Apple Watch deals taking place right now. Read onward and you’ll find plenty of details on how to save, as well as some information on which Apple Watch may best suit your needs.
Best Apple Watch SE deals

The first-generation Apple Watch SE, which was released in 2020, and the second-generation Apple Watch SE, which was rolled out in 2022, are the most affordable ways of getting an Apple Watch. They don't give up too much in order to keep costs low compared to their more expensive peers though. The Apple Watch SE 2, in particular, still provides comprehensive fitness tracking features, a comfortable fit, and excellent software as it can be updated to Apple's latest watchOS 10.

Read more