Skip to main content

“HummingBad,” a new Android malware, has infected more than 10 million devices

Mobile Malware
Image used with permission by copyright holder
There is a new form of Android malware on the loose, and it is wreaking havoc. According to a detailed report from mobile security firm Check Point, HummingBad, a sophisticated bit of malicious code that emerged in February, has already managed to infect more than 10 million Android devices across the globe.

It is not your everyday, run-of-the-mill malware. HummingBad is the product of what Check Point describes as a group of “highly organized … Chinese cyber criminals that is working alongside multimillion-dollar Beijing analytics company Yingmob. It has serious developer muscle behind it: the HummingBad division, which bears the innocuous title “Development Team for Overseas Platform,” staffs 25 developers split into “four separate groups,” each responsible for maintaining the malware’s individual components. And Yingmob shares resources, including servers and the software certificates necessary to perform app installations, with HummingBad.

Recommended Videos

HummingBad infects primarily through “drive-by download,” or by installing itself on devices that visit infected webpages and sites. Its code, which is obfuscated by encryption, attempts to install itself on a given device persistently by multiple means.

The first, a “silent operation” that occurs in the background, is triggered every time the device boots up and its screen turns on. Hummingbird then checks to see if the device’s user account is “rooted” — i.e., has administrative privileges that can bypass security checks — and, if it is, it grants itself unfettered access to files and folders. Failing that, the malware attempts to root the device itself by running “multiple exploits” until it finds one that works.

But HummingBad has a Plan B, too: social engineering. The app pops open a window about an imminent “system update, which, in reality, is malicious code. If an unwitting victim permits the bogus “upgrade,” HummingBad connects to a remote server to download and launch additional applications. One nasty possibility? A keylogger that could “capture credentials and even bypass encrypted email containers used by enterprises,” wrote Check Point.

The driving force behind HummingBad’s development is profit, Check Point reported. Yingmob is currently generating $300,000 per month — $4 million per year — in fraudulent ad revenue. But the group, if it chose, could decide to pursue a far more nefarious purpose: the sale of personal data on infected devices.

HummingBad has gained its largest footholds in Asian markets. More than 1.6 million of the infected devices reside in China and another 1.35 million in India. That compares to 288,800 in the US. Collectively, Yingmob’s suite of malware now reaches 85 million phones and tablets and is now autonomously installing more than 50,000 apps a day, according to Checkpoint.

Google has yet to issue guidance regarding the detection and removal of HummingBad. We will update this story if it does.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Google’s Pixel Weather app just got two new features. Here’s how they work
The Pixel Weather app on a Google Pixel 9.

The Pixel Weather app has been the focus of a lot of attention lately as Google revamps the user experience and adds more features. Now, there's more good news: two of those promised functions — the Pollen count card and immersive vibrations — are newly available, at least for some users.

Thanks to "immersive weather vibrations," the Pixel Weather app vibrates to match the animated backgrounds it displays, with intensity levels that mirror the precipitation amount (because it's not just rainfall), according to 9to5Google. Of course, if you don't like the feature, you can disable it in the account menu.

Read more
2025 could finally be the year of a budget-friendly Samsung Galaxy Z Flip
A person closing the Samsung Galaxy Z Flip 6.

The idea of a more budget-friendly Samsung clamshell has gained steam as well-known leakers drop more and more hints that a new Galaxy Z Flip is on the way. Today, another leak from someone in the know adds even more credence to that rumor.

Ross Young made a post on X where he suggested that Samsung might release a Z Flip 7 FE in 2025 with the clamshell design fans have waited for. Young has a proven record for accurate leaks, and their work in the supply chain gives him a unique insight into what companies are working on.

Read more
Google just announced Android 16. Here’s everything new
The Android 16 logo on a smartphone, resting on a shelf.

No, that headline isn't a typo. A little over a month after Android 15 was released to the masses in October, Google has already announced Android 16 and begun rolling out its first developer beta of the newest Android version.

If this seems like a much earlier release than usual, that's because it is. We typically expect the first developer beta of the next Android update to arrive in February. For Android 16, however, Google has pushed the timeline up by a few months and launched Android 16 Developer Preview 1 in mid-November.
Why Android 16 is launching so much earlier

Read more