Android Hummingbad Malware: What You Need to Know 1

Android Hummingbad Malware: What You Need to Know

by final report Some new Android malware called HummingBad has infected more than 10 million smartphones and tablets and can be installed on around 85 million devices worldwide. Frankly, news like this is alarming and that’s what we know so far.

Cybersecurity software company Check Point recently published its findings on HummingBad, which led to tons of people. reports to claim millions users everywhere are at risk.

Similar to the StageFright scare in 2015, users need to know all the details before jumping to conclusions. While Stagefright has the potential to infect a billion devices, HummingBad isn’t, and it’s not as common as the security firm would like everyone to believe. Below is what users need to know about Android HummingBad malware.

News about a virus or malware for both Android and iOS comes out all the time, and often the situation is not as deadly as some believe. However, it is he who is responsible for this that should worry users today and in the future.

The problem with this new report isn’t how many devices are infected or what it’s doing, it’s that there is a genuine legitimate company behind the attacks and infections. According to Check Point, a team of about 25 developers at a Beijing-based multi-million dollar advertising company, Yingmob is the cause of all this noise.

Yingmob is an advertising and analytics company that makes millions of dollars from clickable ads, pop-ups and even app downloads. Other reports suggest that the same company is behind some recent iPhone hacks as well. Here’s what we know.

Do I Have HummingBad Malware?

No, you most likely do not have a HummingBad malware infection on your smartphone or tablet. From what we understand, around 288,000 devices in the United States may be infected, and under 100,000 in the UK or Australia. Larger markets such as China near the company appear to be at risk, with 1.6 million and possibly 1.4 million devices in India.

Screenshot 2016-07-05 11.10.59 AM

The number is actually just under 10 million in total, which is still a lot. The report cites 84 million devices because YingMob has access to that many. This does not mean that they are all infected or not at all.

The scary thing about this report is that only a small group of devices had HummingBad malware installed, but they saw a huge spike in May which led to the report and findings being made public. At the end of the day, no, you have nothing to worry about. Especially if you pay attention to what is clicked, where you download apps, and if you use secure devices like Samsung KNOX.

China and India are huge markets, with millions of cheap Chinese knockoffs or budget devices with stock Android, outdated software with poor security, and more. The image above shows it running older versions of the most infected Android.

What is HummingBad?

From what we’ve gathered so far, HummingBad is not malware that does anything malicious and is a move to generate more ad revenue and make hundreds of thousands of dollars. Simply by simulating clicks on a device. Of course, rooting a smartphone or tablet is never good, but we don’t see any signs of anything extremely malicious.

HummingBad started out as the typical “car-attack” in which Android devices were infected after visiting a website, but has since evolved into something much more powerful in an effort to make more money.

According to the Check Point report, the company tries to root thousands of smartphones every day, which gives the company access to the system level of a device where malware activities are taking place. Many succeed, but many fail, resulting in a second attempt via a bogus “system update notification”. If a user clicks it, certain system-level permissions are granted to HummingBad.

201310DIY-Android-Malware-Analysis-Detach-OBAD

The end result of HummingBad infecting a device seems to be automatically clicking on ad links and following a link and downloading tons of apps from shady places, all aimed at profit. Check Point states that about 50,000 apps are installed daily.

However, if the company did indeed infect 84 million Android devices, something much more malicious could happen, but it doesn’t seem to be happening yet.

How HummingBad Works

HummingBad works by attacking the root system of Android smartphones and tablets running Android Ice Cream Sandwich up to the latest Android 6.0.1 Marshmallow. If root access is not achieved, another level is given (if successful) after the fake system update notification.

Once done, the malware essentially hijacks certain aspects of the device. From here it downloads apps from Stores, clicks online ads and shares other malware. All of this gives Yingmob about $300,000 a month through false clicks and app downloads.

Check Point continued to issue this statement, which essentially “can be done” with this malware.

“The group tries to root thousands of devices every day and succeeds in hundreds of attempts. With these devices, a group can create a botnet, carry out targeted attacks on businesses or government agencies, and even sell access to other cybercriminals on the black market. All data on these devices is at risk, including corporate data on these devices that serve dual personal and business purposes for end users.

The research firm noted that YingMob could potentially sell information gathered from devices and even sell access to a large batch of devices on the black market.

Can I Control HummingBad

While this malware doesn’t seem to be that big of a problem, especially in the United States, and it doesn’t do anything extremely malicious (besides making fake clicks to make tons of money), it’s still something users need to know a little bit about. of-of.

No information has been published on how to check for or remove HummingBad malware on devices. However, most likely your device is not infected with a virus. There are numerous virus scanners and preventative apps on the Google Play Store that can scan and check for infections when you need them.

Other details

There have been no comments so far from Google or the company reportedly responsible, Yingmob, but we will be on the lookout for any information. Unfortunately, we hear about such stores often, but for the most part, they are not as much of a concern as some claim.

At the end of the day it’s all about using common sense. Only download apps from Google Play Store, be careful and smart about what you click or download. Google is constantly updating Android to be more secure, promising monthly security patches and more. We’ll update when we learn more.

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.