Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HummingBad

Description

This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arsenal of over 85 million mobile devices around the world. With the potential to sell access to these devices to the highest bidder

AI Analysis

· 1 week ago

Executive Summary

HummingBad is a criminal group exploiting Android devices to generate $300,000 monthly in fraudulent ad revenue by infecting over 85 million devices globally. This threat actor monetizes compromised devices through unauthorized ad clicks and potentially sells access to third parties. The scale of infection indicates a highly operational and financially motivated campaign targeting mobile users.

Goals & Targeting

HummingBad's primary objective is financial gain through fraudulent ad revenue generation. The actor targets Android users globally, with no specific sector or country focus, as mobile devices represent a universal attack surface. Vulnerable users, particularly those in regions with high smartphone penetration and less stringent app store security, are likely victims. The group's operations suggest a preference for low-risk, high-reward attacks that avoid direct confrontation with law enforcement, prioritizing persistence and stealth over advanced technical intrusions.

Enhanced Description

HummingBad operates as a large-scale criminal group specializing in mobile malware that hijacks Android devices to generate illicit revenue through ad fraud. The malware is typically distributed via malicious apps, often disguised as legitimate software, and remains persistent on infected devices to continuously monetize the compromised infrastructure. By leveraging a vast network of infected devices, the group can sell access to external actors, further amplifying financial gains. The operational model relies on exploiting Android users' trust in app stores and third-party distribution channels, making detection challenging. The actor's focus on ad-based monetization suggests limited interest in data exfiltration or espionage, aligning with a purely commercial objective. The sheer scale of infection indicates a high level of automation and infrastructure management capabilities, though technical sophistication remains moderate compared to state-sponsored groups.

Key Capabilities

  • Large-scale Android device infection via malicious app distribution
  • Persistence mechanisms for long-term device control
  • Ad revenue generation through unauthorized in-app advertisements
  • Potential for selling device access to third parties
  • Exploitation of Android app store vulnerabilities for undetected distribution

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery

ATT&CK Techniques

T1197.001 - Software Deployment: Android Malware Installation
T1112 - Modify Existing Permissions
T1055 - Input Capture
T1566.001 - Phishing
T1082 - System Information Discovery

Software / Tooling

HummingBad malware
Ad fraud framework components
Custom Android exploitation modules

Campaigns & Victims

HummingBad has demonstrated sustained operational tempo, with campaigns like 'A Whale of a Tale: HummingBad Returns' indicating ongoing activity and adaptation to countermeasures. The actor's campaigns focus on mobile devices, leveraging app distribution networks to maintain a low profile. Notable operations include the use of compromised ad networks to avoid detection, suggesting a strategic effort to blend with legitimate traffic. The group's ability to consistently infect millions of devices highlights their resourcefulness in maintaining infrastructure and evading removal.

IOC Patterns

  • hash-sha256: [specific malware hashes provided]
  • Android app packages with suspicious permissions
  • C2 communication via legitimate ad network domains

Recommended Actions

  • Monitor for known HummingBad SHA-256 hashes in endpoint and network traffic
  • Implement strict app store policies and mobile device security controls
  • Deploy mobile threat defense solutions to detect anomalous app behavior
  • Regularly update device OS and apps to mitigate exploitation risks
  • Conduct user education on app download practices and phishing awareness

Suggested Tags

criminal
ad-fraud
mobile-malware
financial-motivated
android-exploitation

Confidence Assessment

The threat intelligence is highly confident in the actor's financial motivations, scale of infection, and malware distribution methods, based on linked campaigns and IOCs. However, operational details such as complete TTPs, full infrastructure maps, and precise command-and-control (C2) techniques remain partially obscured. The lack of detailed MITRE technique mapping and the absence of public attribution to specific regions limit deeper analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 10 MD5 Hash 10

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

450

IOCs

0

Observed Data

0

Tactics

Tags

criminal
ad-fraud
mobile-malware
financial-motivated
android-exploitation

Details

Type
Criminal
Country of Origin
C
Confidence
70%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.