This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arsenal of over 85 million mobile devices around the world. With the potential to sell access to these devices to the highest bidder
Executive Summary
HummingBad is a criminal group exploiting Android devices to generate $300,000 monthly in fraudulent ad revenue by infecting over 85 million devices globally. This threat actor monetizes compromised devices through unauthorized ad clicks and potentially sells access to third parties. The scale of infection indicates a highly operational and financially motivated campaign targeting mobile users.
Goals & Targeting
HummingBad's primary objective is financial gain through fraudulent ad revenue generation. The actor targets Android users globally, with no specific sector or country focus, as mobile devices represent a universal attack surface. Vulnerable users, particularly those in regions with high smartphone penetration and less stringent app store security, are likely victims. The group's operations suggest a preference for low-risk, high-reward attacks that avoid direct confrontation with law enforcement, prioritizing persistence and stealth over advanced technical intrusions.
Enhanced Description
HummingBad operates as a large-scale criminal group specializing in mobile malware that hijacks Android devices to generate illicit revenue through ad fraud. The malware is typically distributed via malicious apps, often disguised as legitimate software, and remains persistent on infected devices to continuously monetize the compromised infrastructure. By leveraging a vast network of infected devices, the group can sell access to external actors, further amplifying financial gains. The operational model relies on exploiting Android users' trust in app stores and third-party distribution channels, making detection challenging. The actor's focus on ad-based monetization suggests limited interest in data exfiltration or espionage, aligning with a purely commercial objective. The sheer scale of infection indicates a high level of automation and infrastructure management capabilities, though technical sophistication remains moderate compared to state-sponsored groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HummingBad has demonstrated sustained operational tempo, with campaigns like 'A Whale of a Tale: HummingBad Returns' indicating ongoing activity and adaptation to countermeasures. The actor's campaigns focus on mobile devices, leveraging app distribution networks to maintain a low profile. Notable operations include the use of compromised ad networks to avoid detection, suggesting a strategic effort to blend with legitimate traffic. The group's ability to consistently infect millions of devices highlights their resourcefulness in maintaining infrastructure and evading removal.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat intelligence is highly confident in the actor's financial motivations, scale of infection, and malware distribution methods, based on linked campaigns and IOCs. However, operational details such as complete TTPs, full infrastructure maps, and precise command-and-control (C2) techniques remain partially obscured. The lack of detailed MITRE technique mapping and the absence of public attribution to specific regions limit deeper analysis.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
450
IOCs
0
Observed Data
0
Tactics