A threat actor operating malware that compromises Android devices to generate fraudulent ad revenue from over 85 million devices.
Analyst brief
HummingBad is a threat actor known for malware that compromises Android devices to generate fraudulent ad revenue, reportedly earning $300,000 per month. The group controls a botnet of over 85 million mobile devices worldwide, with the potential to sell access to the highest bidder. Key TTPs include exploiting existing vulnerabilities to gain root privileges on Android, establishing persistence, and communicating with C2 servers to execute ad fraud activities. Defenders should monitor for unusual network traffic, excessive battery drain, unauthorized root access attempts, and the appearance of unexpected pop-up ads on Android devices, while enforcing strict mobile application allowlisting.
HummingBad
unknown
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arsenal of over 85 million mobile devices around the world. With the potential to sell access to these devices to the highest bidder
What activities does the HummingBad group perform on Android devices?+
HummingBad gains root privileges to establish persistence on Android devices, communicates with C2 servers, and generates fraudulent ad revenue through fake clicks and ad impressions.
What is the scale of the botnet controlled by the HummingBad group?+
The group controls a botnet of over 85 million mobile devices worldwide.