Android's lack of timely updates, massive fragmentation, and an overwhelming number of devices in circulation make it a tempting target for malware developers, and one of the latest examples is HummingBad. This variant aims to generate fake clicks, install malicious apps, and obtain other illegitimate gains through advertising. Since its discovery, it is estimated that more than 85 million devices have been compromised.
Discovery and Monitoring
If there is one thing we can say with certainty about malware, it is that it doesn't sit still. Every new report on infections or widespread attacks brings a new fact, discovery, or resource being exploited by malicious developers. On desktop computers, the rise of ransomware has been astonishing, precisely breaching unprotected terminals in places like hospitals and government agencies. Moving to mobile devices, the preferred target is undoubtedly Android, due to the impressive number of smartphones and tablets on the market, and its natural design flaws that prevent it from responding quickly enough to immediate threats. This brings us to HummingBad, a new malware discovered in February 2016 and monitored by the security firm Check Point over the past few months.
Technical Details and Yingmob
HummingBad remained relatively dormant during the "February-March-April" period, but its activity exploded in May, prompting us to talk about a total that exceeds 85 million devices. From a technical standpoint, HummingBad is a rootkit, whose first action seeks to gain root access on the device, and if it fails, it will try to trick the user into granting the necessary permissions. Its work is divided into three parts: Generate fake clicks, install malicious apps, and inject advertising on the device. This triple mechanism has allowed Yingmob, a Beijing-based advertising agency and the intellectual author of HummingBad through its "development group for external platforms", to obtain fraudulent gains of about 300 thousand dollars per month on average.
Impact and Prevention
The folks at Check Point indicate that there are about ten million active users 'using' Yingmob's malicious apps installed by HummingBad, and although the main group is in China and India, the 'top 10' shows that Brazil and Mexico have more than 300 thousand affected users, while the United States surpasses 280 thousand. Another detail to consider is that the vast majority of HummingBad infections (90 percent) were concentrated in the Jelly Bean and KitKat versions of Android, and only eight percent affected the latest editions. Both Google and Yingmob have maintained radio silence, and Check Point did not provide a direct means to eliminate HummingBad, but we estimate that infected users will need to perform a factory reset on their devices, and that the best way to prevent is, as always, to limit our downloads to the Google Play Store.