Remember HummingBad? We first talked about that malware in the middle of last year, and it affected more than 85 million devices An important problem behind any malware is that it only needs basic modifications to turn into something different, and that's how we arrive at HummingWhale, which managed to infiltrate the Google Play Store. The infected apps were downloaded at least two million times, and despite its changes, the goal is the same: generate profits with advertising and fake apps.
Android users are a very tempting target, and there are always occasions when a malicious developer manages to hide their code inside what appears to be a legitimate application. This is an arms race for Google. The Mountain View giant is quite good at detecting infected apps, but once “the other side” assimilates its methods, it does everything possible to evade and insert its malware. The latest report published by the folks at Check Point tells us about a new campaign under the name HummingWhale. If the name sounds familiar, it's because we are facing a variant of the famous HummingBad, with the difference that it is much smarter.
How HummingWhale works
In total, twenty apps with HummingWhale were detected, and they were downloaded between two and twelve million times. Check Point followed this malware family for months and determined that instead of seeking root access on the device, virtual machines techniques. When the user tries to close HummingWhale's malicious ads, the malware downloads unwanted apps inside that virtual machine and creates a fake identification that allows it to obtain additional profits by abusing referrals. The use of a virtual machine eliminates the need for root, and as if that were not enough, HummingWhale can post fake comments and ratings with the aim of improving the reputation of infected apps in the store.
Detection and removal
Check Point's report has the complete list of apps, but in essence they start with “com” and end with “camera” (for example, “com.note.ocean.camera”). As expected, Google has already removed the apps in question, and Check Point offers a compatible app capable of detecting this type of infection, as does Lookout, one of its direct competitors.