Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

“HummingBad,” a new Android malware, has infected more than 10 million devices

Add as a preferred source on Google

There is a new form of Android malware on the loose, and it is wreaking havoc. According to a detailed report from mobile security firm Check Point, HummingBad, a sophisticated bit of malicious code that emerged in February, has already managed to infect more than 10 million Android devices across the globe.

It is not your everyday, run-of-the-mill malware. HummingBad is the product of what Check Point describes as a group of “highly organized … Chinese cyber criminals that is working alongside multimillion-dollar Beijing analytics company Yingmob. It has serious developer muscle behind it: the HummingBad division, which bears the innocuous title “Development Team for Overseas Platform,” staffs 25 developers split into “four separate groups,” each responsible for maintaining the malware’s individual components. And Yingmob shares resources, including servers and the software certificates necessary to perform app installations, with HummingBad.

Recommended Videos

HummingBad infects primarily through “drive-by download,” or by installing itself on devices that visit infected webpages and sites. Its code, which is obfuscated by encryption, attempts to install itself on a given device persistently by multiple means.

The first, a “silent operation” that occurs in the background, is triggered every time the device boots up and its screen turns on. Hummingbird then checks to see if the device’s user account is “rooted” — i.e., has administrative privileges that can bypass security checks — and, if it is, it grants itself unfettered access to files and folders. Failing that, the malware attempts to root the device itself by running “multiple exploits” until it finds one that works.

But HummingBad has a Plan B, too: social engineering. The app pops open a window about an imminent “system update, which, in reality, is malicious code. If an unwitting victim permits the bogus “upgrade,” HummingBad connects to a remote server to download and launch additional applications. One nasty possibility? A keylogger that could “capture credentials and even bypass encrypted email containers used by enterprises,” wrote Check Point.

The driving force behind HummingBad’s development is profit, Check Point reported. Yingmob is currently generating $300,000 per month — $4 million per year — in fraudulent ad revenue. But the group, if it chose, could decide to pursue a far more nefarious purpose: the sale of personal data on infected devices.

HummingBad has gained its largest footholds in Asian markets. More than 1.6 million of the infected devices reside in China and another 1.35 million in India. That compares to 288,800 in the US. Collectively, Yingmob’s suite of malware now reaches 85 million phones and tablets and is now autonomously installing more than 50,000 apps a day, according to Checkpoint.

Google has yet to issue guidance regarding the detection and removal of HummingBad. We will update this story if it does.

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Apple says Lockdown Mode thwarted spyware attacks with a clean slate
Apple’s strongest defense is actually holding up
Lockdown Mode information page on an iPhone 14 Pro.

Apple says it has not seen a successful spyware attack on any iPhone with Lockdown Mode enabled, a claim it shared with TechCrunch.

Lockdown Mode arrived in 2022 as an opt-in feature for iPhone, iPad, and Mac. It was introduced as a stricter security mode for people at high risk of targeted attacks, such as journalists, activists, and government officials.

Read more
The Dynamic Island could shrink on the iPhone 18 series, and not just on the Pro models
One leaker, one claim, and a big question: is Apple genuinely ready to give every iPhone buyer the same design treatment as Pro owners this cycle?
Apple iPhone 17 Pro in Cosmic Orange leaning on a gray wall.

Apple’s Dynamic Island has been around long enough that most people have made their peace with it or forgotten it’s there. In fact, I’ve seen people associating the pill-shaped notch with newer iPhone models (released in the last 3 years). Now, a fresh leak suggests that the notch replacement is about to shrink, not just on the expensive models. 

What did the leaker actually say?

Read more
Apple Podcasts finally gets serious about video, adds multiple YouTube-inspired features
With offline downloads, Picture-in-Picture, and a dedicated video hub, iOS 26.4 turns Apple Podcasts into a platform creators can no longer afford to ignore.
Electronics, Phone, Mobile Phone

For years, the Apple Podcasts app supported video, at least it did technically, but nobody used it. Creators ignored it, while listeners forgot it. Meanwhile, other platforms like YouTube and Spotify quietly built empires on video podcasting. However, that changes with the iOS 26.4 update, or at least that is what Apple hopes for. 

Video podcasting exploded in popularity in recent years, with audiences gravitating toward platforms that treated the format well (as already mentioned above). Despite being an iPhone user, I personally consume podcasts on YouTube (I briefly paid for the Premium membership as well). 

Read more