More than 85 million Android devices worldwide have been taken over by Yingmob, a China-based cybercriminal group that created the HummingBad malware, according to a Check Point report released last week.
HummingBad installs a persistent rootkit on Android devices, generates fake ad revenue, and installs additional malicious apps.
If it fails to install the rootkit, it then “bombards” the target device with “poisoned” apps.
HummingBad has generated revenue of $300,000 per month, according to Check Point.

The malicious software runs together with the legitimate advertising campaigns that Yingmob has created for the legitimate ad analysis business.
“We have been aware of this evolving malware family for some time, and we are constantly improving our detection systems,” said a Google spokesperson.
HummingBad uses a sophisticated, multi-stage chain attack with two main components.
The first part uses a rootkit that exploits multiple vulnerabilities to attempt to root the target device.
The SSP injects a library into the Google Play process using ptrace, which allows HummingBad to mimic installation / purchase / acceptance button clicks inside Google Play.
If this fails, the second component, CAP, installs malicious applications using sophisticated techniques. It decrypts module_encrypt.jar when it starts on a device, then dynamically loads code that contains the main malware. The next step is to decrypt and execute, among other things, a native binary.
Regardless of the success of rooting, HummingBad downloads as many malicious apps as it can for the target device.
