Word Template
ID: cf233770-b143-4317-9295-0b03b7009ac4
STIX ID: report--cf233770-b143-4317-9295-0b03b7009ac4
Threat Score
80/100
Uploaded: 2026-08-15
Published Date: 2016-06-29
Last Modified Date: 2016-06-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Check Point report analyzes the HummingBad Android malware campaign operated by a Chinese ad-analytics company (Yingmob). It describes a multi-stage campaign that uses rooting exploits and social-engineered update prompts to gain persistence, injects native libraries into Google Play to simulate install/click activity, fabricates device identifiers (fake IMEI), and silently or fraudulently installs apps to perpetrate large-scale ad fraud. The investigation provides scale metrics (~85 million devices reached, ~10 million malicious-app users), monetization figures (~$300K/month), component-level technical details (SSP, CAP, RightCore), code excerpts, command-and-control configuration samples, and numerous SHA-256 indicators of compromise.
