logo

Word Template

ID: cf233770-b143-4317-9295-0b03b7009ac4

STIX ID: report--cf233770-b143-4317-9295-0b03b7009ac4

Threat Score

80/100

Uploaded: 2026-08-15

Published Date: 2016-06-29

Last Modified Date: 2016-06-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Check Point report analyzes the HummingBad Android malware campaign operated by a Chinese ad-analytics company (Yingmob). It describes a multi-stage campaign that uses rooting exploits and social-engineered update prompts to gain persistence, injects native libraries into Google Play to simulate install/click activity, fabricates device identifiers (fake IMEI), and silently or fraudulently installs apps to perpetrate large-scale ad fraud. The investigation provides scale metrics (~85 million devices reached, ~10 million malicious-app users), monetization figures (~$300K/month), component-level technical details (SSP, CAP, RightCore), code excerpts, command-and-control configuration samples, and numerous SHA-256 indicators of compromise.