Skip to content

S0322 HummingBad

HummingBad is a family of Android malware that generates fraudulent advertising revenue and has the ability to obtain root access on older, vulnerable versions of Android. 1

Item Value
ID S0322
Associated Names
Version 1.1
Created 25 October 2017
Last Modified 21 April 2023
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
mobile T1404 Exploitation for Privilege Escalation HummingBad can exploit unfixed vulnerabilities in older Android versions to root victim phones.1
mobile T1643 Generate Traffic from Victim HummingBad can create fraudulent statistics inside the official Google Play Store, and has generated revenue from installing fraudulent apps and displaying malicious advertisements.1