Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:31:47 UTC Home > List all groups > List all tools > List all groups using tool HummingBad Tool: HummingBad Names HummingBad Category Malware Type Rootkit, Downloader Description (Check Point) In February 2016, Check Point researchers first discovered HummingBad, a malware that establishes a persistent rootkit on Android devices, generates fraudulent ad revenue, and installs additional fraudulent apps. Information MITRE ATT&CK AlienVault OTX Last change to this tool card: 08 May 2020 Download this tool card in JSON format All groups using tool HummingBad Changed Name Country Observed Other groups Yingmob 2016-Jan 2017 1 group listed (0 APT, 1 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0a1298da-a7b6-4ff4-a56d-2b042f8e16c5 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=0a1298da-a7b6-4ff4-a56d-2b042f8e16c5 Page 1 of 1