Hummer is an Android malware family described as a rootkit/trojan that is extremely difficult to remove once it infects a device. After compromising a phone, it attempts to obtain root or administrator-level privileges using multiple rooting methods; the content states the family includes more than 18 such methods. Once elevated access is achieved, Hummer displays advertisements, downloads and installs applications in the background without user consent, and can repeatedly reinstall unwanted apps even after the user removes them. Reported payloads include games, adult entertainment applications, and other malware, which may also cause rapid battery drain. The malware is also described as collecting personal information from infected devices, including online banking usernames and password pairs. The content identifies Android as the target platform and states it has not spread to iOS. It is characterized as potentially one of the most widespread trojans, with reports that it may have infected millions of phones. High-confidence infection and exposure vectors mentioned in the content include unsafe mobile practices such as downloading apps from unofficial app stores and clicking SMS links carelessly. No specific threat actor attribution or concrete IOCs are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hummer is a malware discussed in the weekly cybersecurity review, but no specific details about its functionality or impact are provided in the content.
Android malware/rootkit that gains root privileges, displays pop-up ads, installs unwanted applications in the background, reinstalls removed apps, and steals personal information including banking credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.