Malware discovered embedded in firmware of low-cost Android smartphones

Campaign dubbed 'Midnight Mimosa' turns devices into residential proxies and enables ad fraud across 150 countries

By LineZotpaper
Published
Read Time2 min
A malware campaign called Midnight Mimosa has been discovered preinstalled on low-cost Android smartphones, with malicious software embedded directly into the device firmware, giving attackers system-level control to install apps, commit ad fraud, and use the phones as residential proxies.

Researchers at Bitdefender have uncovered a malware campaign affecting low-cost Android smartphones that ship with malicious software baked into their firmware. The campaign, named Midnight Mimosa, has been active for approximately two years and has infected thousands of devices across more than 150 countries, with the highest number of victims in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

The malware is believed to have been introduced somewhere in the device supply chain. It remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred. The affected devices use MediaTek chipsets, and the malware resides in the system partition, granting it system-level privileges that allow it to silently install and remove applications, grant permissions, and execute remotely downloaded code without user interaction.

Bitdefender found the malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones that impersonate Samsung and Apple products. The malicious programs disguise themselves as legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Because the applications are signed and run with elevated privileges, they cannot be removed through Android's normal uninstall process.

Owners of Cubot and Doogee smartphones reported suspicious applications that reinstalled themselves after removal on an XDA forums discussion page. One Doogee Fire 3 Max owner said an official firmware update infected the device with the malware. The infection disappeared after restoring an older firmware version but returned when the update was installed again.

Some users reported that manufacturers released firmware updates that resolved the infections, but the manufacturers have not publicly explained how the malicious software was introduced.

Bitdefender identified approximately 32 applications distributed through the malware framework, which downloads additional modules from command-and-control servers to perform different malicious activities. The campaign was discovered when the company's App Anomaly Detection technology flagged a suspicious system application silently installing and removing other apps.

§

Analysis

Why This Matters

  • Consumers buying low-cost Android devices may unknowingly receive phones that are compromised before they even power them on, with no way to remove the malware through normal means.
  • The use of residential proxies means attackers can route malicious traffic through victims' phones, potentially implicating innocent users in cybercrime or exposing them to legal risk.
  • The supply chain infection highlights a vulnerability in the manufacturing process for budget devices, raising questions about security standards and oversight.

Background

Midnight Mimosa is a type of malware known as a trojan, embedded in the firmware of low-cost Android phones. Unlike typical malware that requires user action to install, it is preinstalled at the system level, making it extremely difficult to remove. The campaign has been running for two years, affecting devices globally. The malware uses the phone's internet connection to route traffic, turning it into a residential proxy, which can be used for ad fraud or to hide malicious activity. MediaTek is a common chipset supplier for budget phones, and the infection is believed to occur in the supply chain, possibly during manufacturing or through firmware updates.

Key Perspectives

Affected users: Report persistent infections that survive factory resets and reinstallation, with no clear way to secure their devices beyond reverting to older firmware or waiting for manufacturer patches. Bitdefender researchers: Identified the malware through anomaly detection and urge consumers to be cautious when purchasing low-cost Android devices, recommending that manufacturers improve supply chain security. Manufacturers (Doogee, Cubot): Have not publicly commented on how the malware was introduced. Some have released firmware updates addressing infections, but the lack of transparency leaves consumers uncertain about the safety of future updates.

What to Watch

  • Whether manufacturers like Doogee and Cubot issue public statements explaining how the malware entered their firmware and what steps they are taking to prevent future infections.
  • If other budget Android brands are similarly affected, as the campaign has been operational for two years across many countries.
  • Potential regulatory responses or class-action lawsuits from affected users, which could pressure the industry to adopt stricter supply chain security measures.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.