HomeYoutubeMidnight Mimosa: Thousands of Android devices with pre-installed malware

Midnight Mimosa: Thousands of Android devices with pre-installed malware

A widespread cybercrime campaign dubbed Midnight Mimosa is exposing the dangers that can lurk in budget Android smartphones , which are reaching consumers with pre-installed malware . According to Bitdefender research , thousands of unique infected devices have been detected in the past two years in more than 150 countries , with attackers exploiting their infrastructure primarily for ad fraud and botnet creation.

What is particularly worrying is that the infection may have occurred before the buyer even turns on their phone. In these cases, the malware is embedded in the firmware, the low-level software necessary for the device to function. As a result, the threat is not treated like a regular malicious application, which the user can uninstall with a few taps on the screen.

How the Midnight Mimosa campaign works

The campaign appears to be exploiting the large international market for budget Android smartphones, particularly devices based on MediaTek. The use of a particular processor does not mean that MediaTek products are inherently vulnerable or infected. The problem is related to the manufacturing process, distribution, and possible integration of malicious code into the software of certain devices.

Once the phone is activated, the malware can start operating without requiring any action from the owner. It then communicates with a Command and Control (C2) server, through which its operators can send instructions and manage the infected devices remotely.

Midnight Mimosa: Thousands of Android devices with pre-installed malware

This architecture allows attackers to tailor the malware's behavior to their goals. Because it is a persistent system application, its removal is usually not possible with standard application uninstallation procedures.

System-level access and silent application installation

One of the most serious features of Midnight Mimosa is the level of access it can gain. The malware has system privileges, which allow it to perform actions that are normally unavailable to a common application.

Among the capabilities described are the installation and removal of applications without the usual user interaction, granting permissions , and loading additional code sent from remote servers.

This means that a device can change its functionality after purchase, without the owner easily realizing what is happening in the background. Operators can add new features, change the malicious payload, and integrate the phone into larger cybercrime infrastructures.

This feature makes the threat particularly difficult to deal with, as simply deleting suspicious applications may not be enough to restore the device.

See also: RatHat Android Malware Console uses Gemini to locate victims

Ad fraud and botnets

The main goal of Midnight Mimosa appears to be generating illegal profit through ad fraud. The malware can use infected devices to perform automated interactions with ads, generating fictitious clicks and activity that can lead to illegal payments.

Click fraud costs advertisers money by potentially paying for interactions that don't come from real users, and it undermines the reliability of metrics used to evaluate advertising campaigns.

However, the economic exploitation of infected devices is not limited to advertising. A botnet, a network of remotely controlled devices, can be a marketable resource for other criminals. The more devices it includes, the greater the potential for abusing computing resources, hiding the origin of web traffic, and other illegal activities.

Article Image: Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Bitdefender does not specify the total financial benefit that the campaign’s operators have reaped. The extent of the spread, however, shows how even relatively small revenues per device can gain significant value when aggregated on a large scale.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Incidents in more than 150 countries

The geographic spread of infected devices demonstrates that the threat is not limited to one market or region. According to Bitdefender data, Mexico and France are among the countries with the highest incidence, followed by Italy, the US, Germany, Brazil and Spain.

At a regional level, Western Europe and the Americas. This distribution highlights that supply chain-based campaigns can impact users in different markets, regardless of where the original source of the problem is located.

See also: Android car head units: Malware hides in updates

Thirteen apps on Google Play with the same malicious code

The investigation also uncovered 13 apps published on Google Play that contained the same ad fraud code . Theapps used different signing certificates and were associated with two developer accounts.

Although these apps did not have the same system privileges as the pre-installed malware, their presence suggests that the campaign is not solely based on infection during device manufacturing or distribution. The apps acted as an additional channel for the malicious code to spread.

Of particular concern is the reported behavior of disabling the Google Play Store and Play Protect protection mechanism when installing additional malicious components, before re-enabling them. Such a process can temporarily limit the ability to control applications and make it difficult to detect the activity.

malware - SecNews.gr

What users can do

Midnight Mimosa is a typical example of a supply chain threat, as contamination can precede purchase and survive routine cleaning operations.

Consumers should prefer devices from trusted manufacturers and official sales channels, check for available security updates, and avoid apps from unknown sources. The presence of a device in Google Play Protect is not an absolute guarantee that its firmware is clean.

See also: RemControl: New Android malware steals banking information

If a phone is showing unexplained activity, installing apps without permission, or showing unusual data and battery usage, further investigation is warranted. In case of suspected firmware-level infection , a simple factory reset may not be enough. The safest option is to contact the manufacturer or seller and, if the integrity of the software cannot be confirmed, replace the device.

The case highlights a critical issue for the budget smartphone market: low price should not be accompanied by opaque manufacturing processes and inadequate security controls. When malware is already inside the device, the user can be exposed from the very beginning, without having made any mistakes.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS