Bitdefender has uncovered Midnight Mimosa malware embedded in low-cost Android firmware, giving attackers system-level control over thousands of devices in more than 150 countries.

Budget Android Phones Found Shipping With Preinstalled Malware Across 150 Countries

The420 Web Correspondent
6 Min Read

Security researchers have uncovered a global Android malware campaign in which malicious software is embedded directly into the firmware of some low-cost smartphones before they reach buyers.

Bitdefender has named the campaign Midnight Mimosa.

The malware has been observed on thousands of devices in more than 150 countries and can silently install applications, grant permissions, load new code and turn infected phones into parts of large botnets.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Malware Is Present Before the Phone Is First Used

Unlike most Android malware, Midnight Mimosa does not depend on a user clicking a malicious link or installing an unsafe APK.

Bitdefender says the malicious component is already inside the device firmware.

Because it operates as a system application, it receives privileges ordinary apps do not have.

That allows it to install or remove applications without normal user interaction, grant sensitive permissions and execute code delivered remotely by its command-and-control infrastructure.

The malware also survives normal attempts to remove it because it resides in the system partition.

A regular uninstall is therefore not enough.

Ad Fraud and Proxy Abuse Are Main Uses

Researchers say the campaign appears primarily designed to make money.

The malware performs automated advertising and click fraud and collects information about infected devices and installed applications.

It can also turn a phone into a residential proxy node.

That means internet traffic belonging to someone else can be routed through the victim’s device and IP address.

Such proxy networks are valuable because malicious traffic can appear to come from ordinary residential internet connections rather than known data centres or suspicious servers.

The same infrastructure could potentially be used for broader botnet activity because operators retain extensive remote control over affected devices.

Doogee and Cubot Models Appeared in Research

Bitdefender observed infections associated with low-cost Android devices built on MediaTek platforms.

Among the highest-volume model strings seen were the Doogee S200 X and Cubot KINGKONG X.

Researchers also saw firmware identifying devices using names that imitate high-end products, including supposed Galaxy and iPhone models.

That does not mean genuine Samsung or Apple devices are infected.

Some of the affected hardware appears to be counterfeit or white-label Android equipment using misleading model names.

It also does not establish that every Doogee or Cubot device is affected.

Bitdefender has not published a complete list of compromised models.

Supply Chain Entry Point Is Still Unknown

The biggest unanswered question is who placed the malware into the firmware.

Bitdefender describes Midnight Mimosa as a supply-chain threat because the malicious code appears to have been introduced before sale.

But researchers have not determined whether that happened at a manufacturer, firmware provider, intermediary or some other point in the production chain.

Some affected firmware was associated with certificates bearing the name Shenzhen Zediel Co., Ltd.

Researchers cautioned that this does not prove the company created the malware or knowingly distributed compromised firmware.

Attribution therefore remains unresolved.

Malware Temporarily Blinds Google Play Protect

Midnight Mimosa also includes techniques designed to avoid Android’s built-in security mechanisms.

Researchers observed the malware disabling the Google Play Store or interfering with Play Protect while additional applications were installed.

The security controls were then restored after installation.

This creates a short period in which malicious applications can be installed without Google’s normal scanning protections operating as expected.

Bitdefender says the malware can also disguise installed applications as legitimate utilities such as weather tools, file managers or other everyday software.

Same Malware Family Reached Google Play

The campaign is not limited to compromised phone firmware.

Bitdefender also found 13 applications on Google Play containing code linked to the same broader Midnight Mimosa ecosystem.

Those apps were distributed through two developer accounts and used separate signing certificates.

The Google Play versions did not have the same system-level privileges as the malware embedded in firmware.

But their presence shows that the operators had more than one way to reach Android users.

That makes the campaign both a device-supply-chain problem and an app-distribution problem.

Users Cannot Easily Fix an Infected Phone

For ordinary users, this is one of the most difficult types of Android compromise to solve.

A factory reset may not remove malware embedded in the firmware.

Bitdefender says proper remediation may require replacing or reflashing the firmware with a trusted clean version.

For many buyers, that is not realistic.

The safer option may be to stop using a confirmed affected device for banking, email or other sensitive activity and replace it if a trusted firmware image is unavailable.

The case also shows why buying extremely cheap or counterfeit smartphones from unknown sellers can carry risks that are invisible at the time of purchase.

What this means for you

If a new budget Android phone behaves strangely, installs apps by itself or shows unexplained advertising activity, do not assume a factory reset will solve the problem. Buy devices from reputable sellers, check that the hardware is Play Protect certified, and avoid using a suspicious handset for banking or sensitive accounts until the firmware can be verified.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected