NEW DELHI — Serious security concerns have emerged over budget Android smartphones after cybersecurity researchers discovered a widespread malware operation, dubbed Midnight Mimosa, embedded directly inside device firmware. Operating silently for nearly two years, the campaign has affected thousands of handsets across more than 150 countries. Because the malicious code sits within the core system software rather than conventional user-downloaded applications, it activates the moment a phone is powered on. Security analysts at Bitdefender found that the malware grants attackers deep system-level privileges, allowing them to install unauthorized software, run advertising fraud, and convert victim devices into residential internet proxies.
Supply Chain Vulnerabilities and System-Level Access
The investigation revealed that the compromised firmware primarily targeted low-cost smartphones equipped with MediaTek processors. Affected hardware included models such as the Doogee S200 X and the Cubot KingKong X, alongside counterfeit units designed to imitate devices from Samsung and Apple, though researchers noted that such imitations do not indicate involvement by those brands. Investigators suspect the malicious code was introduced somewhere along the hardware supply chain, though it remains undetermined whether the tampering occurred during manufacturing, software development, or third-party distribution.
Equipped with elevated operating permissions, the firmware disguised its components under names resembling legitimate Android system processes, including packages such as com.android.system.lite and com.android.sys.prot. These system privileges meant standard uninstallation methods were entirely ineffective. Frustrated users on technical forums reported that suspicious applications consistently reappeared after manual deletion. In one documented case, an owner of a Doogee Fire 3 Max traced the infection directly to an official manufacturer software update. While reverting to an earlier firmware build resolved the issue, reinstalling the newer build brought the malware back immediately. Although some manufacturers later issued corrective patches that removed the infection, none provided a public explanation regarding how the malicious code entered their firmware in the first place.
Deceptive Applications and Covert Ad Fraud
Beyond firmware tampering, researchers identified approximately 32 deceptive applications masquerading as routine utilities, including weather monitors, file organizers, app lockers, audio editors, and optical character recognition tools. These utilities served as vehicles for lucrative advertising fraud. According to the investigation, the software loaded commercial advertisements inside invisible background windows and generated synthetic clicks without the user’s knowledge, generating illicit revenue for the operators.
To protect its operations from discovery, the malware could temporarily disable the Google Play Store on infected devices. Researchers noted that this tactic allowed malicious software to bypass security evaluations conducted by Google Play Protect during installation. Once installation finished, the Play Store was restored to normal operation. In addition, altered installer records were deployed to make unauthorized applications appear as though they had been sourced legitimately from official application stores.
Traffic Redirection and Residential Proxy Networks
A particularly severe element of the campaign involved converting infected smartphones into network relays, or residential proxies. This functionality enables malicious actors to route unauthorized internet traffic through private consumer connections, masking their original location and infrastructure behind legitimate consumer IP addresses.
Researchers located a dedicated TCP proxy component within an application labeled com.mobile.applock.en, which maintained connections to an external command server capable of instructing the smartphone to relay network requests. While researchers did not observe active traffic relaying through newly registered test devices during their assessment, the command server remained operational and continued accepting new handset registrations. Bitdefender noted that resolving these deep-seated infections is difficult for non-technical users, typically requiring manufacturer-level firmware updates or manual removal via the Android Debug Bridge.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics