
A malware campaign dubbed “Midnight Mimosa” was discovered on cheap Android smartphones that shipped with malware embedded in their firmware, allowing attackers to silently install apps, carry out ad fraud, and turn the devices into residential proxies.
The malware is believed to have been introduced somewhere in the devices’ supply chain, but it is not clear who is responsible for modifying the firmware or at what stage the tampering took place.
The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, granting it system-level privileges that allow it to install and remove apps, grant sensitive permissions, and execute downloaded code remotely without user interaction.
According to Bitdefender researchers, the campaign affected thousands of devices in more than 150 countries over a period of approximately two years, with the highest number of victims recorded in Mexico, France, Italy, the United States, Germany, Brazil and Spain.
Researchers found pre-installed malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as on phones impersonating Samsung and Apple products.
In a post on the XDA Forums, owners of Cubot and Doogee smartphones reported finding suspicious apps that repeatedly reinstalled themselves after deletion.
A Doogee Fire 3 Max owner also reported that an official firmware update infected the device with the malware, which disappeared after restoring an older firmware version, but returned when the update was reinstalled.
Some users said that manufacturers released firmware updates that fixed the infections. However, the manufacturers have not publicly explained how the malware was introduced into the affected firmware.
Bitdefender also mentioned the XDA forum post in its report and said that one of the malicious packages reported by forum users, com.android.non.szczis part of the same malware family.
Pre-installed Android malware
Unlike regular Android malware that requires users to install a malicious app, Midnight Mimosa is already installed in the device’s system partition when customers receive their phone.
Malware impersonates legitimate Android system packages, using names like com.android.system.lite, com.android.sys.protAnd com.android.sys.gmsprot.
Since these apps are signed and run with elevated system privileges, they cannot be removed through the normal Android app uninstallation process.
Bitdefender discovered the campaign after its application anomaly detection technology flagged a suspicious system application named com.android.system.lite which silently installed and removed other applications.
Further investigation determined that the application was part of a larger malware framework that downloads additional modules from command and control (C2) servers to perform different malicious activities.
Researchers identified around 32 apps distributed through the framework, including apps disguised as weather utilities, file managers, app lockers, OCR tools, and audio editors.
“The system app itself does not record fraudulent impressions and clicks,” Bitdefender explains.
“The revenue engine is driven by discontinued cover apps, including Weather, App Lock, Ratings, and OCR apps, which load authentic ads through a legitimate ad SDK. The objective is simple: load an invisible window above the applications which records the advertisements broadcast.
These apps are used to generate fraudulent ad impressions and clicks, with some displaying ads in hidden windows or automatically interacting with ads without the participation of the device owner.
The malware also uses techniques designed to evade Android’s security protections.
Before silently installing malicious apps, it temporarily disables Google Play Store app, com.android.vendingwhich, according to Bitdefender, aims to prevent Google Play Protect from detecting the installation.
Once the installation is complete, the malware reactivates the Play Store to avoid arousing suspicion.
Some malware variants also manipulate recorded Android installation information to make it appear that malicious apps were installed through Google Play, even if they were deployed directly by the malware.
The malware also includes features that turn infected Android phones into residential proxies capable of relaying network traffic.
Bitdefender has identified a malicious application disguised as an application locker, com.mobile.applock.enwhich contains a TCP proxy component that registers infected devices with a remote command server.
Once registered, the malware can receive instructions to connect to specified hosts and forward traffic through the infected device.
This could allow attackers to route malicious traffic through phone owners’ Internet connections, thereby hiding the true origin of attacks or allowing access to devices accessible from the infected device.
Bitdefender confirmed that the proxy command and control infrastructure was operational and accepting device registrations.
However, in their testing, the researchers said their newly registered device did not receive any relay targets and so they could not confirm whether the attacker was actively forwarding traffic.

Source: Bitdefender
Researchers also discovered 13 Android apps distributed through the Google Play Store that contained the same ad fraud code and communicated with known Midnight Mimosa infrastructure.
Unlike pre-installed system components, these applications do not have elevated privileges necessary to silently install other software.
However, they can still display ads outside of their user interface, including when users are not using their phone.
The apps were distributed using 13 different signing certificates and at least two developer accounts, identified as fivedev And CPS Developer.
Researchers also discovered firmware signed using certificates associated with Chinese device maker Shenzhen Zediel, but said it was unclear whether the company was involved in the malware campaign.
For affected consumers, malware removal is difficult because the malware is installed as a high-privileged system application.
Bitdefender states that removing the infection requires cleaning at the firmware level or disabling the malicious component using Android Debug Bridge (ADB), which can be complicated for many users.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL and Atlassian for a two-hour digital summit on what attacks change at AI speed, what defenders should stop doing and how to validate, decide, remediate and revalidate at machine speed.
Save your place
Gn tech

