← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Low-cost Android phones ship with 'Midnight Mimosa' residential proxy malware

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malware 'Midnight Mimosa' found on low-cost Android phones.
  • Embedded in firmware, granting system-level privileges.
  • Used for app installation, ad fraud, and residential proxies.
  • Affected thousands of devices in over 150 countries.

Firmware-Embedded Malware Discovered

A malware campaign, dubbed 'Midnight Mimosa', has been identified on low-cost Android smartphones. This malicious software is embedded directly into the devices' firmware, granting it system-level privileges. The malware enables attackers to silently install applications, conduct ad fraud, and convert infected devices into residential proxies.

Supply Chain Infection

The malware is believed to have been introduced into the device supply chain, though the exact point of tampering and responsible party remain unknown. It primarily affects devices utilizing MediaTek chipsets. Bitdefender researchers reported that the campaign impacted thousands of devices across more than 150 countries over approximately two years, with significant concentrations in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

Affected Devices and User Reports

Preinstalled malware was found on devices with model names associated with legitimate manufacturers, including Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products. Users on XDA forums reported suspicious applications that reinstalled themselves after removal. One Doogee Fire 3 Max owner noted that an official firmware update introduced the malware, which reappeared after re-installing the update.

Malware Characteristics and Persistence

Unlike typical Android malware, 'Midnight Mimosa' is present in the device's system partition upon purchase. The malicious programs mimic legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Due to being signed and running with elevated system privileges, these applications cannot be removed through standard Android methods.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A malware campaign named 'Midnight Mimosa' has been discovered on low-cost Android smartphones, embedding malicious software in their firmware to install apps, perform ad fraud, and turn devices into residential proxies. The malware, present on devices from manufacturers like Doogee and Cubot, affected thousands of devices across over 150 countries by exploiting system-level privileges.