A malware campaign, dubbed 'Midnight Mimosa', has been identified on low-cost Android smartphones. This malicious software is embedded directly into the devices' firmware, granting it system-level privileges. The malware enables attackers to silently install applications, conduct ad fraud, and convert infected devices into residential proxies.
The malware is believed to have been introduced into the device supply chain, though the exact point of tampering and responsible party remain unknown. It primarily affects devices utilizing MediaTek chipsets. Bitdefender researchers reported that the campaign impacted thousands of devices across more than 150 countries over approximately two years, with significant concentrations in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.
Preinstalled malware was found on devices with model names associated with legitimate manufacturers, including Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products. Users on XDA forums reported suspicious applications that reinstalled themselves after removal. One Doogee Fire 3 Max owner noted that an official firmware update introduced the malware, which reappeared after re-installing the update.
Unlike typical Android malware, 'Midnight Mimosa' is present in the device's system partition upon purchase. The malicious programs mimic legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Due to being signed and running with elevated system privileges, these applications cannot be removed through standard Android methods.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A malware campaign named 'Midnight Mimosa' has been discovered on low-cost Android smartphones, embedding malicious software in their firmware to install apps, perform ad fraud, and turn devices into residential proxies. The malware, present on devices from manufacturers like Doogee and Cubot, affected thousands of devices across over 150 countries by exploiting system-level privileges.