Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Midnight Mimosa: Preinstalled Malware Turns Budget Android Phones Into Silent Profit Engines

Дата публикации: 09-10-2026 00:52:14

Bitdefender researchers exposed Midnight Mimosa, malware embedded in the firmware of cheap MediaTek Android phones before first use. The threat carries system privileges, performs ad fraud, collects data and turns devices into residential proxies across 150+ countries. Buyers of budget handsets face risks that ordinary security tools cannot fully address.

Основное содержимое страницы с новостью.

Buyers of low-cost Android handsets expect compromises. Slower processors. Fewer updates. But few anticipate the device arrives compromised from the first power-on.

Researchers at Bitdefender uncovered exactly that this week. They call the operation Midnight Mimosa. The malware sits inside the firmware of phones built on MediaTek chips. It carries system-level privileges. Ordinary removal methods fail.

“The malware ships preinstalled in the device firmware,” Bitdefender stated in its Oct. 8 report. “It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.” (Bitdefender Labs)

The core component often appears as a system app named com.android.system.lite. Variants include com.android.sys.prot, com.android.sys.gmsprot and others. Each carries platform signing certificates. Android treats them as trusted parts of the operating system. That trust opens doors.

Once running, the malware acts with broad authority. It installs and removes applications without user input. It grants permissions on demand. It downloads and executes arbitrary code from remote servers. Operators can reshape each device’s behavior over time. One day for ad fraud. Another for proxy traffic. The flexibility proves lucrative.

Bitdefender tracked the campaign across roughly two years. It touched thousands of devices. More than 150 countries saw infections. Mexico, France and Italy showed the highest numbers. The United States, Germany, Brazil and Spain followed. (The Record from Recorded Future)

Many affected phones sell as white-label products or outright counterfeits. Some mimic Samsung Galaxy models with names like S25 Ultra. Others copy Apple designs labeled i17 Pro Max. Legitimate budget brands also appear. Doogee S200 X and Cubot KINGKONG X models turned up in the telemetry. Firmware on certain units carried signatures tied to Shenzhen Zediel Co., Ltd., though Bitdefender stopped short of assigning blame.

The business model relies on volume and persistence. The malware deploys a rotating cast of at least 32 disguised payload apps. Fake AppLock utilities. Weather tools. File managers. OCR scanners. Audio editors. These apps use legitimate advertising SDKs yet run ads invisibly. They generate clicks that users never see. Battery drains. Data gets consumed. Revenue flows to the operators.

Thirteen additional apps carrying related code reached Google Play. Bitdefender noted them in its analysis. The company did not publish package names for those titles in the initial release. The presence on the official store shows how the campaign bridges preinstalled firmware and post-sale distribution.

One technical trick stands out for its precision.

Before pushing a new payload, the malware temporarily disables the Google Play Store. This step dodges Play Protect checks. Installation completes. The store reactivates. Users notice nothing unusual. The maneuver reveals planning. Operators understand Android defenses and work around them methodically.

Beyond advertising, the malware gathers device details and lists of installed apps. It can enroll phones as residential proxy nodes. Traffic routed through these devices appears to come from ordinary consumers. That value attracts botnet builders and fraud networks. Bitdefender observed the proxy functionality in action though it saw limited use of granted Accessibility or Notification permissions. Those capabilities remain available for future commands.

News outlets moved quickly on the disclosure. Bleeping Computer highlighted the residential proxy angle and noted user reports on XDA forums of suspicious apps that reinstall after deletion. One Doogee owner described a firmware update that introduced the malware; rolling back removed it temporarily. (Bleeping Computer)

HackRead emphasized the supply-chain uncertainty. “The malware is believed to have been introduced somewhere in the device supply chain, but it remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred.” (HackRead)

Android Authority, whose earlier coverage helped frame the discovery, pointed to the same core findings while stressing the risk to everyday buyers chasing bargains under $200. The publication linked the campaign to broader patterns of firmware tampering seen in past Android threats. (Android Authority)

Industry watchers note this case differs from typical sideloaded malware. Here the compromise precedes first use. Factory resets often fail because the code lives in the system partition. Advanced users might reflash clean firmware if they can locate unmodified images for their exact hardware. Most owners lack those skills or tools.

MediaTek did not issue an immediate public statement. The Taiwanese chipmaker supplies components to countless manufacturers, many of them small factories in Asia producing devices for online marketplaces. Responsibility likely fragments across the long supply chain. Firmware customization. Certificate signing. Quality control gaps. Each link offers an opportunity for insertion.

Google faces questions too. Its Play Protect service cannot scan system-level components embedded before shipment. The company has improved verification for new devices in recent years. Yet budget handsets often ship with older Android versions and minimal ongoing support. That leaves millions exposed.

So what should buyers do? Avoid ultra-cheap no-name phones sold primarily on third-party marketplaces. Check for clear manufacturer support promises. Prefer devices from brands that publish security update timelines. Even then, run reputable mobile security software that can detect anomalous behavior even if it cannot delete the root cause.

Enterprises sourcing bulk budget devices for field workers or kiosks face heightened risk. A single infected fleet could drain corporate data plans, generate fraudulent ad charges and expose network traffic through residential proxies. Procurement teams may need to add firmware integrity checks to their evaluation criteria.

The discovery arrives at a moment when Android holds roughly 70 percent of the global smartphone market. Low-cost models drive growth in emerging regions. Their owners often have fewer resources to spot problems or replace hardware. Midnight Mimosa exploits that dynamic with quiet efficiency.

Bitdefender researchers described the payloads as not entirely new. Similar ad fraud and proxy code has circulated before. The innovation lies in the delivery method and the scale of preinstallation. This campaign baked the threat into the device at a level most defenses never examine.

Further analysis may reveal exactly when and where the firmware received its malicious additions. Shenzhen Zediel certificates provide one thread. User complaints on forums supply another. Yet the operators have already profited for two years. Thousands of phones continue working as unwitting participants in a distributed revenue scheme.

Short-term fixes remain limited. Long-term pressure must fall on manufacturers, chip suppliers and marketplaces to demand verifiable clean firmware. Until then, the warning stands clear. Some phones come infected before their boxes even open. And their owners pay the price in data, battery life and unwitting participation in fraud.

Additional reporting from today reinforced the global reach. Italian and Spanish technology sites noted high infection rates in Southern Europe, aligning with Bitdefender’s charts. No new technical breakthroughs appeared in the first hours after publication, but the story continues to spread across security communities on X. (Undercode News)

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1На недорогих Android-смартфонах обнаружено предустановленное вредоносное ПО Midnight Mimosa011.2309-10-2026
2Вредоносное ПО в прошивках китайских Android-смартфонов на чипах MediaTek010.7609-10-2026
3Россию завалило крайне опасными смартфонами со встроенными вирусами. Они официально продаются в Ozon, Wildberries и «Яндекс Маркете»07.8709-10-2026
4Россию завалило крайне опасными смартфонами со встроенными вирусами. Они официально продаются в Ozon, Wildberries и «Яндекс Маркете»07.8709-10-2026
5Россию завалило крайне опасными смартфонами со встроенными вирусами. Они официально продаются в Ozon, Wildberries и «Яндекс Маркете»07.8709-10-2026
6Android-малварь Mantax Otax шифрует файлы, ворует данные и запугивает жертв09.211-09-2026
7Шпионское Android-приложение DragonDoll распространяется в 26 странах015.6924-08-2026
8Орловцев предупреждают, что Android-устройства могут быть заражены опасным вирусом013.7801-10-2026
9Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks07.9328-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 9.76. Источник: www.webpronews.com.