Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Bitdefender researchers have uncovered the Midnight Mimosa malware preinstalled on low-cost MediaTek Android phones, enabling ad fraud and proxyware activity. This malware affects multiple low-cost Android phone brands built on MediaTek platforms, allowing operators to install apps, grant permissions, and load code without the owner’s consent. The infection occurs below the normal app-installation layer.
In their research, Bitdefender notes that “every user-facing defense had already been bypassed” by the time the phone was switched on. The malware hides in system packages such as com.android.system.lite and com.android.sys.prot. Because these packages run with Android system privileges, users cannot normally remove them. A native library called libeasy.so decrypts another component and connects to api.weatherlive.world to download more code.
Key Observations
- The malware can install or remove apps without user consent and grant those apps additional permissions.
- The main activity observed was not data theft but monetization. It utilizes ad fraud and proxyware, leveraging its privileged access to change or expand the payloads later.
- Proxyware turns a device’s internet connection into a relay for other traffic, often making that traffic appear to come from the infected user’s IP address.
To evade detection, the malware temporarily disables the Google Play Store package, com.android.vending, before installing a payload and restores it afterward. This may create a window for payload installation while avoiding normal Play Protect checks. The malware can also make a sideloaded app appear to have been installed from Google Play, even though it lacks the cryptographic “frosting” marker found on genuine Play apps.
Bitdefender found payloads such as com.mobile.applock.en, which connects to a proxy network over TCP port 6000, and com.mobile.applock.wt, which contains an ad-fraud module. The malware also installs apps for functions such as weather, AppLock, notes, and OCR. These apps use legitimate advertising SDKs, but the malware can run ads in the background and generate fake impressions and clicks without the user seeing them.
Global Impact
Bitdefender observed thousands of infected devices in more than 150 countries. Affected hardware included counterfeit phones reporting names such as “S25 Ultra” and “i17 Pro Max,” along with budget models including the Doogee S200 X and Cubot KINGKONG X. The same ad-fraud code was also found in 13 Google Play apps, indicating that the operation was not limited to preinstalled firmware.
A platform certificate used by com.android.system.lite was associated with Shenzhen Zediel Co., Ltd. However, Bitdefender stated that this does not prove the company inserted or knowingly distributed the malware. The entry point of the malware into the supply chain remains unknown.
Conclusion
For buyers, the issue is that a normal factory reset or uninstall may not suffice. Midnight Mimosa resides in system-level firmware, so affected devices may require trusted firmware replacement, vendor remediation, or even replacement of the phone itself.
To read the complete article see: Read full article