Midnight Mimosa malware is preinstalled on cheap Android phones

A drawing of a phone with a lock on it surrounded by malware bugs.

When you buy a new phone, pre-installed malware is probably the last thing you'd think of.

For some, however, that nightmare may be coming true, as researchers have uncovered a malware campaign targeting low-cost Android smartphones.

The devices are already compromised before you get a chance to use them. Bitdefender highlighted the discovery of a malicious scheme called Midnight Mimosa in its blog.

The malware is pre-installed in the device's firmware, so even if the owner hasn't turned on the device, the threat is still there. To make matters worse, you can't uninstall it like a regular Android app, so you're stuck with it.

Midnight has powerful system-level access

Midnight Mimosa relies on a persistent system app that is built into the phone's firmware, giving it system-level access.

The researchers discovered 32 disguised apps that were linked to this fraudulent operation. These apps are used for advertising and click fraud, generating fake impressions without users' consent or knowledge.

The campaign is more planned than we might have guessed, as the malware can temporarily disable the Google Play Store app while carrying out some of its payloads. The Play Store is re-enabled after the payloads come into play.

Toggling Google Play Store helps bypass detection by Google Play Protect during installation.

The affected phones are mostly cheap Android devices

Midnight Mimosa is reported on budget multi-brand Android devices built on MediaTek platforms, and although these are mostly lesser-known models, it has still affected smartphones in more than 150 countries.

Some devices are counterfeit clones of more premium models such as the Galaxy S24 Ultra or S26 Ultra, but genuine Samsung phones remain unaffected.

The full list of devices affected by the threat remains unknown at this stage, but researchers have highlighted a range of low-cost Android phones that were part of the malware campaign.

The investigation further uncovered 13 Google Play apps communicating with the same infrastructure as Midnight Mimosa. This means the threat is more widespread than the infected phones.

Midnight Mimosa is a reminder to buy phones from authorized sellers and invest in original devices to avoid being handed harmful software. If you are one of the unfortunate ones ended up with the security threat, there is not much you can do to remove it, and your best bet would be to replace the device altogether.

Original source Midnight Mimosa malware is preinstalled on cheap Android phones

Back to home