Particle.news

Midnight Mimosa Malware Found Preinstalled on Low‑Cost MediaTek Android Phones

Bitdefender says the firmware backdoor gains system privileges, runs ad fraud, turns phones into proxy relays, survives factory resets, and keeps related Play Store apps active.

Overview

  • Bitdefender researchers found a firmware‑level malware campaign they call Midnight Mimosa installed on multiple low‑cost Android models that use MediaTek chips.
  • The malicious code activates at first boot, runs with Android system privileges, can load remote code, and cannot be removed by normal uninstalls or factory resets.
  • Operators use invisible 'cover' apps and system‑sounding packages to generate ad and click fraud, collect device and app data, and turn infected phones into residential‑proxy nodes for botnets.
  • The operation hides under rotating system package names and temporarily disables Play Store checks to sideload payloads, and researchers linked 13 apps on Google Play to the same control servers.
  • Thousands of devices across many countries appear affected, and full remediation will likely require coordinated action from device makers, MediaTek, and Google or replacement of firmware or devices.