- Researchers have uncovered a malware campaign affecting some low-cost Android phones, including devices from Doogee and Cubot.
- Dubbed Midnight Mimosa, the malware is embedded in device firmware and can install apps, grant permissions, evade Play Protect, and turn phones into botnet nodes.
- The campaign has been seen on thousands of devices across more than 150 countries, and removing the malware isn’t easy because it lives in the system partition.
Over the years, we’ve been warned about the dangers of downloading unknown apps on our smartphones. The instructions have been clear: stick to the Google Play Store, and if you must sideload APKs, use trusted sources. Those instructions make sense when your phone is malware-free in the first place, but what if your phone was already compromised before you even took it out of its box?
That’s exactly the situation researchers at Bitdefender have uncovered, as shared on their blog. There’s a new malware campaign dubbed Midnight Mimosa, and as pleasant as that name sounds, you definitely don’t want it served to you.
