- Bitdefender found Midnight Mimosa preinstalled in firmware on thousands of low-cost <a href="https://myappsplus.com/amazon-launches-all-new-android-kids-tablets-where-to-buy/” title=”Amazon launches all-new Android kids tablets: Where to buy”>Android devices.
- Researchers observed affected devices in more than 150 countries, including Mexico, France, Italy, the US, and Germany.
- The malware can install apps, grant permissions, create ad fraud, run code, and turn phones into proxies.
- Removing it is difficult; researchers say vendors and marketplaces must fix the affected firmware.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Bitdefender researchers have discovered a malware campaign dubbed Midnight Mimosa, which comes preinstalled in the firmware of thousands of low-cost Android devices.
Over two years, the campaign was observed on “thousands of unique devices across more than 150 countries,” with Mexico, France, Italy, the US, and Germany in the top five.
The malware comes embedded in some Android devices using MediaTek chips, including phones marketed with misleading flagship-style names.
The application can silently install and remove other apps, grant permissions, generate fraudulent ad activity, and execute malicious code.
According to the researchers, some affected devices can also be used as residential proxies in a botnet.
Although the campaign was associated with low-cost, multi-brand Android hardware, researchers warn that such devices are not necessarily unsafe by default, but that “danger rises when a deal seems too good to be true”. This could include a current-generation flagship “at a ridiculously low price”, an unknown seller, or a listing that hides the actual manufacturer.
Researchers also identified 13 apps containing malware that were distributed through Google Play. The preinstalled component could temporarily disable the Google Play Store, allowing it to install malicious apps while avoiding detection by Google Play Protect.
The malware cannot easily be removed on affected phones, with researchers saying that “clearing the device requires firmware-level cleanup or disabling the component over ADB, and neither is realistic for most people who own these phones.”
“The durable fix sits with the vendors and the marketplaces that ship and sell the affected firmware,” they add.
The campaign is not currently attributed to any threat actor, and it’s unclear at what stage of manufacturing the compromise occurs.
Some affected firmware was signed with certificates associated with Shenzhen Zediel, which appears to be Zedi Technology, a Chinese manufacturer that designs smart hardware and motherboards for Rockchip processors. However, researchers could not establish whether the company was involved in the campaign.
“How these certificates ended up on those phones — and whether the certificate owner was involved in or aware of the malware deployment — remains unclear,” the researchers said.
Earlier in March, the BADBOX 2.0 botnet infected more than one million Android devices worldwide, with malware preinstalled on cheap, off-brand hardware.
