Malware called 'Midnight Mimosa' was discovered pre-installed in the firmware of low-cost Android phones using MediaTek chipsets, allowing attackers to install apps, commit ad fraud, and convert devices into residential proxies. The malware affected thousands of devices across over 150 countries, with the highest concentration in Mexico, France, Italy, the US, Germany, Brazil, and Spain. The malicious software was likely introduced during the device supply chain, though the responsible party remains unidentified.
Bitdefender researchers discovered Midnight Mimosa, a malware campaign preinstalled in firmware on low-cost MediaTek Android devices that runs with system privileges to commit ad fraud, collect device data, and operate botnets. The malware cannot be uninstalled and ships under rotating system package names, with 13 related apps also found on Google Play communicating with the same control servers.