Malware called 'Midnight Mimosa' has been discovered pre-installed in the firmware of low-cost Android phones using MediaTek chipsets, affecting thousands of devices across over 150 countries. The malware, likely introduced during the supply chain, grants attackers system-level privileges to install apps, commit ad fraud, and convert devices into residential proxies without user knowledge.
Malware called 'Midnight Mimosa' was discovered pre-installed in the firmware of low-cost Android phones using MediaTek chipsets, allowing attackers to install apps, commit ad fraud, and convert devices into residential proxies. The malware affected thousands of devices across over 150 countries, with the highest concentration in Mexico, France, Italy, the US, Germany, Brazil, and Spain. The malicious software was likely introduced during the device supply chain, though the responsible party remains unidentified.