A new malware campaign called Midnight Mimosa has raised security concerns after researchers discovered that malicious software was pre-installed on some cheap Android smartphones. The threat is particularly concerning because the malware is built into the device’s firmware, meaning it can be present before users even turn on their new phones.
According to security researchers at Bitdefender, Midnight Mimosa is linked to a campaign involving disguised applications, fraudulent advertising activities, and system-level access. Unlike ordinary malicious apps, users cannot simply uninstall the malware through their phone’s settings.
Midnight Mimosa Malware Targets Cheap Android Smartphones in 150 Countries
The discovery highlights the risks associated with buying inexpensive smartphones from unknown brands or unauthorized sellers, particularly when the devices may contain modified or compromised software.
How Midnight Mimosa Malware Works
Midnight Mimosa operates through a persistent system application integrated into a smartphone’s firmware. This gives the malware elevated privileges that regular Android applications do not normally have.
With these privileges, the malicious software can install and remove applications, download additional code from remote servers, and grant permissions to other apps. These capabilities allow it to carry out activities without the user’s knowledge or approval.
Researchers also identified 32 disguised applications associated with the operation. These apps reportedly support advertising fraud by generating fake impressions and clicks, allowing the operators to benefit from fraudulent advertising activity.
Another concerning feature is the malware’s ability to temporarily disable the Google Play Store while executing certain malicious operations. It can restore the Play Store after completing these activities.
This technique may help the malware avoid detection by Google Play Protect during particular stages of its operation. It also makes the threat harder for ordinary users to identify because the phone may appear to work normally.
Cheap Android Phones Are the Main Target
The Midnight Mimosa campaign has primarily affected low-cost Android smartphones from multiple brands, particularly devices built on MediaTek platforms.
Although many affected models come from lesser-known manufacturers, the campaign reportedly reaches users in more than 150 countries. This suggests that the threat extends beyond a single market or region.
Researchers have also found that some affected devices are counterfeit copies of premium smartphones, including models designed to resemble the Samsung Galaxy S24 Ultra and Galaxy S26 Ultra.
However, genuine Samsung smartphones are not affected by this campaign, according to the report. The presence of counterfeit devices highlights the importance of checking a phone’s authenticity before purchasing it.
The complete list of affected smartphone models remains unknown. Therefore, buyers should not assume that every inexpensive Android phone is infected, but they should exercise caution when purchasing devices from unfamiliar sellers.
Researchers Find More Suspicious Apps
The investigation also uncovered 13 Google Play applications that communicated with the same infrastructure used by Midnight Mimosa.
This finding suggests that the campaign may extend beyond smartphones carrying the pre-installed malware. Applications communicating with the same infrastructure could represent another part of the broader operation, although their precise role requires further investigation.
The discovery also demonstrates why checking individual apps may not be enough to protect a device when the underlying firmware itself has been compromised.
Can Users Remove Midnight Mimosa?
Removing Midnight Mimosa may be difficult because the malware is integrated into the phone’s firmware rather than installed as a normal application.
Users generally cannot eliminate such threats by uninstalling an app or clearing the device’s storage. A factory reset may also fail to remove malware that resides in the firmware.
If a phone is suspected of carrying Midnight Mimosa, users should avoid entering sensitive information, including banking credentials and passwords, until the device’s security has been assessed. They should contact the manufacturer or a qualified security professional for guidance.
If the malware cannot be safely removed, replacing the device with a trusted, genuine smartphone may be the most practical option.
How to Avoid Pre-Installed Malware
The Midnight Mimosa discovery serves as a reminder to check a smartphone’s source before making a purchase. Buying from authorized retailers and established manufacturers can reduce the risk of receiving counterfeit or compromised devices.
Consumers should also be cautious of smartphones offered at unusually low prices, particularly models that imitate premium devices from well-known brands.
Keeping Android and installed applications updated is important for general security, but software updates may not resolve malware embedded in compromised firmware.
Ultimately, Midnight Mimosa shows that smartphone security risks can begin before a user installs their first application. Choosing a genuine device from a reliable seller remains one of the most effective ways to reduce the risk of buying a phone that already contains malicious software.
Leave a comment
Your email address will not be published. Required fields are marked *