// 1 ZERO-DAY · 2 CVE IN THE LAST 24H→
The Midnight Mimosa campaign has infected the firmware of thousands of budget Android devices. The malware generates ad fraud and turns phones into residential proxy nodes for DDoS botnets, operating with system-level privileges before the user ever powers on the device.

Bitdefender has documented a campaign of malware preinstalled in the firmware of budget Android smartphones sold online, affecting thousands of devices across more than 150 countries over roughly two years. The payload, dubbed Midnight Mimosa, operates with system-level privileges before the user turns on the phone for the first time, making removal impossible without advanced technical intervention. The discovery, published today, exposes a systemic failure in the hardware supply chain that no pre-installed antivirus can fix.

Key Takeaways
  • The Midnight Mimosa malware is preinstalled in the ROM firmware of budget Android smartphones with MediaTek chips, including Doogee, Cubot brands, and counterfeit white-label devices
  • The payload operates with platform-level system privileges, silently installs at least 32 disguised apps, and disables Google Play Store to evade Play Protect
  • 13 apps officially distributed on Google Play communicate with the same command-and-control infrastructure and share the identical ad-fraud code
  • Monetization occurs via legitimate ad SDKs loaded in invisible windows, with the capability to convert devices into residential proxies for DDoS botnets

How the Firmware-Level Infection Works

The Midnight Mimosa mechanism nests upstream of user interaction. According to the Bitdefender researchers' blog, the malware "ships preinstalled in the device firmware" and activates on the device's first boot. The platform-level signature grants it system privileges that no user app can obtain, allowing silent installation of additional applications, automatic granting of sensitive permissions, and downloading of remote executable code.

Persistence relies on techniques that exploit Accessibility Services and Notification Access — Android mechanisms normally intended for visually impaired users but here weaponized for device control. Native libraries compiled for the ARM architecture of MediaTek chips handle runtime activation, making the malware's footprint independent of the Java framework and harder to detect via conventional static analysis.

Play Protect evasion occurs through a telling technical precaution: the payload temporarily disables the Google Play Store application immediately before installing new components. This suggests the operators know Google's scanning timing and mechanisms, adapting the malware's behavior to reduce exposure to standard security checks.

"The malware ships preinstalled in the device firmware. It's on the phone before the owner switches it on for the first time, and it can't be uninstalled." — Bitdefender Labs

The Fraud Infrastructure: 32 Disguised Apps and C2 Hidden in Weather APIs

Bitdefender identified at least 32 disguised applications distributed by the preinstalled malware, with names mimicking legitimate utilities: weather apps, OCR scanners, notes, app-locks, calculators, and file managers. Once installed, they load advertisements via legitimate SDKs — Google AdMob and analogues — but render them in windows invisible to the user, generating fraudulent impressions and clicks without any real interaction.

The command-and-control server masquerades as a weather API service, an exfiltration into daily data traffic that reduces visible anomalies to network monitoring tools. From this node, operators coordinate ad payload rotation and activate secondary capabilities on compromised devices.

A particularly concerning element involves the Google Play ecosystem. According to The Record Media, which directly cited the researchers, 13 applications officially published on the Google Play store communicate with the same C2 infrastructure and contain the identical ad-fraud code. This overlap between preinstalled malware and apps distributed through the official channel raises questions about Google's controls that the dossier does not clarify.

From Ad Fraud to DDoS Botnet: The Dual Monetization

The campaign combines two profit models. The primary, explicitly stated by Bitdefender Labs, is revenue generation via ad fraud and click fraud: "This scheme is likely designed mainly to generate revenue. The operators carry out ad and click fraud, collect device and installed-app information." The second model, documented in the same report, expands the value of the compromised device beyond advertising.

Researchers found that Midnight Mimosa can "turn infected devices into residential-proxy relay nodes, making them zombies in botnets" and "helping launch DDoS attacks when called upon." The conversion to residential proxy is strategic: residential IP addresses, unlike data center IPs, traditionally enjoy greater trust in anti-fraud and rate-limiting systems, making both distributed attacks and ad fraud itself more effective.

The collection of "device and installed-app information" adds a further layer of value, enabling granular profiling for the sale of access to ad networks and data brokers. The dossier does not quantify the revenue generated by the campaign nor the volume of DDoS traffic actually routed.

The Compromised Supply Chain: Where the Malware Enters

The precise point of insertion in the supply chain has not been determined. Bitdefender lists four non-exclusive hypotheses: the ODM (Original Design Manufacturer) that produces the device, the integrator that compiles the firmware, a logistics partner handling distribution, or other intermediaries in the chain between factory and end consumer.

An indicative technical datum emerges from the firmware signature: some analyzed images bear certificates in the name of Shenzhen Zediel, a Chinese company whose role in the malicious distribution — or awareness of its involvement — is not documented. Researchers explicitly stated they cannot attribute responsibility based solely on the certificate's presence.

The examined devices — sold for approximately $180 — include recognized budget brands like Doogee and Cubot, alongside counterfeit white-label products that aesthetically replicate premium models. According to researchers cited by The Record Media: "The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones. One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards."

What to Do Now

The preinstalled nature of the malware drastically reduces remediation options for the average user. Bitdefender detected the campaign via behavioral anomaly detection on its own endpoints, not via static signatures: the malware was already present when the antivirus was installed, but its runtime activity pattern triggered the alert. This indicates that continuous behavioral monitoring, rather than preventive scanning, represents the effective line of defense.

  • Avoid purchasing budget Android smartphones via unauthorized online marketplaces, especially white-label devices or those priced significantly below market
  • For devices already owned and suspected, request technical verification at authorized brand service centers; removal requires firmware flashing or ADB interventions
  • Monitor anomalous battery consumption and data traffic, which may signal residential proxy activity or background ad loading
  • Report suspicious apps to Google Play Support that exhibit excessive permission request patterns for seemingly innocuous categories like weather apps or notes

Why This Discovery Changes the Mobile Security Paradigm

Midnight Mimosa is not a case of a user tricked by a malicious app: it is proof that the entire pre-sale protection stack can be bypassed upstream. Play Protect, Google certification, firmware signature checks — all these mechanisms assume the software present at first boot is legitimate. When the threat actor inserts the payload into the ROM image, every subsequent defense operates on false premises.

The campaign's geography — with Italy among the hardest-hit countries after Mexico and France — indicates the phenomenon is neither marginal nor confined to emerging markets. The presence of 13 apps on Google Play linked to the same infrastructure further suggests the boundary between preinstalled malware and the official ecosystem is more permeable than Google and vendors acknowledge.

The mobile security sector faces a structural challenge: detection must shift from the entry point to the point of behavior, accepting that initial compromise may be undetectable. Bitdefender has demonstrated this transition is technically possible, but it requires distributed behavioral analysis capabilities that few consumer users possess independently.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. therecord.media
  2. nvd.nist.gov
  3. bitdefender.com
  4. androidauthority.com
  5. krebsonsecurity.com