The prominent cybersecurity firm Bitdefender recently published a comprehensive report revealing a massive malware campaign dubbed Midnight Mimosa. This insidious operation primarily targets budget-friendly Android devices. Shockingly, the malware exists on these smartphones long before the user ever powers them on for the very first time. Essentially, original equipment manufacturers (OEMs) are pre-installing this malicious software directly onto the devices. Once an unsuspecting user purchases and successfully activates their new smartphone, the dormant malware simultaneously awakens. Consequently, it immediately begins facilitating a myriad of nefarious activities.
Camouflaged as Essential System Components
Bitdefender asserts that its dedicated security research team discovered this alarming activity across thousands of compromised devices. These infected smartphones span across more than 150 different countries and diverse regions globally. The profoundly affected devices encompass numerous recognizable brands alongside various unbranded, generic models. Deceptively, the malware meticulously disguises itself as fundamental system components.
Operating with dangerous system-level privileges, it silently executes commands while the user remains completely oblivious. It can stealthily install or ruthlessly uninstall applications, unilaterally grant expansive permissions, and seamlessly load remote code. Furthermore, the malware cunningly disables the official Google Play Store temporarily. During this vulnerable window, it installs malicious payloads cleverly disguised as benign weather applications, file managers, or application lock utilities. Once the insidious installation completes, it promptly restarts the app store. This calculated maneuver significantly reduces the probability of detection by Google Play Protect. Ultimately, these hidden payloads are relentlessly utilized to conceal aggressive ad displays and systematically execute automated ad clicks.
Exploiting Devices as Residential Proxies
The malicious payload harbors even more sinister capabilities, including a sophisticated TCP proxy function. This insidious feature can forcefully register the victim’s device as a remote-controlled relay node. Consequently, third-party network traffic is systematically routed directly through the user’s personal network, effectively obscuring the true origin of the traffic. Alternatively, attackers can exploit this relay node to infiltrate the user’s internal, localized network.
However, Bitdefender currently can only verify the definitive existence of the proxy control interface. During their rigorous practical testing, researchers did not observe any actual forwarded targets. Therefore, they remain unable to confirm definitively whether the compromised test devices successfully forwarded any illicit traffic.
Uncovering the Origins and Supply Chain Risks
Intriguingly, specific model identifiers related to the Doogee S200X and Cubot KINGKONG X frequently appeared within the extensive telemetry records. Furthermore, the diligent security team discovered the name of Shenzhen Zedi Technology embedded within certain firmware signature certificates. Despite these compelling clues, the precise stage at which the malware is illicitly implanted remains unconfirmed. Nevertheless, the industry has certainly witnessed horrifying historical precedents where malicious software was covertly injected during the precarious flashing process within the intricate supply chain.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!