Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
Description
Midnight Mimosa is a malware campaign involving preinstalled firmware malware on low-cost Android devices, primarily built on MediaTek platforms. The malware runs with system-level privileges, allowing remote operators to install and remove apps, grant permissions, and load arbitrary code. It is focused on ad fraud, automated click fraud, and building large botnets. The campaign affects devices in over 150 countries, with no single region dominating. Additionally, related apps carrying the same malware code have been found on Google Play, though with less privilege. The malware disables Google Play Protect during malicious app installations to evade detection. This campaign represents a supply-chain threat with persistent, preinstalled malware that cannot be removed by normal uninstall methods.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Midnight Mimosa is a persistent malware campaign discovered by Bitdefender that targets low-cost Android devices, primarily those built on MediaTek platforms. The malware is preinstalled in the device firmware as a system app with system-level privileges, enabling remote operators to silently install and remove apps, grant permissions, and execute arbitrary code. The campaign's primary activities include ad fraud and automated click fraud, leveraging infected devices as components of large botnets. The malware disables Google Play Protect temporarily to install additional payloads without detection. Bitdefender observed thousands of unique infected devices across more than 150 countries, with significant presence in Mexico, France, Italy, the US, Germany, Brazil, and Spain. The campaign also includes 13 related apps found on Google Play, which share code markers but lack system-level privileges. Midnight Mimosa exemplifies a supply-chain compromise where malware is integrated into devices before sale, providing attackers extensive control from device activation.
Potential Impact
The malware grants attackers system-level control over infected Android devices, enabling them to install and remove apps silently, manipulate permissions, and execute arbitrary code remotely. This control facilitates large-scale ad fraud and click fraud operations, generating revenue for attackers. Additionally, infected devices can be conscripted into botnets for further malicious activities. The malware's persistence as preinstalled firmware means it cannot be removed by standard uninstall procedures, making affected devices permanently compromised unless reflashed or replaced. The disabling of Google Play Protect during payload installation increases the risk of undetected malicious activity. The widespread distribution across 150+ countries indicates a global scale threat with significant potential impact on users of low-cost Android devices.
Defensive Guidance
No official patch or remediation is indicated in the provided information. As this is a supply-chain malware preinstalled on devices, remediation typically requires device replacement or reflashing with clean firmware. Users should avoid purchasing low-cost Android devices from untrusted sources, especially those with MediaTek platforms known to be affected. Monitoring for suspicious app behavior and using reputable mobile security solutions may help detect related malicious activity. The presence of related malicious apps on Google Play suggests caution when installing apps, even from official stores. Users and organizations should consult vendor advisories and security reports for updated mitigation guidance. Since the malware disables Google Play Protect during installation, relying solely on Play Protect is insufficient. No indication that the malware is currently mitigated or that no action is required.
Technical Details
- Classification
- {"confidence":0.67,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/","fetched":true,"fetchedAt":"2026-10-09T10:03:22.373Z","wordCount":1274}
Threat ID: 6ac8bbea2cdf04f65647f69f
Added to database: 10/09/2026, 10:03:22 UTC
Last enriched: 10/09/2026, 10:03:31 UTC
Last updated: 10/09/2026, 16:03:23 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.