Protect.Computer
NEWS

Cheap Android Phones Ship With Midnight Mimosa Ad-Fraud Malware

· 2 min read · Device safety Malicious byte
Cheap Android Phones Ship With Midnight Mimosa Ad-Fraud Malware

Bitdefender researchers have found malware preinstalled in the firmware of thousands of cheap Android phones. The campaign, which they call Midnight Mimosa, affects low-cost, multi-brand devices built on MediaTek chips, including white-label and counterfeit models made to resemble Samsung Galaxy phones and iPhones. Bitdefender saw it on devices in more than 150 countries over roughly two years, with Mexico, France and Italy making up the largest shares, followed by the United States, Germany, Brazil and Spain. “It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled,” the researchers wrote.

The malicious app runs with system-level privileges, so it can silently install and remove apps, grant them permissions and load code supplied remotely. Its main use is ad and click fraud: it drops at least 32 disguised apps (fake weather, app-lock, note-taking, file-manager and OCR tools) that load real ads in invisible windows over other apps so impressions register without the owner seeing them. Bitdefender says the malware also collects device and installed-app information and can turn phones into residential-proxy relay nodes and botnet members, and that it temporarily disables the Google Play Store while installing payloads. Thirteen apps on Google Play talked to the same infrastructure; they have no special privileges but could also show ads outside the app. Bitdefender has not determined who planted the malware or at what point in the supply chain. Some affected firmware was signed with certificates bearing the name of Shenzhen Zediel, but the researchers say that does not show the company created or knew about it. The phones are sold through mainstream online marketplaces; one examined device cost about $180.

How to check if you’re affected

Affected devices are low-cost Android phones, often unbranded or imitating a better-known model, running on MediaTek platforms and bought through online marketplaces. Bitdefender’s report lists the system package names (for example com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot and com.android.sys.bcprot), the disguised payload apps and the 13 Google Play apps tied to the campaign, so compare your installed apps and system packages against it. Because the malware is in the firmware, removing the visible apps may not clear it; the sources do not describe a fix, so treat such a phone as untrusted for banking and other sensitive accounts and consider replacing it with a device from a known vendor.

Sources

Related reading