Low-cost Android phones ship with residential proxy malware

Low-cost Android phones found to ship with residential proxy malware, threatening user data and online security.

A disturbing trend has emerged in the world of low-cost Android smartphones. Researchers at Bitdefender have discovered that thousands of devices across 150 countries are being shipped with malicious software embedded directly into their firmware. Dubbed “Midnight Mimosa,” this campaign is a wake-up call for users to take control of their online security.

The malware, which has been present in these devices for over two years, gives attackers system-level privileges that allow them to silently install apps, perform ad fraud, and turn devices into residential proxies. This means that even if you’re using a legitimate app or service, your device can be hijacked by malicious actors without your knowledge.

The campaign is believed to have affected millions of users worldwide, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain. The malware has been found on devices from reputable manufacturers, including Samsung and Apple impersonators, as well as legitimate brands like Doogee and Cubot.

One Doogee Fire 3 Max owner reported that an official firmware update infected their device with the malware, which disappeared after restoring an older firmware version but returned when the update was installed again. This raises serious questions about the security measures in place within these manufacturers’ supply chains.

Unlike traditional Android malware, Midnight Mimosa doesn’t require users to install a malicious app; it’s already embedded in the device’s system partition when customers receive their phones. The malicious programs impersonate legitimate Android system packages, making them nearly impossible to remove through standard means. These applications are signed and run with elevated system privileges, allowing them to evade detection.

Bitdefender discovered the campaign after its App Anomaly Detection technology flagged a suspicious system application named com.android.system.lite that was silently installing and removing other applications. Further investigation revealed a larger malware framework downloading additional modules from command-and-control (C2) servers to perform different malicious activities.

The researchers identified over 32 applications distributed through this framework, including apps disguised as weather utilities, file managers, app lockers, OCR tools, and audio editors. These applications are used to generate fraudulent advertising impressions and clicks, with some displaying advertisements in hidden windows or automatically interacting with ads without the device owner’s involvement.

To avoid falling victim to Midnight Mimosa, users should exercise caution when purchasing low-cost Android devices. If you suspect your phone has been infected, don’t rely on firmware updates from manufacturers; instead, back up your data and consider performing a factory reset. This may not eliminate the malware entirely, but it will prevent further malicious activity.

In light of this disturbing trend, users are reminded to remain vigilant when using their mobile devices online. Always keep your operating system and apps up-to-date, use reputable security software, and be cautious when installing new applications or accepting updates. By taking control of your online security, you can minimize the risk of falling prey to malicious campaigns like Midnight Mimosa.


Source: Bleeping Computer — 2026-10-08