A Global Malware Campaign Targets Budget Android Devices in Over 150 Countries
A sophisticated malware campaign, dubbed Midnight Mimosa, has been discovered infecting budget Android devices across more than 150 countries. The malware, preinstalled on millions of devices built on MediaTek platforms, is a persistent and powerful tool that allows attackers to remotely control infected devices for malicious purposes.
When an affected device is turned on, the malware becomes active, granting system-level privileges to its operators. This enables them to silently install and remove apps, grant permissions, and load arbitrary code from remote servers. In essence, this means that attackers can turn each device into a botnet soldier, capable of performing tasks such as ad fraud and automated click fraud.
The campaign is not confined to preinstalled firmware alone; researchers also found 13 apps on the Google Play Store carrying the same ad-fraud code as the dropped cover apps. These apps do not have the same level of access as the preinstalled malware but are associated with the broader ecosystem, providing attackers with an additional distribution channel.
The malware’s ability to evade detection is impressive; it disables the Play Store before installing additional payload applications and then re-enables it afterward, likely to avoid triggering Google Play Protect. This sophisticated approach allows Midnight Mimosa operators to install malicious apps without being detected by the platform’s built-in scanner.
Bitdefender, the security firm that discovered the campaign, notes that the potential for this type of malware infection is massive, with thousands of unique affected devices observed in over 150 countries. The report highlights Mexico and France as leaders in terms of distribution, followed closely by Italy, the US, Germany, Brazil, and Spain.
The actual monetary gain achieved by Midnight Mimosa operators remains unclear, but researchers suspect that it is substantial due to the campaign’s focus on ad fraud and botnet rentals. With a large army of infected devices at their disposal, attackers can generate significant revenue from click frauds over time.
To prevent infections, users are advised to exercise caution when purchasing budget Android devices, especially those built on MediaTek platforms. Additionally, researchers recommend taking the following steps:
* Regularly update your device’s operating system and apps
* Use a reputable antivirus solution to scan for malware
* Be cautious of suspicious apps and their permissions
* Avoid installing apps from unknown developers
While Midnight Mimosa is a concerning development in the world of cybersecurity, it serves as a reminder of the importance of vigilance when dealing with budget Android devices. By taking proactive steps to protect our digital lives, we can minimize the risk of falling victim to such sophisticated malware campaigns.
Source: SecurityWeek — 2026-10-09