A widespread malware campaign has been uncovered on low-cost Android smartphones, compromising thousands of devices worldwide. Dubbed “Midnight Mimosa,” this insidious threat embeds malicious software into the firmware of vulnerable phones, giving attackers unfettered access to sensitive information and system-level privileges.
The malware is believed to have been introduced somewhere in the device supply chain, but its exact origin remains unclear. However, it’s evident that legitimate manufacturers’ devices were affected, including models associated with Doogee, Cubot, Samsung, and Apple products. The highest number of victims was found in Mexico, France, Italy, United States, Germany, Brazil, and Spain.
Researchers at Bitdefender discovered the campaign after their App Anomaly Detection technology flagged suspicious system applications on compromised devices. Further investigation revealed that these apps were part of a larger malware framework, designed to silently install malicious software, perform ad fraud, and turn devices into residential proxies. The framework consists of approximately 32 applications, including weather utilities, file managers, app lockers, OCR tools, and audio editors.
These seemingly innocuous apps are actually used to generate fraudulent advertising impressions and clicks. By displaying hidden windows or automatically interacting with ads without the device owner’s involvement, attackers aim to deceive advertisers into paying for fake ad views. The malware also employs techniques to evade Android’s security protections, such as temporarily disabling the Google Play Store app to prevent detection.
One of the most concerning aspects of this campaign is its ability to survive firmware updates and reinstallation attempts. In some cases, restoring older firmware versions seemed to resolve the infections, only for the malware to return after updating again. This suggests that manufacturers may be unknowingly distributing infected firmware or that the malware has become deeply embedded in the device’s system.
While it’s unclear how widespread this issue is, Bitdefender estimates that thousands of devices across more than 150 countries were affected over a two-year period. Manufacturers have not publicly explained how the malicious software was introduced into their firmware, leaving users vulnerable to exploitation.
To mitigate this risk, Android phone owners should remain vigilant when installing apps and be cautious of suspicious system applications. Regularly updating your device’s firmware is crucial, but don’t rely solely on manufacturer updates – manually check for malware indicators and consider using reputable security software. In the face of this sophisticated threat, users must stay informed and take proactive steps to protect their devices from becoming part of the Midnight Mimosa campaign’s vast network of compromised Android phones.
Source: Bleeping Computer — 2026-10-08