BITDEFENDER researchers have uncovered a campaign, dubbed Midnight Mimosa, that implants Android malware directly into the firmware of low-cost MediaTek-powered phones. The threat is preinstalled on devices from multiple brands and can be present before the user even switches the device on, making it unrecoverable by conventional means.
The core component hides in the system partition and operates with system-level privileges, enabling silent installation and removal of apps, permission grants, and remote code downloads, all without user awareness. The malware is spread across several packages with different signing certificates, but shares a common malicious core.
In-field activity includes the ability to silently install at least 32 payload apps disguised as useful tools, while repeatedly enabling sensitive permissions such as Accessibility, Notification Access and even SMS read/write. The operators deploy an ad fraud operation that loads ads via cover apps and an invisible overlay, while sometimes turning devices into residential proxy relay nodes that could be used for DDoS attacks.
One payload is a dedicated TCP proxy that relays traffic through four domains, with the control channel operating over port 6000. The campaign leverages legitimate-looking apps published on Google Play to reach users, and Fake devices and firmware signed by Shenzhen Zediel appear across devices, including counterfeit models like “i17 Pro Max” or “iPadAirPro”.
Bitdefender notes that removing the infection is not achievable by uninstalling the apps; the root lies in the system partition, requiring firmware-level cleanup or disabling via ADB. The durable defence rests with vendors and marketplaces to curb affected firmware, as store reviews and uninstall options offer no protection here. Over about two years, the operation affected devices in more than 150 countries, with Mexico, France and Italy most prominent.