Low-cost Android phones ship with residential proxy malware
Key Points:
- The "Midnight Mimosa" malware campaign infects low-cost Android smartphones by embedding malicious software directly into device firmware, enabling silent app installation, ad fraud, and turning devices into residential proxies.
- The malware targets devices with MediaTek chipsets, granting system-level privileges that allow it to install and remove apps and execute code without user interaction, affecting thousands of devices in over 150 countries, notably in Mexico, France, Italy, the US, Germany, Brazil, and Spain.
- Infected devices include models from legitimate manufacturers like Doogee and Cubot, as well as phones impersonating Samsung and Apple, with some firmware updates reportedly introducing or resolving the malware, though manufacturers have not clarified how the malware entered the supply chain.
- The malware impersonates legitimate system apps, disables Google Play Store temporarily to evade detection, and uses hidden apps to generate fraudulent ad revenue by loading invisible ad windows and simulating ad interactions.
- Additionally, the malware can convert infected phones into residential proxies to relay network traffic, and related malicious apps were also found on the Google Play Store, though removing the infection typically requires complex firmware-level intervention.