MalwareMedium

Cheap Android phones ship with firmware malware used for ad fraud and proxies

Bitdefender found Midnight Mimosa preinstalled in the firmware of low-cost MediaTek-based Android phones, infecting thousands of devices in more than 150 countries over two years.

Cheap Android phones ship with firmware malware used for ad fraud and proxies

At a glance

  • The malware sits in the system partition and cannot be removed by normal uninstallation, Bitdefender says.
  • Affected models include the Doogee S200 X, Doogee Fire 3 Max and Cubot KINGKONG X, plus Samsung and Apple look-alikes.
  • It silently installs about 32 apps used for hidden ad fraud and includes a residential proxy component.
  • Bitdefender also found 13 Google Play apps tied to the same infrastructure.

Thousands of low-cost Android phones sold through mainstream online marketplaces have been shipping with malware embedded in their firmware, according to research from Bitdefender reported by BleepingComputer and The Record. The campaign, which Bitdefender calls Midnight Mimosa, has been observed for about two years on devices in more than 150 countries and is used mainly for advertising fraud, with a component that can turn phones into residential proxies.

What happened

BleepingComputer reported that Bitdefender's App Anomaly Detection technology flagged a system app named com.android.system.lite that was silently installing and removing other apps. Further analysis showed the code was preinstalled in the system partition of low-cost phones built on MediaTek chipsets. Bitdefender said the malware "ships preinstalled in the device firmware" and "can't be uninstalled," The Record reported.

According to BleepingComputer, affected models include the Doogee S200 X, Doogee Fire 3 Max and Cubot KINGKONG X, as well as phones that impersonate Samsung and Apple products. The largest numbers of victims were in Mexico, France and Italy, followed by the United States, Germany, Brazil and Spain.

Technical details

The malicious packages disguise themselves as system components such as com.android.system.lite, com.android.sys.prot and com.android.sys.gmsprot. Because they are signed and run with system privileges, they can install and remove apps, grant sensitive permissions and run remotely downloaded code without user interaction, BleepingComputer said.

The framework installs around 32 apps disguised as weather tools, file managers, app lockers and similar utilities. These load real ads through a legitimate ad SDK but display them in hidden windows to generate impressions and, in some cases, automated clicks. Bitdefender said the malware temporarily disables the Google Play Store before silent installations, likely to avoid detection by Google Play Protect.

One app, com.mobile.applock.en, contains a TCP proxy component that registers devices with a command server, which can instruct them to relay traffic. BleepingComputer noted that Bitdefender's test device received no relay targets, so active traffic forwarding could not be confirmed. Bitdefender also found 13 Google Play apps with the same ad-fraud code connected to the campaign's infrastructure.

Who is responsible

Bitdefender has not determined where in the supply chain the malware was added. The Record reported that some firmware was signed with certificates bearing the name of Chinese electronics firm Shenzhen Zediel, but Bitdefender said this does not prove the company created or knowingly distributed the malware. Possible points of introduction include the manufacturer, a firmware integrator or another intermediary.

What to do

According to BleepingComputer, some owners reported that manufacturer firmware updates removed the infection, although one Doogee Fire 3 Max owner said an official update reinstalled it. Removal otherwise requires firmware-level cleanup or disabling the components via Android Debug Bridge (ADB). Buyers should be cautious with very cheap, unbranded or look-alike phones, and organizations should keep such devices off corporate networks.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.