Bitdefender researchers discovered a malicious campaign they named Midnight Mimosa, targeting low-cost Android phones and reaching users embedded in the device firmware. Because it has system-level privileges, the malware can install and delete apps, grant sensitive permissions, and execute code downloaded remotely without user interaction.
Bitdefender’s findings indicate that thousands of devices in more than 150 countries were affected over a period of approximately two years. The largest numbers of victims were recorded in Mexico, France, Italy, the United States, Germany, Brazil, and Spain, but the campaign has an international scope, and the report does not identify who introduced the malware into the devices or at which stage the tampering occurred within the supply chain.
Malware Inside the System Partition
The campaign used names that mimic system Android packages, including com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. These components are signed and operate with elevated privileges, so users cannot remove them through the usual Android settings.
Bitdefender detected the activity after its App Anomaly Detection technology identified a suspicious system app named com.android.system.lite, which secretly installed and deleted other apps. Subsequent analysis revealed a larger framework that connected to command-and-control servers to download additional modules, including about 32 apps disguised as tools for weather, file management, app locking, optical character recognition, and audio editing.
Ad Fraud and Residential Proxies
The campaign relies on the apps dropped by the malware to generate fraudulent advertising revenue. It uses legitimate advertising SDKs to display ads inside hidden windows or interact with them automatically without the phone owner’s knowledge. Some versions also temporarily disabled the Google Play Store app before installing the malicious apps, with the aim of preventing Play Protect from detecting them, then re-enabled it after the operation was complete. In other cases, installer data was modified to make the apps appear to have come from Google Play.
The campaign also includes a component that turns the phone into a residential proxy. An app disguised as an app locker, named com.mobile.applock.en, contained a TCP proxy that registered the device with a remote server. It could then receive instructions to connect to specified hosts and route traffic through the user’s connection. Bitdefender confirmed that the proxy’s control infrastructure was operational and accepting device registrations, but it did not receive relay targets during testing and therefore could not prove that the attackers were actually relaying traffic.
What Changes in Practice for Users?
The danger of Midnight Mimosa lies in the fact that the infection precedes phone use and does not depend on the user downloading a suspicious app. Bitdefender also found 13 apps on Google Play carrying the same ad-fraud code and connecting to the campaign’s infrastructure, but they lacked the system-component privileges required for silent installation.
The researchers also found firmware signed with certificates associated with the Chinese company Shenzhen Zediel, but they stressed that the company’s involvement in the campaign is unclear. Users of Cubot and Doogee phones reported that suspicious apps kept reinstalling themselves, while the owner of a Doogee Fire 3 Max said that an official update reinfected the device after he had removed the malware by reverting to an older version. User reports indicated that some companies released updates that addressed the problem, without publicly explaining how the malware entered the firmware.
Bitdefender says that removing the infection requires firmware-level cleaning or disabling the malicious component using Android Debug Bridge, procedures that are complex for many users. The campaign therefore leaves an open question about security oversight of the low-cost device supply chain, while the source does not identify the party responsible for the modification or the extent to which the proxy infrastructure was actually used.