Midnight Mimosa

31273618279?profile=RESIZE_400xCybersecurity researchers at Bitdefender have identified a campaign called Midnight Mimosa affecting multiple low-cost Android phone brands built on MediaTek platforms, allowing operators to install apps, grant permissions and load code without the owner’s consent.

The infection happens below the normal app-installation layer. In its research shared with Hackread.com, Bitdefender notes that “every user-facing defense had already been bypassed” by the time the phone was switched on.[1]

Example online listing for a low-cost “S25 Ultra” Android phone. Researchers found Midnight Mimosa on counterfeit and budget Android devices, including phones using similar reported names (Source: Bitdefender)

Malware Hidden as a System Component - The malware hides in system packages such as com.android.system.lite and com.android.sys.prot.  Because they run with Android system privileges, users cannot normally remove them.

31273618291?profile=RESIZE_584xProtectDevices - A native library called libeasy.so decrypts another component and connects to api.weatherlive.world to download more code. The malware can then install or remove apps without asking the user and give those apps additional permissions.

Bitdefender also found Accessibility and Notification Access being turned on and off automatically but did not see the malware use either feature for malicious activity.

The main activity observed was not data theft but monetization.  The malware uses ad fraud and proxyware, while its privileged access gives operators a way to change or expand the payloads later.

ProtectDevices - For context, proxyware turns a device’s internet connection into a relay for other traffic, often making that traffic appear to come from the infected user’s IP address.

Play Protect Evasion and Hidden Ad Fraud - Before installing a payload, the malware temporarily disables the Google Play Store package, com.android.vending, and restores it afterward. Bitdefender assessed that this may create a window for payload installation while avoiding normal Play Protect checks.

The malware can also make a sideloaded app appear to have been installed from Google Play, even though it lacks the cryptographic “frosting” marker found on genuine Play apps. Bitdefender found payloads such as com.mobile.applock.en, which uses EnLoaderLib v1.0.6 and connects to a proxy network over TCP port 6000. Another payload, com.mobile.applock.wt, contains an ad-fraud module.

The malware also installs apps for functions such as weather, AppLock, notes and OCR. These apps use legitimate advertising SDKs, but the malware can run ads in the background and generate fake impressions and clicks without the user seeing them.

ProtectDevices / Thousands of Devices in 150+ Countries - Bitdefender observed thousands of infected devices in more than 150 countries. Affected hardware included counterfeit phones reporting names such as “S25 Ultra” and “i17 Pro Max,” along with budget models including the Doogee S200 X and Cubot KINGKONG X.

31273618469?profile=RESIZE_584xBitdefender’s country distribution chart for infected Midnight Mimosa devices over a two-year window. Mexico, France, Italy and the United States were among the most affected countries (Source: Bitdefender)

The same adfraud code was also found in 13 Google Play apps, showing that the operation was not limited to preinstalled firmware.

A platform certificate used by com.android.system.lite was associated with Shenzhen Zediel Co., Ltd. However, Bitdefender said this does not prove the company inserted or knowingly distributed the malware. The point where the malware entered the supply chain remains unknown.

ProtectDevices - For buyers, the problem is that a normal factory reset or uninstall may not be enough. Midnight Mimosa sits in system-level firmware, so affected devices may require trusted firmware replacement, vendor remediation or replacement of the phone itself.

This article used AI to craft the contents and is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/7855487668891299929

[1] https://hackread.com/midnight-mimosa-malware-preinstalled-android-phones/#google_vignette

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!