Low-cost Android phones ship with residential proxy malware

Refract AI Intelligence Digest

BLUF

Pre-installed firmware malware on budget Android devices creates a massive, hard-to-remove botnet for cybercriminals.

NEWS

Researchers identified the 'Midnight Mimosa' campaign affecting low-cost Android smartphones shipped with malicious code embedded in the firmware. This malware enables attackers to silently install applications, conduct ad fraud, and hijack devices as residential proxies without user consent. The infection persists even after factory resets due to its deep system integration.

Why I Care

This compromises user privacy and device performance while exposing networks to illicit traffic routed through innocent devices. Budget-conscious consumers and enterprises deploying mobile fleets are at risk of data leakage and reputational damage from compromised endpoints.

Next Steps

Consumers should avoid purchasing unbranded or ultra-low-cost Android devices from unknown vendors until further notice. Organizations must inventory mobile assets and isolate affected devices immediately while security teams monitor for unusual network traffic patterns associated with proxy activity.

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.