Low-cost Android phones ship with residential proxy malware
BLUF
Pre-installed firmware malware on budget Android devices creates a massive, hard-to-remove botnet for cybercriminals.
NEWS
Researchers identified the 'Midnight Mimosa' campaign affecting low-cost Android smartphones shipped with malicious code embedded in the firmware. This malware enables attackers to silently install applications, conduct ad fraud, and hijack devices as residential proxies without user consent. The infection persists even after factory resets due to its deep system integration.
Why I Care
This compromises user privacy and device performance while exposing networks to illicit traffic routed through innocent devices. Budget-conscious consumers and enterprises deploying mobile fleets are at risk of data leakage and reputational damage from compromised endpoints.
Next Steps
Consumers should avoid purchasing unbranded or ultra-low-cost Android devices from unknown vendors until further notice. Organizations must inventory mobile assets and isolate affected devices immediately while security teams monitor for unusual network traffic patterns associated with proxy activity.
Source: BleepingComputer ·