PhonesAI

Bitdefender Finds Midnight Mimosa Malware Preinstalled on Budget Android Phones

Bitdefender researchers say the Midnight Mimosa campaign ships in the firmware of some low-cost Android phones and has appeared in over 150 countries.

Bitdefender researchers have uncovered a malware campaign they call Midnight Mimosa that is embedded in the firmware of some low-cost Android phones, according to androidauthority.com. Devices from manufacturers including Doogee and Cubot are among those affected.

The malware is capable of installing apps, granting itself permissions, evading Google Play Protect, and turning infected phones into botnet nodes. According to the researchers, the campaign has been seen on thousands of devices across more than 150 countries.

Cleaning up an infection is difficult because the malicious code lives in the system partition, meaning it is present before the user ever sets up the phone and cannot be removed through a routine app uninstall.

Google Play Protect is the built-in security layer on Android devices that scans apps for malicious behaviour. Bitdefender's findings indicate the Midnight Mimosa code has been able to bypass that protection on the affected handsets.

The researchers did not specify which exact models carry the malware beyond naming Doogee and Cubot as manufacturers whose devices have been linked to the campaign.

Quick answers

What is Midnight Mimosa?

Midnight Mimosa is a malware campaign uncovered by Bitdefender that is embedded in the firmware of some low-cost Android phones, including devices from Doogee and Cubot.

Can Midnight Mimosa be removed?

Removal is difficult because the malware lives in the system partition, so it is present on the device before the user sets it up.

What can the malware do?

According to Bitdefender, it can install apps, grant permissions, evade Google Play Protect, and turn phones into botnet nodes.

Source