Skip to content
Threat Feed
high advisory

Midnight Mimosa Pre-installed Malware Campaign

The Midnight Mimosa campaign utilizes platform-signed, pre-installed malware on low-cost MediaTek Android devices to execute ad fraud, click fraud, and residential-proxy botnet enrollment.

Midnight Mimosa is an Android malware campaign discovered by Bitdefender, affecting low-cost, multi-brand devices built on MediaTek hardware. The malware is present in the device firmware before the user switches the phone on for the first time. The primary infection vector is a platform-signed system package, such as 'com.android.system.lite', 'com.android.sys.prot', or 'com.android.sys.gmsprot', which runs with system-uid privileges.

This privileged access allows the malware to silently install and remove applications, grant sensitive permissions, and load arbitrary code via remote DEX plugins. The malware uses a native library (libeasy.so) to decrypt and drop an obfuscated Java framework that manages C2 communication and payload deployment. Beyond pre-installed components, the campaign involves thirteen malicious applications distributed via Google Play that share common C2 infrastructure. The operation generates revenue through ad fraud, click fraud, and by transforming compromised devices into residential-proxy nodes for botnets.

Attack Chain

  1. Factory-level firmware modification embeds a platform-signed, system-uid application (e.g., com.android.system.lite) into the device ROM.
  2. Upon boot, the system app initializes and executes a native library (libeasy.so).
  3. The native library RC4-decrypts an obfuscated Java framework within the system-uid process.
  4. The framework fetches remote configuration from a C2 server masquerading as a weather API.
  5. The malware silently installs stage-2 and stage-3 DEX plugins to facilitate monetization.
  6. The system-uid process grants itself sensitive permissions (Accessibility, Notification Access) to maintain control and perform background actions.
  7. The malware disables the Google Play Store momentarily to install dropper payloads (e.g., com.mobile.applock.wt) and re-enables it afterwards.
  8. Payloads execute hidden ad fraud, automated clicking, or initiate residential-proxy relay connections to support DDoS botnets.

Impact

The campaign affects low-cost Android devices, often marketed as counterfeit flagship models (e.g., S24 Ultra, S25 Ultra). Successful infection grants operators permanent, unremovable system-level access, leading to unauthorized ad revenue generation, potential DDoS participation, and exposure of user data via residential-proxy exploitation. The impact is persistent, as the malware cannot be uninstalled by the end-user.

Recommendation

Prioritize detection and monitoring of device behavior rather than relying on static file scanning, as the malware is platform-signed and persistent.

  • Implement behavioral analysis to detect anomalous system-uid processes that repeatedly enable/disable sensitive permissions like Accessibility or Notification Access.
  • Monitor for unauthorized installation of system packages or unexpected background activity involving packages like 'com.android.system.lite' or 'com.android.sys.prot'.
  • Conduct network traffic analysis for devices communicating with known weather API-disguised command-and-control servers.
  • Restrict the procurement of low-cost, unverified Android hardware in enterprise environments, as firmware integrity cannot be guaranteed.

Immediate actions

Review mobile device fleet for low-cost MediaTek-based hardware and audit installed system packages.

SOC 48h

Threat Hunt

Identify devices with unrecognized system packages like com.android.system.lite or com.android.sys.prot.

T1082 high high confidence hunt now

Data: Mobile Device Management (MDM) inventory

Mitigations

Isolate devices confirmed to be running persistent system-uid malware.

immediate IT Operations

Persistent malware persistence