{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/android-low-cost-hardware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Android (low-cost hardware)"],"_cs_severities":["high"],"_cs_tags":["mobile","malware","android","botnet","ad-fraud","supply-chain"],"_cs_type":"advisory","_cs_vendors":["MediaTek"],"content_html":"\u003cp\u003eMidnight Mimosa is an Android malware campaign discovered by Bitdefender, affecting low-cost, multi-brand devices built on MediaTek hardware. The malware is present in the device firmware before the user switches the phone on for the first time. The primary infection vector is a platform-signed system package, such as 'com.android.system.lite', 'com.android.sys.prot', or 'com.android.sys.gmsprot', which runs with system-uid privileges.\u003c/p\u003e\n\u003cp\u003eThis privileged access allows the malware to silently install and remove applications, grant sensitive permissions, and load arbitrary code via remote DEX plugins. The malware uses a native library (libeasy.so) to decrypt and drop an obfuscated Java framework that manages C2 communication and payload deployment. Beyond pre-installed components, the campaign involves thirteen malicious applications distributed via Google Play that share common C2 infrastructure. The operation generates revenue through ad fraud, click fraud, and by transforming compromised devices into residential-proxy nodes for botnets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eFactory-level firmware modification embeds a platform-signed, system-uid application (e.g., com.android.system.lite) into the device ROM.\u003c/li\u003e\n\u003cli\u003eUpon boot, the system app initializes and executes a native library (libeasy.so).\u003c/li\u003e\n\u003cli\u003eThe native library RC4-decrypts an obfuscated Java framework within the system-uid process.\u003c/li\u003e\n\u003cli\u003eThe framework fetches remote configuration from a C2 server masquerading as a weather API.\u003c/li\u003e\n\u003cli\u003eThe malware silently installs stage-2 and stage-3 DEX plugins to facilitate monetization.\u003c/li\u003e\n\u003cli\u003eThe system-uid process grants itself sensitive permissions (Accessibility, Notification Access) to maintain control and perform background actions.\u003c/li\u003e\n\u003cli\u003eThe malware disables the Google Play Store momentarily to install dropper payloads (e.g., com.mobile.applock.wt) and re-enables it afterwards.\u003c/li\u003e\n\u003cli\u003ePayloads execute hidden ad fraud, automated clicking, or initiate residential-proxy relay connections to support DDoS botnets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign affects low-cost Android devices, often marketed as counterfeit flagship models (e.g., S24 Ultra, S25 Ultra). Successful infection grants operators permanent, unremovable system-level access, leading to unauthorized ad revenue generation, potential DDoS participation, and exposure of user data via residential-proxy exploitation. The impact is persistent, as the malware cannot be uninstalled by the end-user.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize detection and monitoring of device behavior rather than relying on static file scanning, as the malware is platform-signed and persistent.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement behavioral analysis to detect anomalous system-uid processes that repeatedly enable/disable sensitive permissions like Accessibility or Notification Access.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized installation of system packages or unexpected background activity involving packages like 'com.android.system.lite' or 'com.android.sys.prot'.\u003c/li\u003e\n\u003cli\u003eConduct network traffic analysis for devices communicating with known weather API-disguised command-and-control servers.\u003c/li\u003e\n\u003cli\u003eRestrict the procurement of low-cost, unverified Android hardware in enterprise environments, as firmware integrity cannot be guaranteed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T13:13:07Z","date_published":"2026-10-08T13:13:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-midnight-mimosa/","summary":"The Midnight Mimosa campaign utilizes platform-signed, pre-installed malware on low-cost MediaTek Android devices to execute ad fraud, click fraud, and residential-proxy botnet enrollment.","title":"Midnight Mimosa Pre-installed Malware Campaign","url":"https://feed.craftedsignal.io/briefs/2026-10-midnight-mimosa/"}],"language":"en","title":"CraftedSignal Threat Feed - Android (Low-Cost Hardware)","version":"https://jsonfeed.org/version/1.1"}