Skip to content
firewallpulse
Bits, bytes and breaking security news
Cyber Attacks

Inexpensive Androids Come With Midnight Mimosa Firmware Bug for Ad Fraud

Hackread and BleepingComputer report that cheap Android smartphones ship with pre-installed firmware malware enabling ad fraud and proxy abuse before users power on.

Inexpensive Androids Come With Midnight Mimosa Firmware Bug for Ad Fraud
Illustration: Firewall Pulse

Key points

  • Midnight Mimosa malware is embedded in the firmware of low-cost Android phones.
  • The compromise exists before the device is switched on or activated by the buyer.
  • Attackers use the infected devices for ad fraud and residential proxy networks.

Low-cost Android smartphones are arriving with firmware-level malware pre-installed, according to reports from Hackread and BleepingComputer. The campaign, dubbed Midnight Mimosa, embeds malicious code directly into the device operating system. This allows attackers to silently install applications and hijack network connections without user interaction or consent.

Root cause

The malware is baked into the firmware during manufacturing or distribution, meaning the device is compromised before the user powers it on. Hackread states that these low-cost Android phones arrive already infected. This early-stage compromise bypasses standard application security controls because the malicious components are part of the core system image rather than a downloaded app.

Attack path

Attackers leverage the firmware-level access to silently install additional applications on the infected devices. According to BleepingComputer, the malware enables ad fraud by generating fake traffic and clicks. The compromised smartphones are also turned into residential proxies, masking the true location of malicious actors. This abuse occurs while the device appears to function normally for the unsuspecting owner.

Affected versions

Reports from Hackread and BleepingComputer identify the affected hardware as low-cost Android smartphones. No specific Android version numbers, device models, or manufacturers are named in the current reporting. The malware is present in the firmware of these budget devices, which are likely sourced from specific supply chains that have not been fully disclosed in the initial reports.

Mitigation

  • Inspect new low-cost Android devices for unknown system applications immediately after setup.
  • Avoid using budget smartphones for sensitive corporate tasks or accessing internal networks.
  • Monitor network logs for unexpected outbound traffic or proxy-like behaviour from new endpoints.
  • Verify the supply chain integrity of mobile devices before deploying them in professional environments.

Background: Malware

Malware analysis reveals the specific behaviour of a threat, allowing you to tailor detection rules and containment strategies. Without it, you guess at the scope of an infection, risking persistent access and data loss while wasting resources on irrelevant alerts.

Read the full guide: Malware Analysis: Why It Matters for Security Decisions

What to do and how to stay safe: Midnight Mimosa

  • Audit all recently acquired low-cost Android devices for unauthorised system-level applications or firmware anomalies.
  • Isolate new mobile endpoints from critical internal networks until their firmware integrity is verified.
  • Monitor network logs for unusual outbound traffic patterns that may indicate proxy usage or ad fraud.
  • Once the vendor provides an update, apply security patches immediately to address any known firmware vulnerabilities.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Is Midnight Mimosa a virus that spreads between phones?

No, the malware is embedded in the firmware of the device before it is switched on, according to Hackread.

Which Android phones are affected by this malware?

Reports indicate that low-cost Android smartphones are affected, but no specific models are named.

What does the malware do on the device?

It silently installs apps, performs ad fraud, and turns the phone into a residential proxy.

Sources

  1. Hackread
  2. BleepingComputer
Midnight MimosaAndroidfirmware malwareresidential proxylow-cost smartphones

Related stories

Vishing Attack Meaning: How Voice Phishing Works and How to Stop It

Voice phishing exploits psychological urgency rather than software flaws, making technical controls alone insufficient for defence against social engineering.