Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices.

Android malware

There is a large global market for low-cost Android devices. Bad actors are aware and are servicing the demand through devices built on MediaTek platforms – but with malware preinstalled in the device firmware. 

When the recipient of such an affected device switches it on, the malware is present, unseen, and available to any bad actor who can control it remotely from its C2. It is a persistent, pre-installed firmware system app that cannot be removed by normal uninstall procedures.

The campaign, dubbed Midnight Mimosa, was discovered and analyzed by Bitdefender.

The potential for this type of malware infection controlled via the actor’s C2 is massive. “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” writes the Bitdefender report.

Midnight Mimosa is focused on ad fraud, automated click fraud, and turning the device into a single component of a much larger botnet. This makes sense for a campaign seeking to fly under the radar with an army of soldiers. Many thousands of click frauds over a period of time would provide a healthy ROI for any bad actor. And botnets are described as a hot commodity that can be rented out to other bad actors. The bigger the botnet, the better the bounty.

Over the last two years, Bitdefender has observed thousands of unique affected devices in more than 150 countries. No single country or region dominates distribution. Mexico and France lead, followed by Italy, US, Germany, Brazil and Spain. Regionally, Western Europe and the Americas stand out. The report gives no indication of the actual monetary gain achieved by the Midnight Mimosa operators but does provide an extensive list of IoCs to help prevent it.

Advertisement. Scroll to continue reading.

Bitdefender also found 13 apps on Google Play with separate signing certificates under two developer accounts and containing the same Midnight Mimosa ad-fraud code. “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself,” note the researchers.

These Play Store apps do not have the same privileged access as the preinstalled malware, but are considered associated with the broader ecosystem, giving the attackers an additional distribution channel.

Whether the malware is preinstalled or loaded from Play Store, it has been seen disabling the Play Store before installing additional payload applications and then re-enabling it afterward – probably to avoid detection by Play Protect. “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install,” note the researchers. “The malicious install happens in a window where Google’s scanner is switched off.”

Midnight Mimosa is best considered as a supply-chain threat where malware is largely integrated into the Android device prior to sale. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse and remote payload management. Attackers have extensive control over affected devices from the get-go.

Related: RatHat Android Trojan Uses AI for Automation

Related: Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Related: New BTMOB Android Malware Enables Full Device Takeover

Related: Mirax RAT Targeting Android Users in Europe

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.