Malware has been discovered preinstalled on thousands of inexpensive Android phones, capable of generating fraudulent ad revenue and potentially turning infected devices into components of larger botnets, based on information published by The Record.
The malware, identified as Midnight Mimosa by Bitdefender, is embedded in the firmware of devices from various brands that utilize MediaTek chips. This preinstalled application operates with system-level privileges, enabling it to silently install or remove other apps, grant permissions, and download additional code without user consent. The primary objective appears to be financial gain through advertising and click fraud. The malware can also gather device information and possesses capabilities for botnet integration. Over two years, it was observed on thousands of devices in over 150 countries, with Mexico, France, and Italy showing the highest prevalence. Affected devices are often low-cost, white-label, or counterfeit models sold through online marketplaces. The malware operates by secretly installing disguised applications that use legitimate advertising services to display ads in invisible windows or generate automated clicks, potentially evading detection by temporarily disabling the Google Play Store. While the exact point of introduction into the supply chain remains undetermined, it could have originated from manufacturers, firmware integrators, or other intermediaries seeking to recoup hardware costs through software monetization.
Source: The Record
