Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ‘We’re not asking for luxury’: school protesters in Paris suburb feel abandoned by French state | France

    October 10, 2026

    How This Tiny Startup Built the World’s Safest Bike Helmet

    October 10, 2026

    Microsoft AI Releases Microsoft-Decision-1: A Qwen3.5-9B Decision-Scoring Model

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ‘We’re not asking for luxury’: school protesters in Paris suburb feel abandoned by French state | France
    • How This Tiny Startup Built the World’s Safest Bike Helmet
    • Microsoft AI Releases Microsoft-Decision-1: A Qwen3.5-9B Decision-Scoring Model
    • FBI arrests another suspected ShinyHunters hacker after agency breach
    • Tech chief says EU can handle AI risks
    • These women are bringing Darwin’s rheas back to Chilean Patagonia
    • The Pentagon Gave Contracts to Alvarez & Marsal Federal, a Firm Closely Tied to a Senior Defense Official — ProPublica
    • Public executions in the US stopped nearly a century ago – why are they resuming now?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    There is a large global market for low-cost Android devices. Bad actors are aware and are servicing the demand through devices built on MediaTek platforms – but with malware preinstalled in the device firmware. 

    When the recipient of such an affected device switches it on, the malware is present, unseen, and available to any bad actor who can control it remotely from its C2. It is a persistent, pre-installed firmware system app that cannot be removed by normal uninstall procedures.

    The campaign, dubbed Midnight Mimosa, was discovered and analyzed by Bitdefender.

    The potential for this type of malware infection controlled via the actor’s C2 is massive. “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” writes the Bitdefender report.

    Midnight Mimosa is focused on ad fraud, automated click fraud, and turning the device into a single component of a much larger botnet. This makes sense for a campaign seeking to fly under the radar with an army of soldiers. Many thousands of click frauds over a period of time would provide a healthy ROI for any bad actor. And botnets are described as a hot commodity that can be rented out to other bad actors. The bigger the botnet, the better the bounty.

    Over the last two years, Bitdefender has observed thousands of unique affected devices in more than 150 countries. No single country or region dominates distribution. Mexico and France lead, followed by Italy, US, Germany, Brazil and Spain. Regionally, Western Europe and the Americas stand out. The report gives no indication of the actual monetary gain achieved by the Midnight Mimosa operators but does provide an extensive list of IoCs to help prevent it.

    Advertisement. Scroll to continue reading.

    Bitdefender also found 13 apps on Google Play with separate signing certificates under two developer accounts and containing the same Midnight Mimosa ad-fraud code. “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself,” note the researchers.

    These Play Store apps do not have the same privileged access as the preinstalled malware, but are considered associated with the broader ecosystem, giving the attackers an additional distribution channel.

    Whether the malware is preinstalled or loaded from Play Store, it has been seen disabling the Play Store before installing additional payload applications and then re-enabling it afterward – probably to avoid detection by Play Protect. “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install,” note the researchers. “The malicious install happens in a window where Google’s scanner is switched off.”

    Midnight Mimosa is best considered as a supply-chain threat where malware is largely integrated into the Android device prior to sale. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse and remote payload management. Attackers have extensive control over affected devices from the get-go.

    Related: RatHat Android Trojan Uses AI for Automation

    Related: Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

    Related: New BTMOB Android Malware Enables Full Device Takeover

    Related: Mirax RAT Targeting Android Users in Europe

    Android budget countries devices Firmware hits Malware PreBaked
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    FBI arrests another suspected ShinyHunters hacker after agency breach

    The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition

    ‘If voters aren’t better off by the next election, we’re screwed’: Labour insiders voice fears over budget | Budget

    OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks

    AI Scramble Drives Cybersecurity M&A Boom

    Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ‘We’re not asking for luxury’: school protesters in Paris suburb feel abandoned by French state | France

    October 10, 2026

    How This Tiny Startup Built the World’s Safest Bike Helmet

    October 10, 2026

    Microsoft AI Releases Microsoft-Decision-1: A Qwen3.5-9B Decision-Scoring Model

    October 10, 2026

    FBI arrests another suspected ShinyHunters hacker after agency breach

    October 10, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ‘We’re not asking for luxury’: school protesters in Paris suburb feel abandoned by French state | France

    October 10, 2026

    How This Tiny Startup Built the World’s Safest Bike Helmet

    October 10, 2026

    Microsoft AI Releases Microsoft-Decision-1: A Qwen3.5-9B Decision-Scoring Model

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.