Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Floodwaters Overwhelm Thailand – NASA Science

    October 9, 2026

    Can a New Credit Rating Agency Help Africans Borrow at Better Rates?

    October 9, 2026

    OpenAI bans Russian, Iranian ChatGPT propaganda networks

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Floodwaters Overwhelm Thailand – NASA Science
    • Can a New Credit Rating Agency Help Africans Borrow at Better Rates?
    • OpenAI bans Russian, Iranian ChatGPT propaganda networks
    • EU faces gas supply shortage as winter looms – POLITICO
    • Ben Affleck is an AI nerd, and the internet is impressed
    • Low-cost Android phones ship with residential proxy malware
    • Bitcoin rebounds to $82,000 as Trump rules out Iran strikes. What next?
    • Einstein Probe reveals a hidden phase of neutron star collisions
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Low-cost Android phones ship with residential proxy malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

    The malware is believed to have been introduced somewhere in the device supply chain, but it remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred.

    The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, giving it system-level privileges that allow it to install and remove applications, grant sensitive permissions, and execute remotely downloaded code without user interaction.

    According to Bitdefender researchers, the campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain.

    The researchers found preinstalled malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products.

    In an XDA forums post, owners of Cubot and Doogee smartphones reported finding suspicious applications that repeatedly reinstalled themselves after removal.

    One Doogee Fire 3 Max owner also reported that an official firmware update infected the device with the malware, which disappeared after restoring an older firmware version but returned when the update was installed again.

    Some users said the manufacturers released firmware updates that resolved the infections. However, the manufacturers have not publicly explained how the malicious software was introduced into the affected firmware.

    Bitdefender also mentioned the XDA forum post in its report and said one of the malware packages reported by forum users, com.android.non.szcz, is part of the same malware family.

    Pre-installed Android malware

    Unlike typical Android malware that requires users to install a malicious application, Midnight Mimosa is already installed in the device’s system partition when customers receive their phones.

    The malicious programs impersonate legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot.

    Because these applications are signed and run with elevated system privileges, they cannot be removed through Android’s normal application uninstall process.

    Bitdefender discovered the campaign after its App Anomaly Detection technology flagged a suspicious system application named com.android.system.lite that was silently installing and removing other applications.

    Further investigation determined that the application was part of a larger malware framework that downloads additional modules from command-and-control (C2) servers to perform different malicious activities.

    The researchers identified approximately 32 applications distributed through the framework, including apps disguised as weather utilities, file managers, app lockers, OCR tools, and audio editors.

    “The system app itself doesn’t register the fraudulent impressions and clicks,” explains Bitdefender.

    “The revenue engine is driven by the dropped cover apps, including real-looking weather, app-lock, note, and OCR apps, which load genuine ads through a legitimate ad SDK. The goal is simple: to load an invisible window on top of apps that registers ads being shown.”

    These applications are used to generate fraudulent advertising impressions and clicks, with some displaying advertisements in hidden windows or automatically interacting with ads without the device owner’s involvement.

    The malware also employs techniques designed to evade Android’s security protections.

    Before silently installing malicious applications, it temporarily disables the Google Play Store app, com.android.vending, which Bitdefender says is intended to prevent Google Play Protect from detecting the installation.

    After the installation completes, the malware re-enables the Play Store to avoid raising suspicion.

    Some malware variants also manipulate Android’s recorded installer information to make malicious applications appear to have been installed through Google Play, even though they were deployed directly by the malware.

    The malware also includes features that turn infected Android phones into residential proxies that can relay network traffic.

    Bitdefender identified a malicious application disguised as an app locker, com.mobile.applock.en, which contains a TCP proxy component that registers infected devices with a remote command server.

    Once registered, the malware can be sent instructions to connect to specified hosts and forward traffic through the infected device.

    This could allow attackers to route malicious traffic through the internet connections of phone owners, concealing the true origin of attacks or allowing access to devices reachable from the infected device.

    Bitdefender confirmed that the proxy command-and-control infrastructure was operational and accepting device registrations.

    However, during their tests, the researchers said their newly registered device did not receive any relay targets, so they could not confirm whether the attacker’s were actively forwarding traffic.

    SystemLite delivery and payload architecture
    SystemLite delivery and payload architecture
    Source: Bitdefender

    The researchers also discovered 13 Android applications distributed through the Google Play Store that contained the same advertising fraud code and communicated with known Midnight Mimosa infrastructure.

    Unlike the preinstalled system components, these applications do not have elevated privileges needed to silently install other software.

    However, they can still display advertisements outside their user interface, including when users are not using the phone.

    The applications were distributed using 13 different signing certificates and at least two developer accounts, identified as fivedev and CPS Developer.

    The researchers also found firmware signed using certificates associated with Chinese device manufacturer Shenzhen Zediel, but said it is unclear whether the company was involved in the malware’s campaign.

    For affected consumers, removing the malware is difficult because the malware is installed as a high-privileged system application.

    Bitdefender says removing the infection requires firmware-level cleanup or disabling the malicious component using Android Debug Bridge (ADB), which can be complicated for many users.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Android LowCost Malware phones Proxy residential Ship
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

    ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

    FBI disrupts Chinese hacking tools used to breach critical infrastructure

    Oracle Health Data Breach Tally Climbs to Nearly 20 Million

    SonicWall and Splunk Patch Critical Vulnerabilities

    Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Floodwaters Overwhelm Thailand – NASA Science

    October 9, 2026

    Can a New Credit Rating Agency Help Africans Borrow at Better Rates?

    October 9, 2026

    OpenAI bans Russian, Iranian ChatGPT propaganda networks

    October 9, 2026

    EU faces gas supply shortage as winter looms – POLITICO

    October 9, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Floodwaters Overwhelm Thailand – NASA Science

    October 9, 2026

    Can a New Credit Rating Agency Help Africans Borrow at Better Rates?

    October 9, 2026

    OpenAI bans Russian, Iranian ChatGPT propaganda networks

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.