Researchers have uncovered a troubling trend in the smartphone market, revealing that thousands of inexpensive Android devices come preloaded with malware capable of generating fraudulent advertising revenue. This alarming discovery, termed “Midnight Mimosa” by the Romania-based cybersecurity firm Bitdefender, affects a range of devices from various brands around the globe, all utilizing chips produced by Taiwanese semiconductor giant MediaTek.
According to Bitdefender’s report released on Thursday, the malware is embedded in the device firmware prior to the first power-up, making it impossible for users to uninstall. “The malware ships preinstalled in the device firmware,” the report states, highlighting the insidious nature of this software.
At the heart of this operation lies a malicious Android application that operates with system-level privileges. This allows it to install or remove other applications without user consent, as well as download and execute additional code. The primary aim of this campaign appears to be financial gain through advertising and click fraud, with the malware also possessing the ability to gather information about devices and installed applications, potentially integrating infected phones into larger botnets.
Over the past two years, Bitdefender has detected this malware on thousands of devices across more than 150 countries. The highest concentrations were found in Mexico, France, and Italy, followed closely by the United States, Germany, Brazil, and Spain. Many of the compromised devices are low-cost, white-label, or counterfeit models, some designed to mimic popular smartphones like the Samsung Galaxy and Apple iPhone. These devices are often sold through mainstream online marketplaces, with one example priced around 0.
All about the ads
The preinstalled malware does not directly generate fraudulent ad views. Instead, it stealthily installs seemingly legitimate applications masquerading as weather apps, note-taking tools, app lockers, and file management utilities. These applications utilize authentic advertising services to load real ads but display them in invisible windows over other applications, thus registering ad impressions that users never actually see. Some components are also capable of generating automated clicks.
Bitdefender identified at least 32 disguised applications deployed by the preinstalled malware. Notably, before installing some of these payloads, the malware temporarily disables the Google Play Store to evade detection, reactivating it only after the installation is complete. Additionally, the researchers found 13 apps available through the Google Play Store that communicated with the same infrastructure and contained similar ad-fraud code. Unlike the preinstalled malware, these Play Store apps lack powerful system privileges but offer genuine functionalities, such as weather updates or QR-code scanning. However, they too can display ads outside their intended use, even when the user is not actively engaging with the phone.
While Bitdefender has yet to pinpoint the source of the malware or its entry point in the supply chain, some affected firmware was signed with certificates from Shenzhen Zediel, a Chinese company known for developing smart hardware and consumer electronics. However, Bitdefender clarified that these certificates do not imply that the company created or knowingly distributed the malware.
The researchers suggest that the malicious software could have been introduced at various stages of the supply chain, whether by an original device manufacturer, a firmware integrator, a logistics partner, or another intermediary before the devices reached consumers. “The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones,” the researchers noted. “One way to recoup costs on hardware sold at such low prices is to embed software that generates revenue afterward.”