MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-08 · via BleepingComputer

Firmware on budget Android devices found carrying stealth proxy malware

Image via BleepingComputer
Image via BleepingComputer

Bitdefender researchers uncovered a campaign called Midnight Mimosa that preinstalls malware in the firmware of low-cost Android phones using MediaTek chips. The malicious code runs with system-level privileges, allowing it to install apps silently, commit ad fraud, and turn devices into residential proxies. The campaign affected thousands of devices in more than 150 countries over about two years, including some Doogee and Cubot models, but manufacturers have not explained how the firmware was compromised.

Expanded Detail

Bitdefender's App Anomaly Detection first spotted a system app, com.android.system.lite, quietly adding and deleting software. Investigators linked it to a broader framework that fetches modules from command-and-control servers. Roughly 32 payloads were identified, disguised as weather, file-management, app-lock, OCR, and audio-editing tools.

The campaign, called Midnight Mimosa, targeted budget MediaTek Android handsets. It reached thousands of devices in over 150 countries across about two years. Reported models included Doogee S200 X and Cubot KINGKONG X, plus phones posing as Samsung and Apple products. Some owners saw suspicious apps return after deletion; one said an official update reintroduced the infection.

Context

Consumers who buy inexpensive Android phones may face hidden risks long before installing anything: their devices could silently join ad-fraud schemes or proxy networks, consuming data and battery while masking attackers' traffic. Because the code sits in firmware with system privileges, ordinary removal may fail, and affected users may not know they are involved. This could erode trust in budget device brands and supply chains, while complicating efforts by carriers, platforms, and security teams to identify and remediate compromised handsets.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Low-cost Android phones ship with residential proxy malware.” Browse more stories.