Find notable cyber news and cases, enriched with sources, timelines, and signals.

Midnight Mimosa multi-country Android supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. The operation used preinstalled firmware malware to silently install apps, drive ad fraud, and turn infected phones into residential proxies. Victims were concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.

Related Happenings

Midnight Mimosa preinstalled Android firmware malware

Malware Activity
H score29 First: 08.10.2026 22:20 Last: 08.10.2026 22:20 Sources 1

How related: A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

About this happening: The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud,...

UNKK RemControl TVTap IPTV malvertising campaign

Campaign
H score35 First: 24.09.2026 00:25 Last: 24.09.2026 00:25 Sources 1

About this happening: RemControl is an Android banking trojan campaign tied to UNKK that uses fake Google Play Store pages to impersonate TVTap IPTV and push victims through a malic...

Latest development: 25.09.2026 12:30

Group-IB says the suspected Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command-and-control backend and phishing overlays, and the RemControl C2 panel API documentation was inadvertently exposed during the analysis, giving researchers deep insight into the trojan’s infrastructure.

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity
H score29 First: 24.09.2026 00:25 Last: 24.09.2026 00:25 Sources 1

About this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...

Latest development: 25.09.2026 12:30

Group-IB researchers say the Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command and control backend and phishing overlays. The analysis also says the trojan's C2 panel API documentation was inadvertently exposed, giving researchers deeper insight into the malware infrastructure.

GoldFactory Gigabud banking trojan distribution campaign across 11 countries

Campaign
H score45 First: 09.09.2026 17:30 Last: 09.09.2026 17:30 Sources 1

About this happening: The GoldFactory-linked Gigabud campaign now uses Vwork to create an Android Work Profile on infected phones and hide a tampered banking app from malware checks. ...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

Timeline

  1. 08.10.2026 22:20 2 articles · 2h ago

    Bitdefender uncovers Midnight Mimosa firmware malware on Android phones

    Initial Disclosure

    Bitdefender identified Midnight Mimosa on low-cost Android smartphones using MediaTek chipsets, where malicious firmware embedded in the system partition silently installed and removed apps, evaded Google Play Protect, and supported ad fraud and residential proxying. The campaign was tied to thousands of devices in more than 150 countries, with victims concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain, and detection began when App Anomaly Detection flagged com.android.system.lite.

    Show sources