Midnight Mimosa multi-country Android supply-chain campaign
Campaign
Summary
Hide ▲
Show ▼
Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. The operation used preinstalled firmware malware to silently install apps, drive ad fraud, and turn infected phones into residential proxies. Victims were concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.
Related Happenings
Midnight Mimosa preinstalled Android firmware malware
Malware Activity
H score29
First: 08.10.2026 22:20
Last: 08.10.2026 22:20
Sources 1
How related:
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
About this happening:
The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud,...
Midnight Mimosa preinstalled Android firmware malware
Malware ActivityHow related: A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
About this happening: The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud,...
UNKK RemControl TVTap IPTV malvertising campaign
Campaign
H score35
First: 24.09.2026 00:25
Last: 24.09.2026 00:25
Sources 1
About this happening:
RemControl is an Android banking trojan campaign tied to UNKK that uses fake Google Play Store pages to impersonate TVTap IPTV and push victims through a malic...
UNKK RemControl TVTap IPTV malvertising campaign
CampaignAbout this happening: RemControl is an Android banking trojan campaign tied to UNKK that uses fake Google Play Store pages to impersonate TVTap IPTV and push victims through a malic...
Latest development: 25.09.2026 12:30
Group-IB says the suspected Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command-and-control backend and phishing overlays, and the RemControl C2 panel API documentation was inadvertently exposed during the analysis, giving researchers deep insight into the trojan’s infrastructure.
RemControl Android MaaS malvertising-delivered credential theft platform
Malware Activity
H score29
First: 24.09.2026 00:25
Last: 24.09.2026 00:25
Sources 1
About this happening:
RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
RemControl Android MaaS malvertising-delivered credential theft platform
Malware ActivityAbout this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
Latest development: 25.09.2026 12:30
Group-IB researchers say the Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command and control backend and phishing overlays. The analysis also says the trojan's C2 panel API documentation was inadvertently exposed, giving researchers deeper insight into the malware infrastructure.
GoldFactory Gigabud banking trojan distribution campaign across 11 countries
Campaign
H score45
First: 09.09.2026 17:30
Last: 09.09.2026 17:30
Sources 1
About this happening:
The GoldFactory-linked Gigabud campaign now uses Vwork to create an Android Work Profile on infected phones and hide a tampered banking app from malware checks. ...
GoldFactory Gigabud banking trojan distribution campaign across 11 countries
CampaignAbout this happening: The GoldFactory-linked Gigabud campaign now uses Vwork to create an Android Work Profile on infected phones and hide a tampered banking app from malware checks. ...
BTMOB Android RAT no-code builder malware activity
Malware Activity
H score28
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
Latest development: 29.05.2026 00:10
BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.
Timeline
-
08.10.2026 22:20 2 articles · 2h ago
Bitdefender uncovers Midnight Mimosa firmware malware on Android phones
Initial DisclosureBitdefender identified Midnight Mimosa on low-cost Android smartphones using MediaTek chipsets, where malicious firmware embedded in the system partition silently installed and removed apps, evaded Google Play Protect, and supported ad fraud and residential proxying. The campaign was tied to thousands of devices in more than 150 countries, with victims concentrated in Mexico, France, Italy, the United States, Germany, Brazil, and Spain, and detection began when App Anomaly Detection flagged com.android.system.lite.
Show sources
- Low-cost Android phones ship with residential proxy malware — www.bleepingcomputer.com — 08.10.2026 22:20
- Low-cost Android phones ship with residential proxy malware — www.bleepingcomputer.com — 08.10.2026 22:20