Find notable cyber news and cases, enriched with sources, timelines, and signals.

Midnight Mimosa preinstalled Android firmware malware

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud, and act as residential proxies. The activity has affected thousands of devices across more than 150 countries, with evidence tied to MediaTek-based phones and devices posing as major brands. Because the malware is preinstalled in the system partition, removal often requires firmware-level cleanup or ADB-based intervention.

Related Happenings

Midnight Mimosa multi-country Android supply-chain campaign

Campaign
H score32 First: 08.10.2026 22:20 Last: 08.10.2026 22:20 Sources 1

How related: According to Bitdefender researchers, the campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain.

About this happening: Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. Th...

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity
H score29 First: 24.09.2026 00:25 Last: 24.09.2026 00:25 Sources 1

About this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...

Latest development: 25.09.2026 12:30

Group-IB researchers say the Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command and control backend and phishing overlays. The analysis also says the trojan's C2 panel API documentation was inadvertently exposed, giving researchers deeper insight into the malware infrastructure.

RatHat smishing-malvertising Android APK distribution campaign

Campaign
H score36 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

About this happening: RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

Hagaseca Android RAT spread via THost9 loader and ADB worm behavior

Malware Activity
H score19 First: 10.09.2026 17:36 Last: 10.09.2026 17:36 Sources 1

About this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...

Timeline

  1. 08.10.2026 22:20 2 articles · 2h ago

    Bitdefender uncovers Midnight Mimosa on low-cost Android firmware

    Initial Disclosure

    Bitdefender identified Midnight Mimosa as a preinstalled Android firmware malware campaign on low-cost MediaTek smartphones, where the system-partition component can silently install and remove applications, grant sensitive permissions, execute remotely downloaded code, drive ad fraud, and turn infected phones into residential proxies. The campaign is described as affecting thousands of devices across more than 150 countries over approximately two years, with infections seen on devices using model names tied to Doogee and Cubot as well as phones impersonating Samsung and Apple products. The malware includes system packages such as com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot, and com.mobile.applock.en, and Bitdefender says its proxy command-and-control infrastructure was operational and accepting device registrations. Removing the infection is difficult because it runs as a high-privileged system application, so cleanup may require firmware-level remediation or Android Debug Bridge (ADB)-based intervention.

    Show sources