Midnight Mimosa preinstalled Android firmware malware
Malware Activity
Summary
Hide ▲
Show ▼
The Midnight Mimosa malware activity is embedded in low-cost Android firmware, giving infected phones system-level control to silently install apps, run ad fraud, and act as residential proxies. The activity has affected thousands of devices across more than 150 countries, with evidence tied to MediaTek-based phones and devices posing as major brands. Because the malware is preinstalled in the system partition, removal often requires firmware-level cleanup or ADB-based intervention.
Related Happenings
Midnight Mimosa multi-country Android supply-chain campaign
Campaign
H score32
First: 08.10.2026 22:20
Last: 08.10.2026 22:20
Sources 1
How related:
According to Bitdefender researchers, the campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain.
About this happening:
Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. Th...
Midnight Mimosa multi-country Android supply-chain campaign
CampaignHow related: According to Bitdefender researchers, the campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain.
About this happening: Midnight Mimosa spans thousands of Android devices in more than 150 countries, showing a broad supply-chain operation with sustained reach over about two years. Th...
RemControl Android MaaS malvertising-delivered credential theft platform
Malware Activity
H score29
First: 24.09.2026 00:25
Last: 24.09.2026 00:25
Sources 1
About this happening:
RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
RemControl Android MaaS malvertising-delivered credential theft platform
Malware ActivityAbout this happening: RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scala...
Latest development: 25.09.2026 12:30
Group-IB researchers say the Russian-speaking operator tracked as UNKK appears to have used an AI assistant to build significant portions of the RemControl command and control backend and phishing overlays. The analysis also says the trojan's C2 panel API documentation was inadvertently exposed, giving researchers deeper insight into the malware infrastructure.
RatHat smishing-malvertising Android APK distribution campaign
Campaign
H score36
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
RatHat smishing-malvertising Android APK distribution campaign
CampaignAbout this happening: RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Timeline
-
08.10.2026 22:20 2 articles · 2h ago
Bitdefender uncovers Midnight Mimosa on low-cost Android firmware
Initial DisclosureBitdefender identified Midnight Mimosa as a preinstalled Android firmware malware campaign on low-cost MediaTek smartphones, where the system-partition component can silently install and remove applications, grant sensitive permissions, execute remotely downloaded code, drive ad fraud, and turn infected phones into residential proxies. The campaign is described as affecting thousands of devices across more than 150 countries over approximately two years, with infections seen on devices using model names tied to Doogee and Cubot as well as phones impersonating Samsung and Apple products. The malware includes system packages such as com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot, and com.mobile.applock.en, and Bitdefender says its proxy command-and-control infrastructure was operational and accepting device registrations. Removing the infection is difficult because it runs as a high-privileged system application, so cleanup may require firmware-level remediation or Android Debug Bridge (ADB)-based intervention.
Show sources
- Low-cost Android phones ship with residential proxy malware — www.bleepingcomputer.com — 08.10.2026 22:20
- Low-cost Android phones ship with residential proxy malware — www.bleepingcomputer.com — 08.10.2026 22:20