Midnight Mimosa is a financially motivated Android backdoor and modular malware operation identified by Bitdefender on low-cost, white-label, and counterfeit smartphones using MediaTek platforms. Its core components are embedded in device firmware before sale and execute as persistent, privileged system applications. Observations over approximately two years covered thousands of devices in more than 150 countries, with Mexico, France, and Italy recording the highest prevalence. The operators and the point of insertion into the device supply chain remain unidentified.
The firmware component can silently install and remove applications, grant permissions, modify system settings, and download and execute remotely supplied code. Its modular architecture supports command-and-control-directed updates and payload management. Disguised utility applications provide monetization through legitimate advertising SDKs, while malicious plugins fabricate advertising impressions, clicks, and conversion events without user interaction. Additional payloads include proxyware capable of registering devices with a remotely controlled network and relaying traffic to operator-specified destinations, including local-network hosts. The malware also collects device identifiers and configuration information.
Midnight Mimosa conceals its components under system-like identities, rotates installed payloads, temporarily disables Google Play during payload installation, and can forge installation provenance to make sideloaded applications appear to originate from Google Play. Some advertising surfaces are protected against capture in screenshots and screen recordings. Related ad-fraud code was also identified in 13 Google Play applications, which lacked the firmware component's system privileges. Ordinary application uninstallation cannot remove the firmware-resident component, and a factory reset may be insufficient; remediation may require trusted firmware replacement or device replacement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
143 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Firmware-embedded Android malware found preinstalled on thousands of inexpensive, white-label, or counterfeit phones across more than 150 countries during a two-year observation period. It operates with system-level privileges to silently install or remove applications, grant permissions, collect device information, and download additional code. Its primary observed purpose is advertising and click fraud through disguised applications that display invisible ads or generate automated clicks. It can temporarily disable the Google Play Store to potentially evade detection and has capabilities for botnet integration. The exact point of compromise in the device supply chain remains unknown.
Malware associated with a supply-chain campaign primarily affecting low-cost, MediaTek-based Android devices. Preinstalled as a persistent firmware system app, it cannot be removed through normal uninstall procedures. Its system-level privileges enable silent app installation and removal, permission granting, and execution of remotely supplied code. Operators use it for advertising and automated click fraud, botnet participation, and proxy-network abuse. It temporarily disables Google Play during payload installation, reportedly to evade Play Protect scanning. Bitdefender observed thousands of affected devices across more than 150 countries over two years and identified 13 Google Play apps containing the same ad-fraud code, although those apps lack the firmware malware's privileged access.
Malware preinstalled in system-level firmware on counterfeit and budget Android phones. It uses system privileges to download and execute additional code, silently install or remove apps, and grant permissions. Observed payloads generate hidden advertising impressions and clicks and relay third-party traffic through infected devices. It temporarily disables the Google Play Store during payload installation, potentially avoiding Play Protect checks, and can falsely attribute sideloaded apps to Google Play. Thousands of infected devices were observed across more than 150 countries. Normal uninstallation or factory resets may not remove it; trusted firmware replacement, vendor remediation, or device replacement may be necessary. The supply-chain entry point remains unknown, and data theft was not the main activity observed.
The name denotes the campaign centered on a persistent, platform-signed Android malware core preinstalled in device firmware. Its system privileges enable silent application installation and removal, permission granting, and remote code loading. Remotely provisioned plugins and cover applications conduct hidden advertising and click fraud, collect device information, and deploy residential-proxy payloads. The malware temporarily disables Google Play during payload installation and can forge installer provenance. Accessibility, notification, and SMS capabilities are available, but their malicious use was not observed. Normal application uninstallation cannot remove the firmware-resident core.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.