Skip to content

Image: blogapp.bitdefender.com · rights & removal

Executive Summary

Malware known as Midnight Mimosa targets low-cost, multi-brand Android devices running MediaTek platforms. The malware is preinstalled in the device firmware and resides within multiple system packages across different devices. This malware operates with system-level privileges to install and remove applications, grant permissions, and load arbitrary code remotely. The scheme functions by dropping cover applications, such as fake weather or app-lock tools, which load legitimate ads via a legitimate SDK, creating an illusion of normal operation while facilitating fraudulent ad revenue.
The core malicious component, com.android.system.lite, acts as an enabler, managing the installation and removal of rotating payloads. This process involves silently installing partner applications, including those for ad fraud and botnet enrollment, often bypassing user prompts and security checks by manipulating system processes like PackageInstaller and Play Protect settings. The operation is further enhanced by loading sophisticated code through a native library that decrypts and executes remote instructions, allowing for synthetic clicks and tracking of user interactions.
The broader scheme utilizes these infected devices as residential-proxy relay nodes, integrating them into botnets for activities like ad and click fraud and potential DDoS attacks. The infection vector suggests integration deep within the supply chain, potentially involving firmware signing certificates from entities like Shenzhen Zediel, operating across numerous devices globally.

Facts Only

* Malware targets low-cost, multi-brand Android devices built on MediaTek platforms.
* Malware is shipped preinstalled in the device firmware across multiple system packages depending on the device.
* The malware runs with system-level privileges to install/remove apps, grant permissions, and load arbitrary code remotely.
* The scheme generates revenue through ad and click fraud by loading ads via cover apps that use legitimate SDKs.
* The core system app identified is com.android.system.lite, which manages the installation and removal of payloads.
* The investigation identified rotating system names for the malware core, including com.android.sys.prot, com.android.sys.gmsprot, and com.android.sys.bcprot.
* Thirteen applications on Google Play communicate with the same servers controlling the malware.
* A system application is analyzed as an enabler that manages privileged permissions like INSTALLPACKAGES and DELETEPACKAGES.
* The enabler utilizes a native library (libeasy.so) to decrypt and load payloads from remote C2 servers.
* The payload execution includes functions for programmatic, synthetic clicks and automated reporting of interactions.
* A portfolio of installed applications includes com.mobile.applock.en, com.dmstudio.weather, and others.
* The attack propagates through firmware signed with certificates attributed to Shenzhen Zediel on affected devices.
* Packaged apps are installed by the enabler, often spoofing installation sources to evade detection mechanisms like Play Protect.

Full Take

The narrative describes a sophisticated layered attack that moves beyond simple application installation to establish persistent, privileged control over the operating system environment. The core finding is the shift in security focus from static app scanning (checking what an app *is*) to dynamic behavioral analysis (checking what an app *does*). This demonstrates a critical failure in traditional mobile security assumptions—the assumption that a clean static scan equates to safety.
The attack’s resilience stems from embedding the root mechanism deep within platform-signed system components, specifically com.android.system.lite. By operating at the system-uid level and leveraging undocumented or highly privileged APIs (like granting runtime permissions and managing PackageInstaller sessions without user interaction), the malware bypasses standard user controls and forensic visibility. The use of obfuscation in native libraries and remote C2 communication not only hides the malicious payload but also establishes a self-contained operational model that is difficult to disrupt by patching single components.
The pattern observed extends across the entire ecosystem: exploiting cheap hardware supply chains, using compromised firmware signing for distribution, and layering fake applications over legitimate advertising structures to monetize activity. The subsequent pivot into establishing residential-proxy relay nodes indicates an intent to leverage these compromised devices not just for immediate financial gain, but for participation in larger, more robust criminal infrastructures like botnets. This suggests a systemic strategy where hardware sourcing, firmware integrity, and application behavior are all interconnected attack surfaces that must be analyzed holistically to understand the full scope of compromise and agency loss.
Bridge Questions:
What mechanisms exist outside of on-device behavioral analysis (like Bitdefender's App Anomaly Detection) that can reliably detect deep, system-level modifications before runtime activation?
How can hardware manufacturers and distributors establish verifiable chain-of-custody for firmware and signing certificates to prevent the introduction of persistent malware in the initial stages of the supply chain?
What are the long-term societal and economic consequences when platforms rely on outdated security assumptions that fail against dynamic, system-level attacks?

From the original · Bitdefender Labs

Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms. The malware ships preinstalled in the device firmware, and we found multiple system packages involved, depending on the device.
Read the full story at bitdefender.com
The phone was compromised before the user turned it on: the rise of Midnight Mimosa | Huntaegis