Bitdefender found Midnight Mimosa malware preinstalled in the firmware of thousands of inexpensive Android phones being sold across 150+ countries. Researchers said: “The malware ships preinstalled in the device firmware, and (was) found multiple system packages involved, depending on the device. It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.
“The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets. This scheme is likely designed mainly to generate revenue,” the reviewers said.
Western Europe and the Americas are “centers of gravity” for the infected devices.
Ted Miracco, CEO, Approov:
The uncomfortable takeaway from Midnight Mimosa is that you can’t assess an app’s security in isolation from the environment it runs in.
If malware is embedded in firmware before a phone even reaches the customer, trust is undermined before the first login. The user didn’t have to download a malicious APK. The app didn’t necessarily do anything wrong. The underlying device was already compromised.
For organizations protecting mobile APIs, this raises a bigger question: Should a successful login be enough to trust a mobile request?
The answer is no. Authentication verifies user credentials; it does not establish the integrity of the app or device making the request. App attestation and runtime integrity signals provide additional evidence that should inform API access decisions.
Crucially, those decisions should be enforced outside the potentially compromised device, using remotely evaluated integrity checks and backend verification.
When compromise occurs below the application layer, app and device integrity need to become part of the API security decision—not assumptions sitting underneath it.
Roland Lindsey, Lead Solutions Engineer, Finite State:
“This is why there is no substitute for binary analysis on the shipping firmware. Source trees and build processes are aspirational. If you aren’t looking at what ships to the customer, you are running blind.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“This is a serious supply chain security issue because these devices are potentially compromised before consumers ever turn them on. When malware is embedded in firmware, traditional security tools may have limited visibility, and consumers have little chance of identifying or removing the threat.
“One of the biggest blind spots is the lack of oversight into third-party firmware, preinstalled applications, and software components supplied by outside vendors. Manufacturers need to take responsibility for the entire software supply chain, not just the components they develop themselves.
“Firmware integrity checks, cryptographic signing, secure boot, and independent security testing should be standard practices before devices ship. Security needs to start at manufacturing, not after a compromised device reaches the consumer.”
This is a serious problem as there are millions of Android phones out there and a lot of them are on the cheaper side. This may make people decide to go more upscale if they want a phone that doesn’t have unwanted guests.
Related
This entry was posted on October 8, 2026 at 6:42 pm and is filed under Commentary with tags Bitdefender. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Midnight Mimosa malware in Android firmware with system level privileges
Bitdefender found Midnight Mimosa malware preinstalled in the firmware of thousands of inexpensive Android phones being sold across 150+ countries. Researchers said: “The malware ships preinstalled in the device firmware, and (was) found multiple system packages involved, depending on the device. It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.
“The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets. This scheme is likely designed mainly to generate revenue,” the reviewers said.
Western Europe and the Americas are “centers of gravity” for the infected devices.
Ted Miracco, CEO, Approov:
The uncomfortable takeaway from Midnight Mimosa is that you can’t assess an app’s security in isolation from the environment it runs in.
If malware is embedded in firmware before a phone even reaches the customer, trust is undermined before the first login. The user didn’t have to download a malicious APK. The app didn’t necessarily do anything wrong. The underlying device was already compromised.
For organizations protecting mobile APIs, this raises a bigger question: Should a successful login be enough to trust a mobile request?
The answer is no. Authentication verifies user credentials; it does not establish the integrity of the app or device making the request. App attestation and runtime integrity signals provide additional evidence that should inform API access decisions.
Crucially, those decisions should be enforced outside the potentially compromised device, using remotely evaluated integrity checks and backend verification.
When compromise occurs below the application layer, app and device integrity need to become part of the API security decision—not assumptions sitting underneath it.
Roland Lindsey, Lead Solutions Engineer, Finite State:
“This is why there is no substitute for binary analysis on the shipping firmware. Source trees and build processes are aspirational. If you aren’t looking at what ships to the customer, you are running blind.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“This is a serious supply chain security issue because these devices are potentially compromised before consumers ever turn them on. When malware is embedded in firmware, traditional security tools may have limited visibility, and consumers have little chance of identifying or removing the threat.
“One of the biggest blind spots is the lack of oversight into third-party firmware, preinstalled applications, and software components supplied by outside vendors. Manufacturers need to take responsibility for the entire software supply chain, not just the components they develop themselves.
“Firmware integrity checks, cryptographic signing, secure boot, and independent security testing should be standard practices before devices ship. Security needs to start at manufacturing, not after a compromised device reaches the consumer.”
This is a serious problem as there are millions of Android phones out there and a lot of them are on the cheaper side. This may make people decide to go more upscale if they want a phone that doesn’t have unwanted guests.
Share this:
Like this:
Related
This entry was posted on October 8, 2026 at 6:42 pm and is filed under Commentary with tags Bitdefender. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.