Malware in Budget Android Firmware: Global Security Threat
New Delhi — A significant cybersecurity threat has been uncovered involving malicious software embedded within the firmware of budget Android devices.
Key Details of the Midnight Mimosa Campaign
Researchers have identified a campaign named Midnight Mimosa, which has operated undetected for nearly two years, compromising thousands of devices across more than 150 countries. The malware infiltrated the core system software of low-cost smartphones, bypassing traditional security measures and remaining persistent despite user attempts to remove it.
Targeted Devices and Supply Chain Vulnerabilities
The investigation revealed that the compromised firmware primarily targeted devices equipped with MediaTek processors. Affected models included the Doogee S200 X, Cubot KingKong X, and counterfeit units mimicking popular brands like Samsung and Apple. While these imitations are not linked to the original manufacturers, the presence of such devices highlights vulnerabilities in the supply chain.
Source of the Tampering
The source of the tampering remains unclear, with possibilities spanning manufacturing, software development, or third-party distribution. The malware leveraged elevated system privileges to disguise its components as legitimate Android processes, such as com.android.system.lite and com.android.sys.prot. This allowed it to evade standard uninstallation procedures, as users reported recurring malicious applications even after manual deletion.
Evasion Techniques and User Reports
A user of the Doogee Fire 3 Max traced the infection to an official firmware update, noting that reverting to an earlier version eliminated the threat but reactivation occurred upon reinstalling the updated firmware. Although some manufacturers released patches to address the issue, none publicly disclosed the origin of the malicious code.
Deceptive Applications and Ad Fraud
In addition to firmware infiltration, researchers discovered 32 deceptive applications posing as utility tools. These included weather apps, file managers, and OCR software, which were used to generate fraudulent ad revenue. The malware operated by embedding invisible advertisements in background windows, creating synthetic clicks without user awareness.
Bypassing Security Checks
To avoid detection, it temporarily disabled the Google Play Store during installation, bypassing security checks by Google Play Protect. Once installed, the store was restored, and altered installer records made the apps appear as if they were sourced from official stores.
Network Relay Infrastructure
A critical aspect of the campaign involved converting infected devices into network relays. Researchers identified a TCP proxy component within an application labeled com.mobile.applock.en, which maintained connections to a command server. This infrastructure enabled malicious actors to route traffic through consumer devices, masking their activities behind legitimate IP addresses.
Potential for Abuse
While active traffic relaying was not observed in newly infected devices, the potential for such abuse underscores the severity of the breach. The findings emphasize the risks associated with supply chain vulnerabilities and the challenges of securing low-cost hardware.
Manufacturers and users are urged to remain vigilant, as the persistence of the malware highlights the need for robust firmware validation and transparency in device development.
