Pre-Installed Firmware Malware Affects Affordable Android Phones in 150+ Nations

www.news4hackers.com-pre-installed-firmware-malware-affects-affordable-android-phones-in-150-nations-pre-installed-firmware-malware-affects-affordable-android-phones-in-150-nations

Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries A cybersecurity threat involving pre-installed malware in the firmware of budget Android devices has been identified, impacting over 150 countries.

Midnight Mimosa Analysis

The malicious software, discovered by researchers, is embedded in devices using MediaTek platforms, allowing attackers to maintain persistent control over affected systems. Upon initial activation, the malware operates covertly, granting remote access through a command-and-control infrastructure.

Key Features of Midnight Mimosa

This persistent, system-level application cannot be removed via standard uninstallation processes. The campaign, labeled Midnight Mimosa, was analyzed by cybersecurity firm Bitdefender. The malware leverages elevated privileges to execute unauthorized actions, including installing or removing applications, modifying permissions, and executing remote code.

Malware Capabilities

Researchers highlighted that the malware’s design allows for dynamic reconfiguration, enabling attackers to tailor device behavior to specific objectives. The primary focus of Midnight Mimosa appears to be ad fraud and automated click fraud, with devices serving as components of a larger botnet.

Remote Control and Botnet Use

This capability enables operators to repurpose devices for malicious activities, such as ad fraud and botnet participation. Botnets are also valuable as rental assets for other cybercriminal operations, incentivizing the expansion of such networks.

Distribution and Reach

Over the past two years, Bitdefender identified thousands of unique devices affected across 150+ countries, with no single region dominating the distribution. Notable hotspots include Mexico, France, Italy, the United States, Germany, Brazil, and Spain, with Western Europe and the Americas showing significant activity.

Additional Distribution Vectors

Bitdefender’s analysis revealed 13 applications on Google Play containing the same ad-fraud code as the firmware-based malware. These apps, distributed under separate developer accounts with distinct signing certificates, represent an additional distribution vector.

Installation Techniques

While these applications lack the system-level access of the firmware malware, they contribute to the broader ecosystem by expanding the attack surface. The threat is classified as a supply-chain attack, with malware integrated into devices prior to sale.

Supply-Chain Attack Details

Key characteristics include preinstalled persistence, remote payload management, and abuse of proxy networks. Attackers gain immediate control over affected devices, enabling extensive manipulation. The campaign underscores the risks associated with compromised hardware and the challenges of detecting firmware-level threats.

Indicators of Compromise

Indicators of compromise (IoCs) have been documented to aid in identification and mitigation. The report emphasizes the need for proactive monitoring of device firmware and application behavior to counter such threats.

Conclusion

The discovery highlights the growing sophistication of cybercriminal operations targeting low-cost hardware, leveraging supply-chain vulnerabilities to scale malicious activities globally.

Proactive Monitoring Recommendations

Researchers emphasized the importance of monitoring device firmware and application behavior to detect and mitigate such threats. The global scale of the attack underscores the need for heightened awareness and security measures in budget Android devices.



About Author

en_USEnglish