Bitdefender finds preinstalled Android malware Midnight Mimosa in 150 countries
Bitdefender uncovered Midnight Mimosa, preinstalled malware baked into firmware of low-cost MediaTek Android phones that cannot be removed. With system-level privileges it runs ad and click fraud, silently installs apps and turns devices into residential-proxy nodes for botnets across roughly 150 countries.
- Malware is embedded in firmware, cannot be uninstalled, seen in 150 countries
- Packages com.android.system.lite, sys.prot, sys.gmsprot and sys.bcprot share one codebase
- It silently installs at least 32 apps and enables Accessibility and SMS access
- Infected phones become residential-proxy relay nodes for DDoS botnets
Read next
Security