Midnight Mimosa Malware Found in Firmware of Some Low-Cost Android Phones
Bitdefender found Midnight Mimosa, firmware malware in some low-cost Doogee and Cubot Android phones that can install apps, evade Play Protect and join botnets.
The malware lives in the system partition, which makes it unusually difficult to remove. That placement also means an affected phone can be compromised before a user takes it out of the box. Android Authority reported that Bitdefender shared its findings in a blog post.
The discovery challenges longstanding advice that users should avoid unknown apps, stick to the Google Play Store and rely on trusted sources if they sideload APKs. That guidance assumes a phone is malware-free to begin with. For owners of the affected low-cost devices, the malware may already be part of the firmware, so downloading only from official stores would not address the problem.
Midnight Mimosa can grant permissions and evade Play Protect, giving it significant control over a device. Its botnet functionality links infected phones to a broader network. The report did not provide a full list of affected models or explain exactly how the firmware-level malware was distributed.
Bitdefender researchers described the campaign in a blog post, according to Android Authority. The report said removal is not easy because the malware resides in the system partition. The name may sound pleasant, but the campaign is one that phone owners would not want on their devices.