Low-cost Android phones ship with residential proxy malware
Firmware-level compromise discovered in devices attributed to 'Midnight Mimosa' campaign

Key Takeaways
- Malware 'Midnight Mimosa' embedded in firmware of low-cost Android smartphones at manufacturing stage.
- Enables silent app installation, ad fraud, and conscription of devices into residential proxy networks.
- Firmware-level persistence complicates removal and standard factory resets may not eliminate the threat.
- Affected users are advised to avoid devices from implicated manufacturers and report incidents to consumer protection agencies.
Quick answers
- What happened?
- Security researchers have identified a malware campaign, tracked as 'Midnight Mimosa', where malicious software is embedded in the firmware of low-cost Android smartphones. The compromise enables silent app installation, ad fraud, and the conscription of devices into residential proxy networks without user consent.
- Which products are affected?
- Low-cost Android smartphones (models and manufacturers not independently verified in available reports)
- What should defenders do?
- Affected users should avoid purchasing devices from implicated manufacturers. For devices already in use, performing a factory reset is recommended, though firmware-level persistence may require hardware-level intervention. Reporting the incident to consumer protection agencies is advised. Google Play Protect may detect known variants of the malware.
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, according to security reporting. The compromise allows attackers to silently install applications, perform ad fraud, and turn devices into residential proxies. The firmware-level persistence makes the malware difficult to remove through standard factory resets, as the malicious code persists at the system-on-chip level. Affected devices have been observed globally, primarily impacting budget Android smartphones sold through retail channels. The investigation attributes the campaign to threat actors operating under the 'Midnight Mimosa' moniker, though independent verification of the attribution and the exact scope of affected manufacturers remains limited. Google Play Protect may detect known variants, but no firmware patch is available for the embedded compromise.
Security Details
The malware operates at the firmware level, leveraging Android accessibility services and background services to maintain persistence and proxy functionality. It executes with system privileges at boot, allowing silent installation of applications and background ad fraud operations. The use of firmware as a delivery vector ensures persistence across factory resets and standard remediation efforts.
Affected products
Low-cost Android smartphones (models and manufacturers not independently verified in available reports)
Mitigation
Affected users should avoid purchasing devices from implicated manufacturers. For devices already in use, performing a factory reset is recommended, though firmware-level persistence may require hardware-level intervention. Reporting the incident to consumer protection agencies is advised. Google Play Protect may detect known variants of the malware.
Sources
BleepingComputer
Low-cost Android phones ship with residential proxy malware
Oct 8, 2026 · 19:20
Original link
Related Security News

FBI Disrupts Flax Typhoon Hacking Tools MicroScan and FishHub
The FBI, in coordination with international partners, seized seven domains operated by the Chinese state-sponsored threat actor Flax Typhoon. The domains were used to control two hacking tools, MicroScan and FishHub, which were deployed in attacks breaching critical infrastructure and other organizations worldwide. The operation disrupted the threat actor's command-and-control capabilities.




