Midnight Mimosa malware pre-installed in cheap Android phone firmware
Security researchers have identified a malware called Midnight Mimosa embedded in the firmware of low-cost MediaTek Android devices. The malware is pre-installed as a system app before purchase and activates after the device's first boot. It communicates with a command server disguised as a weather service to download additional modules and can disable the Google Play Store. The malware enables ad fraud and can turn devices into residential proxy nodes without user consent. Devices with this compromised firmware require replacement as the malware cannot be removed through standard methods.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in