Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Mafia III has a free update available right now

    October 10, 2026

    The real reason your high-end Bluetooth headphones don’t sound as good as you’d expect

    October 10, 2026

    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

    October 10, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
    Cybersecurity

    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

    The Tech GuyBy The Tech GuyOctober 10, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    There is a large global market for low-cost Android devices. Bad actors are aware and are servicing the demand through devices built on MediaTek platforms – but with malware preinstalled in the device firmware. 

    Advertisement

    When the recipient of such an affected device switches it on, the malware is present, unseen, and available to any bad actor who can control it remotely from its C2. It is a persistent, pre-installed firmware system app that cannot be removed by normal uninstall procedures.

    The campaign, dubbed Midnight Mimosa, was discovered and analyzed by Bitdefender.

    The potential for this type of malware infection controlled via the actor’s C2 is massive. “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” writes the Bitdefender report.

    Midnight Mimosa is focused on ad fraud, automated click fraud, and turning the device into a single component of a much larger botnet. This makes sense for a campaign seeking to fly under the radar with an army of soldiers. Many thousands of click frauds over a period of time would provide a healthy ROI for any bad actor. And botnets are described as a hot commodity that can be rented out to other bad actors. The bigger the botnet, the better the bounty.

    Over the last two years, Bitdefender has observed thousands of unique affected devices in more than 150 countries. No single country or region dominates distribution. Mexico and France lead, followed by Italy, US, Germany, Brazil and Spain. Regionally, Western Europe and the Americas stand out. The report gives no indication of the actual monetary gain achieved by the Midnight Mimosa operators but does provide an extensive list of IoCs to help prevent it.

    Advertisement. Scroll to continue reading.

    Bitdefender also found 13 apps on Google Play with separate signing certificates under two developer accounts and containing the same Midnight Mimosa ad-fraud code. “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself,” note the researchers.

    These Play Store apps do not have the same privileged access as the preinstalled malware, but are considered associated with the broader ecosystem, giving the attackers an additional distribution channel.

    Whether the malware is preinstalled or loaded from Play Store, it has been seen disabling the Play Store before installing additional payload applications and then re-enabling it afterward – probably to avoid detection by Play Protect. “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install,” note the researchers. “The malicious install happens in a window where Google’s scanner is switched off.”

    Midnight Mimosa is best considered as a supply-chain threat where malware is largely integrated into the Android device prior to sale. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse and remote payload management. Attackers have extensive control over affected devices from the get-go.

    Related: RatHat Android Trojan Uses AI for Automation

    Related: Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

    Related: New BTMOB Android Malware Enables Full Device Takeover

    Related: Mirax RAT Targeting Android Users in Europe

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Insider Cyber Extortion Plot Against Industrial Firm Lands Engineer in Prison

    October 10, 2026

    Google Domains Impacted by Recent ccTLD Hijacks

    October 10, 2026

    OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks

    October 9, 2026

    In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

    October 9, 2026

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    October 9, 2026

    Formula Predicts When AI Chatbots Are at Risk of Turning Bad

    October 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026393 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Mafia III has a free update available right now

    October 10, 2026

    The real reason your high-end Bluetooth headphones don’t sound as good as you’d expect

    October 10, 2026

    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

    October 10, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.