Full Report
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]
Analysis Summary
# Tool/Technique: Midnight Mimosa
## Overview
Midnight Mimosa is a sophisticated malware framework discovered pre-installed in the firmware of low-cost Android smartphones. Its primary purpose is to establish a persistent foothold at the system level to perform large-scale advertising fraud, silent application installation, and the conversion of mobile devices into residential proxies for relaying malicious network traffic.
## Technical Details
- **Type:** Malware Family / Framework
- **Platform:** Android (specifically devices using MediaTek chipsets)
- **Capabilities:** System-level persistence, silent app installation/removal, Google Play Protect evasion, ad-fraud (hidden windows/clicks), residential proxy relaying, and remote code execution.
- **First Seen:** Approximately 2024 (Campaign active for ~2 years prior to discovery).
## MITRE ATT&CK Mapping
- **[TA0027 - Persistence]**
- [T1542.001 - Pre-installed Software]
- **[TA0005 - Evasion]**
- [T1562.001 - Disable or Modify Tools] (Disabling Google Play Store)
- [T1036 - Masquerading] (Impersonating system packages)
- **[TA0003 - Persistence]**
- [T1624.001 - System Partition]
- **[TA0011 - Command and Control]**
- [T1090 - Proxy] (Residential proxy functionality)
- **[TA0030 - Impact]**
- [T1499 - Endpoint Denial of Service] (Through resource consumption for ad-fraud)
## Functionality
### Core Capabilities
- **Firmware Integration:** Located in the system partition with elevated privileges, preventing standard uninstallation.
- **Silent Package Management:** Capability to install and remove apps without user interaction by abusing system permissions.
- **Play Protect Bypass:** Temporarily disables `com.android.vending` (Google Play Store) during malicious installs to avoid security scans.
- **Installer Spoofing:** Manipulates Android metadata to make sideloaded apps appear as if they were legitimately installed via the Google Play Store.
### Advanced Features
- **Residential Proxy Relay:** A TCP proxy component allows attackers to route external internet traffic through the victim’s IP address, masking the attacker's origin.
- **Ad-Fraud Revenue Engine:** Drops "cover apps" (Weather, OCR, etc.) that load invisible windows to register fraudulent ad impressions and clicks in the background.
## Indicators of Compromise
- **File Names (Malicious System Packages):**
- `com.android.system.lite`
- `com.android.sys.prot`
- `com.android.sys.gmsprot`
- `com.android.non.szcz`
- **File Names (Cover/Payload Apps):**
- `com.mobile.applock.en`
- **Developer Accounts (Google Play):**
- `fivedev`
- `CPS Developer`
- **Network Indicators:**
- Communicates with C2 infrastructure associated with "Midnight Mimosa" (Specific domains defanged in full reports).
- **Behavioral Indicators:**
- Automated disabling/re-enabling of the Google Play Store app.
- Unexpected background network traffic on TCP ports associated with proxying.
- Presence of unrecognized apps that reinstall themselves after deletion.
## Associated Threat Actors
- **Unknown:** While firmware certificates associated with **Shenzhen Zediel** were identified, specific attribution to a known threat group has not been confirmed. The campaign targets supply chain vulnerabilities.
## Detection Methods
- **Signature-based detection:** Identifying specific package names (e.g., `com.android.system.lite`) and hashes of the dropped ad-fraud modules.
- **Behavioral detection:** Monitoring for system applications that programmatically disable security services (`com.android.vending`) or initiate unexpected outbound TCP proxy connections.
- **Firmware Scanning:** Using tools to audit the `/system` partition for non-standard, signed packages.
## Mitigation Strategies
- **Prevention:** Avoid purchasing "low-cost" or off-brand Android devices from unverified vendors or those with opaque supply chains.
- **Hardening:** For affected devices, use **Android Debug Bridge (ADB)** to disable malicious packages if they cannot be uninstalled.
- **Remediation:** Check for official manufacturer firmware updates that specifically address "security vulnerabilities" or "pre-installed components." In extreme cases, flashing a clean, trusted ROM is required.
## Related Tools/Techniques
- **LemonGroup / Triada:** Similar pre-installed Android malware families focused on ad-fraud and proxying.
- **Supply Chain Compromise:** The technique of injecting malware into the original equipment manufacturer (OEM) or distributor image.