Full Report
Bitdefender's security researchers have identified a malware campaign (dubbed Midnight Mimosa) running on low-cost, multi-brand Android devices built on MediaTek platforms.
Analysis Summary
# Tool/Technique: Midnight Mimosa
## Overview
Midnight Mimosa is a sophisticated malware campaign targeting low-cost Android devices built on MediaTek platforms. The malware is pre-installed in the device firmware as a platform-signed system application, allowing it to bypass standard security measures and persist even after factory resets. Its primary purpose is to generate revenue for operators through ad/click fraud and by enrolling infected devices into a residential proxy botnet.
## Technical Details
- **Type:** Malware Family (Firmware-level Enabler & Dropper)
- **Platform:** Android (specifically MediaTek-based budget devices)
- **Capabilities:** System-level privileges, silent app installation/removal, automated permission granting (Accessibility, SMS, Notification Access), remote code loading (DEX), proxyware relay, and ad fraud.
- **First Seen:** Identified/Reported October 2026 (Bitdefender)
## MITRE ATT&CK Mapping
- **TA0031 - Persistence**
- T1542.001 - Pre-installed Software
- **TA0030 - Privilege Escalation**
- T1548 - Abuse Elevation Control Mechanism
- **TA0037 - Command and Control**
- T1071.001 - Web Service: Communication over HTTPS
- T1573.001 - Encrypted Channel: Symmetric Cryptography (AES)
- **TA0032 - Credential Access**
- T1636.004 - SMS Messages
- **TA0038 - Effects**
- T1499 - Endpoint Denial of Service (Botnet participation)
- T1643 - Ad Fraud
## Functionality
### Core Capabilities
- **Firmware Persistence:** Resides as a system package (e.g., `com.android.system.lite`) signed with platform certificates, making uninstallation impossible for standard users.
- **Silent Payload Delivery:** Periodically checks a C2 server to download and install "cover apps" (Weather, AppLock, OCR) that act as the revenue-generating engines.
- **Evasion:** Disables the Google Play Store application immediately before installing a payload to avoid Play Protect interference, re-enabling it once the task is complete.
- **Permission Manipulation:** Automatically grants itself and its payloads dangerous permissions like Accessibility Services and Notification Access without user intervention.
### Advanced Features
- **Residential Proxy Integration:** Turns the device into a SOCKS proxy node, allowing threat actors to route malicious traffic through the user’s home IP address.
- **Dynamic Module Loading:** Uses reflective loading to execute encrypted DEX files fetched from remote CDNs (disguised as `.png` files).
- **Invisible Ad Layering:** Renders invisible windows over legitimate apps to register fraudulent ad impressions and clicks via legitimate SDKs.
## Indicators of Compromise
- **File Names (System Packages):**
- `com.android.system.lite`
- `com.android.sys.prot`
- `com.android.sys.gmsprot`
- `com.android.sys.bcprot`
- **Payload App Packages:**
- `com.mobile.applock.wt`
- `com.weather.live.forecast`
- **Network Indicators:**
- `api.weatherlive[.]world` (C2 Command Channel)
- `oss.showtimetool[.]com` (Payload/Module CDN)
- `85.17.70[.]38` (Proxy Botnet Control Server)
- `apple.0aa0cf0637d66c0d[.]com` (DGA/Wildcard DNS for Proxy enrolment)
- **Behavioral Indicators:**
- System apps requesting Accessibility or SMS permissions.
- Unexpected disabling/enabling of the Google Play Store.
- High background data usage attributed to "Weather" or "System" apps.
## Associated Threat Actors
- Unknown (Currently attributed to generalized revenue-motivated cybercrime groups specializing in botnet-as-a-service and ad fraud).
## Detection Methods
- **Signature-based detection:** Scanning for specific package names and signing certificates associated with the "Midnight Mimosa" core.
- **Behavioral detection:** Monitoring for `com.android` namespace apps that perform reflective DEX loading or toggle the status of the Play Store app.
- **Network Monitoring:** Alerting on encrypted POST requests to the `weatherlive[.]world` domain or traffic on port 6000 associated with proxy relaying.
## Mitigation Strategies
- **Hardware Selection:** Avoid purchasing "no-name" or ultra-low-cost Android devices from unverified vendors where supply chain security is weak.
- **Mobile Security:** Deploy mobile threat defense (MTD) solutions that utilize behavioral anomaly detection rather than just static signature scanning.
- **Firmware Updates:** Regularly check for official manufacturer updates, though compromised firmware may prevent legitimate updates.
## Related Tools/Techniques
- **Triada Malware:** Similar firmware-level persistence and injection techniques.
- **LemonGroup:** Known for large-scale pre-installed Android botnets.
- **Socks5 Proxyware:** Similar to "Residential Proxy" tools used to monetize infected hosts.