Threat reportSupply ChainTL-2026-3066

Midnight Mimosa: Low-cost MediaTek Android phones ship with firmware-level ad-fraud and residential proxy malware

highACTIVE

Midnight Mimosa (TL-2026-3066), also tracked as Midnight Mimosa, is a high-severity supply-chain compromise, first published 2026-10-09. It has no confirmed attribution, affects Doogee S200 X, Fire 3 Max (MediaTek-based Android phones), maps to 16 MITRE ATT&CK techniques (T1406, T1407, T1418), and is covered by 9 detection rules and 47 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
47Indicators of compromise

Key facts for TL-2026-3066

Threat ID
TL-2026-3066
Also known as
Midnight Mimosa
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, enterprise-byod, advertising
Target regions
mexico, france, italy, united states of america, germany, brazil, spain, Global
Detection rules
9
Indicators of compromise
47
Updates
2026-10-09 · revalidated 1× · latest source

Malware and tooling in Midnight Mimosa

Malware and tooling: Midnight Mimosa

How Midnight Mimosa works

Bitdefender found the Midnight Mimosa malware preinstalled in the firmware of low-cost MediaTek-based Android phones (e.g. Doogee S200 X, Cubot KINGKONG X, and counterfeit Samsung/Apple-branded devices). A platform-signed system app silently installs and removes apps, loads remote code, commits ad fraud and enrolls devices as residential proxy nodes; activity spans about two years and 150+ countries with no attribution.

Bitdefender Labs (reported by BleepingComputer on 2026-10-08) describes Midnight Mimosa as a malware framework present in the system partition of low-cost Android phones before the user first powers them on. Affected devices are built on MediaTek platforms (board k62v1_64_bsp / MT6762 observed) and include genuine budget brands (Doogee S200 X, Doogee Fire 3 Max, Cubot KINGKONG X), region-coded ODM builds (J10_EEA, A9_EEA, T13_EEA, Q6_EEA) and counterfeit flagship-named devices (S24/S25/S26 Ultra, i16/i17 Pro Max, Note 18 Ultra). Bitdefender's App Anomaly Detection flagged a suspicious system application; the campaign was observed on thousands of devices across 150+ countries over roughly two years, with Mexico, France, Italy, the United States, Germany, Brazil and Spain the most affected.

The enabler is a system app (com.android.system.lite, versionCode 900000, plus variants com.android.sys.prot, com.android.sys.gmsprot, com.android.sys.bcprot and, per BleepingComputer, com.android.non.szcz) signed with a platform key whose certificate is associated with Shenzhen Zediel Co., Ltd. (DN CN=ZED, O=ZED, L=ShenZhen, C=CN). Researchers stress this does not establish that the firmware vendor knowingly distributed the malware. The enabler runs as the system user and holds INSTALL_PACKAGES, DELETE_PACKAGES, GRANT_RUNTIME_PERMISSIONS, WRITE_SECURE_SETTINGS and MOUNT_UNMOUNT_FILESYSTEMS. Before installing payloads it runs 'pm disable com.android.vending' and re-enables Play afterwards, and it sets the installer package to com.android.vending without Play's frosting signature block to fake Google Play provenance. Manifest-declared capabilities also include Accessibility Service, Notification Access and SMS read/write.

A native library, libeasy.so, RC4-decrypts (key 'rc4@sec.com') the dropped framework cn.kw.lib.hex. Strings are protected with AES-128-CFB (keys derived as MD5 of fixed base64-looking constants). The framework contacts api.weatherlive.world (module config via /br_upgrade/upgradeV2/getConfigs, telemetry via /odborwer_dot/cm) and downloads modules from oss.showtimetool.com disguised as .png files. Stage-3 plugins include 'wz' (com.wz.sdk.DxFactory, ad fraud: fake impressions and clicks driven by a RemoteConfig object with silentPercent, notClickPercent, notClickInterval and tap-placement rate parameters, with auto-conversion reports after 60 seconds), 'earn' (com.earnsdk.lib.DxFactory, silent installation) and 'gogo' (com.gogo.third.lib.DxFactory, silent installer with WebView).

The proxyware component is the dropped app com.mobile.applock.en (EnLoaderLib v1.0.6). It registers a device UUID and fingerprint (Model#Release#SDK_INT#Build.ID#Brand), opens a raw TCP socket to {productId}.apple.{domain}:6000 (and 85.17.70.38:6000) and relays bytes full-duplex between the controller and target hosts, turning the phone into a residential proxy node. The same ad-fraud code appears in 13 apps on Google Play published under at least two developer accounts (fivedev, CPS Developer) with 13 distinct signing certificates; they masquerade as weather, file manager, app locker, OCR/picture-translate and audio editor utilities.

Bitdefender links the operation by shared infrastructure to earlier malware: Android.Joker.310.origin (2021, premium-SMS fraud, shared domain zhuifengzhe.top) and Android.Phantom.5 / Android.Click.429.origin (2025, dropper and click fraud). Because the enabler is platform-signed and lives in the system partition, standard uninstall does not work; removal needs firmware-level cleanup or ADB disabling. No CVE or CVSS applies. Attribution to a named actor is not established.

MITRE ATT&CK techniques used in TL-2026-3066

Defense Evasion

T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1629.003 Impair Defenses: Disable or Modify Tools; T1630.002 Indicator Removal on Host: File Deletion; T1655.001 Masquerading: Match Legitimate Name or Location

Discovery

T1418 Software Discovery; T1426 System Information Discovery

Command and Control

T1437.001 Application Layer Protocol: Web Protocols; T1509 Non-Standard Port; T1521.001 Encrypted Channel: Symmetric Cryptography; T1544 Ingress Tool Transfer

Initial Access

T1474.003 Supply Chain Compromise: Compromise Software Supply Chain

Execution

T1575 Native API

defense-evasion

T1604 Proxy Through Victim

Impact

T1643 Generate Traffic from Victim

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Midnight Mimosa

  • Doogee — S200 X, Fire 3 Max (MediaTek-based Android phones)
    Vulnerable versions: Preinstalled firmware builds observed by Bitdefender
  • Cubot — KINGKONG X (MediaTek-based Android phones)
    Vulnerable versions: Preinstalled firmware builds observed by Bitdefender
  • Various / counterfeit (impersonating Samsung and Apple) — Low-cost MediaTek Android phones branded S24/S25/S26 Ultra, i16/i17 Pro Max, Note 18 Ultra and region-coded ODM builds J10_EEA, A9_EEA, T13_EEA, Q6_EEA
    Vulnerable versions: Preinstalled firmware builds observed by Bitdefender

Remediation for Midnight Mimosa

Patches

  • No vendor patch identified in the sources; removal requires a firmware-level cleanup (clean reflash) from a trusted source

Immediate actions

  • Inventory fleet and BYOD Android devices for com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot, com.android.sys.bcprot and com.android.non.szcz
  • Block api.weatherlive.world, oss.showtimetool.com, 85.17.70.38 and the other listed domains at DNS/proxy/firewall, including outbound TCP/6000 from mobile segments
  • Quarantine or deny corporate access to affected Doogee, Cubot and counterfeit-branded devices pending remediation

Workarounds

  • Disable the malicious packages via ADB (standard uninstall is blocked by system-level privileges)
  • Stop using the device for sensitive activity if firmware cannot be replaced

Longer-term hardening

  • Procure devices only from vendors with verified firmware supply chains and Play Protect certification
  • Use mobile threat defense / app anomaly detection to flag unexpected platform-signed system apps and installer-spoofing
  • Add device attestation and compliance checks to MDM access policies

Weaknesses (CWE) in Midnight Mimosa

CWE-506, CWE-1357

Timeline of Midnight Mimosa

  • Android.Joker.310.origin (premium-SMS fraud) observed sharing the domain zhuifengzhe.top with this operator lineage (year only per Bitdefender)
  • MAC OUI A0:53:94 associated with the platform-key certificate holder registered with IEEE
  • Bitdefender App Anomaly Detection behavioral monitoring in place since 2023 (year only per Bitdefender)
  • Midnight Mimosa preinstalled enabler, ad fraud and proxyware activity begins (2024-2025 window; about two years before disclosure)
  • Build tag 20240425 observed in the enabler's nativeInit(), anchoring the start of the roughly two-year campaign window.
  • Android.Phantom.5 / Android.Click.429.origin dropper and click-fraud malware share infrastructure with the campaign (year only per Bitdefender)
  • Payload path oss.showtimetool.com/ssc/2025/12-07/ observed serving disguised .png modules.
  • Payload path oss.showtimetool.com/ssc/2026/03-09/ observed serving disguised .png modules.
  • Payload path oss.showtimetool.com/ssc/2026/07-04/ observed serving disguised .png modules.
  • Payload path oss.showtimetool.com/ssc/2026/08-13/ observed serving disguised .png modules, the most recent staging date in the published IOCs.
  • BleepingComputer reports Bitdefender's findings: Midnight Mimosa in firmware of low-cost Android phones across 150+ countries

Update history for TL-2026-3066

Sources cited for Midnight Mimosa

Detection coverage for TL-2026-3066

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3066 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
47 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats