Threat reportSupply ChainTL-2026-3066
Midnight Mimosa: Low-cost MediaTek Android phones ship with firmware-level ad-fraud and residential proxy malware
Midnight Mimosa (TL-2026-3066), also tracked as Midnight Mimosa, is a high-severity supply-chain compromise, first published 2026-10-09. It has no confirmed attribution, affects Doogee S200 X, Fire 3 Max (MediaTek-based Android phones), maps to 16 MITRE ATT&CK techniques (T1406, T1407, T1418), and is covered by 9 detection rules and 47 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 47Indicators of compromise
Key facts for TL-2026-3066
- Threat ID
- TL-2026-3066
- Also known as
- Midnight Mimosa
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, enterprise-byod, advertising
- Target regions
- mexico, france, italy, united states of america, germany, brazil, spain, Global
- Detection rules
- 9
- Indicators of compromise
- 47
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in Midnight Mimosa
Malware and tooling: Midnight Mimosa
How Midnight Mimosa works
Bitdefender found the Midnight Mimosa malware preinstalled in the firmware of low-cost MediaTek-based Android phones (e.g. Doogee S200 X, Cubot KINGKONG X, and counterfeit Samsung/Apple-branded devices). A platform-signed system app silently installs and removes apps, loads remote code, commits ad fraud and enrolls devices as residential proxy nodes; activity spans about two years and 150+ countries with no attribution.
Bitdefender Labs (reported by BleepingComputer on 2026-10-08) describes Midnight Mimosa as a malware framework present in the system partition of low-cost Android phones before the user first powers them on. Affected devices are built on MediaTek platforms (board k62v1_64_bsp / MT6762 observed) and include genuine budget brands (Doogee S200 X, Doogee Fire 3 Max, Cubot KINGKONG X), region-coded ODM builds (J10_EEA, A9_EEA, T13_EEA, Q6_EEA) and counterfeit flagship-named devices (S24/S25/S26 Ultra, i16/i17 Pro Max, Note 18 Ultra). Bitdefender's App Anomaly Detection flagged a suspicious system application; the campaign was observed on thousands of devices across 150+ countries over roughly two years, with Mexico, France, Italy, the United States, Germany, Brazil and Spain the most affected.
The enabler is a system app (com.android.system.lite, versionCode 900000, plus variants com.android.sys.prot, com.android.sys.gmsprot, com.android.sys.bcprot and, per BleepingComputer, com.android.non.szcz) signed with a platform key whose certificate is associated with Shenzhen Zediel Co., Ltd. (DN CN=ZED, O=ZED, L=ShenZhen, C=CN). Researchers stress this does not establish that the firmware vendor knowingly distributed the malware. The enabler runs as the system user and holds INSTALL_PACKAGES, DELETE_PACKAGES, GRANT_RUNTIME_PERMISSIONS, WRITE_SECURE_SETTINGS and MOUNT_UNMOUNT_FILESYSTEMS. Before installing payloads it runs 'pm disable com.android.vending' and re-enables Play afterwards, and it sets the installer package to com.android.vending without Play's frosting signature block to fake Google Play provenance. Manifest-declared capabilities also include Accessibility Service, Notification Access and SMS read/write.
A native library, libeasy.so, RC4-decrypts (key 'rc4@sec.com') the dropped framework cn.kw.lib.hex. Strings are protected with AES-128-CFB (keys derived as MD5 of fixed base64-looking constants). The framework contacts api.weatherlive.world (module config via /br_upgrade/upgradeV2/getConfigs, telemetry via /odborwer_dot/cm) and downloads modules from oss.showtimetool.com disguised as .png files. Stage-3 plugins include 'wz' (com.wz.sdk.DxFactory, ad fraud: fake impressions and clicks driven by a RemoteConfig object with silentPercent, notClickPercent, notClickInterval and tap-placement rate parameters, with auto-conversion reports after 60 seconds), 'earn' (com.earnsdk.lib.DxFactory, silent installation) and 'gogo' (com.gogo.third.lib.DxFactory, silent installer with WebView).
The proxyware component is the dropped app com.mobile.applock.en (EnLoaderLib v1.0.6). It registers a device UUID and fingerprint (Model#Release#SDK_INT#Build.ID#Brand), opens a raw TCP socket to {productId}.apple.{domain}:6000 (and 85.17.70.38:6000) and relays bytes full-duplex between the controller and target hosts, turning the phone into a residential proxy node. The same ad-fraud code appears in 13 apps on Google Play published under at least two developer accounts (fivedev, CPS Developer) with 13 distinct signing certificates; they masquerade as weather, file manager, app locker, OCR/picture-translate and audio editor utilities.
Bitdefender links the operation by shared infrastructure to earlier malware: Android.Joker.310.origin (2021, premium-SMS fraud, shared domain zhuifengzhe.top) and Android.Phantom.5 / Android.Click.429.origin (2025, dropper and click fraud). Because the enabler is platform-signed and lives in the system partition, standard uninstall does not work; removal needs firmware-level cleanup or ADB disabling. No CVE or CVSS applies. Attribution to a named actor is not established.
MITRE ATT&CK techniques used in TL-2026-3066
Defense Evasion
T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1629.003 Impair Defenses: Disable or Modify Tools; T1630.002 Indicator Removal on Host: File Deletion; T1655.001 Masquerading: Match Legitimate Name or Location
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Command and Control
T1437.001 Application Layer Protocol: Web Protocols; T1509 Non-Standard Port; T1521.001 Encrypted Channel: Symmetric Cryptography; T1544 Ingress Tool Transfer
Initial Access
T1474.003 Supply Chain Compromise: Compromise Software Supply Chain
Execution
defense-evasion
Impact
T1643 Generate Traffic from Victim
Exfiltration
Affected products and versions in Midnight Mimosa
- Doogee — S200 X, Fire 3 Max (MediaTek-based Android phones)
Vulnerable versions: Preinstalled firmware builds observed by Bitdefender - Cubot — KINGKONG X (MediaTek-based Android phones)
Vulnerable versions: Preinstalled firmware builds observed by Bitdefender - Various / counterfeit (impersonating Samsung and Apple) — Low-cost MediaTek Android phones branded S24/S25/S26 Ultra, i16/i17 Pro Max, Note 18 Ultra and region-coded ODM builds J10_EEA, A9_EEA, T13_EEA, Q6_EEA
Vulnerable versions: Preinstalled firmware builds observed by Bitdefender
Remediation for Midnight Mimosa
Patches
- No vendor patch identified in the sources; removal requires a firmware-level cleanup (clean reflash) from a trusted source
Immediate actions
- Inventory fleet and BYOD Android devices for com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot, com.android.sys.bcprot and com.android.non.szcz
- Block api.weatherlive.world, oss.showtimetool.com, 85.17.70.38 and the other listed domains at DNS/proxy/firewall, including outbound TCP/6000 from mobile segments
- Quarantine or deny corporate access to affected Doogee, Cubot and counterfeit-branded devices pending remediation
Workarounds
- Disable the malicious packages via ADB (standard uninstall is blocked by system-level privileges)
- Stop using the device for sensitive activity if firmware cannot be replaced
Longer-term hardening
- Procure devices only from vendors with verified firmware supply chains and Play Protect certification
- Use mobile threat defense / app anomaly detection to flag unexpected platform-signed system apps and installer-spoofing
- Add device attestation and compliance checks to MDM access policies
Weaknesses (CWE) in Midnight Mimosa
Timeline of Midnight Mimosa
- Android.Joker.310.origin (premium-SMS fraud) observed sharing the domain zhuifengzhe.top with this operator lineage (year only per Bitdefender)
- MAC OUI A0:53:94 associated with the platform-key certificate holder registered with IEEE
- Bitdefender App Anomaly Detection behavioral monitoring in place since 2023 (year only per Bitdefender)
- Midnight Mimosa preinstalled enabler, ad fraud and proxyware activity begins (2024-2025 window; about two years before disclosure)
- Build tag 20240425 observed in the enabler's nativeInit(), anchoring the start of the roughly two-year campaign window.
- Android.Phantom.5 / Android.Click.429.origin dropper and click-fraud malware share infrastructure with the campaign (year only per Bitdefender)
- Payload path oss.showtimetool.com/ssc/2025/12-07/ observed serving disguised .png modules.
- Payload path oss.showtimetool.com/ssc/2026/03-09/ observed serving disguised .png modules.
- Payload path oss.showtimetool.com/ssc/2026/07-04/ observed serving disguised .png modules.
- Payload path oss.showtimetool.com/ssc/2026/08-13/ observed serving disguised .png modules, the most recent staging date in the published IOCs.
- BleepingComputer reports Bitdefender's findings: Midnight Mimosa in firmware of low-cost Android phones across 150+ countries
Update history for TL-2026-3066
- 2026-10-09 — Midnight Mimosa: Pre-Installed Firmware Malware on Budget MediaTek Android Devices in 150+ Countries: What changed No field escalation: severity HIGH, exploitability ACTIVE, status ACTIVE and attribution (Unattributed, LOW) are unchanged and corroborated by the newer report. New indicators (17) 6 network indicators (2 embedded framework C2
Sources cited for Midnight Mimosa
- Low-cost Android phones ship with residential proxy malware
- The phone was compromised before the user turned it on: the rise of Midnight Mimosa (Bitdefender Labs)
- Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones (Hackread)
- Some cheap Android phones come with malware in their firmware (Android Authority)
- Related: BadBox botnet expands to over 192,000 devices worldwide (Bitdefender)
- Related: Increased Android.BadBox2 malware infection (NG-CERT)
Detection coverage for TL-2026-3066
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3066 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.