# Midnight Mimosa: Low-cost MediaTek Android phones ship with firmware-level ad-fraud and residential proxy malware

> Bitdefender found the Midnight Mimosa malware preinstalled in the firmware of low-cost MediaTek-based Android phones (e.g. Doogee S200 X, Cubot KINGKONG X, and counterfeit Samsung/Apple-branded devices). A platform-signed system app silently installs and removes apps, loads remote code, commits ad fraud and enrolls devices as residential proxy nodes; activity spans about two years and 150+ countries with no attribution.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T10:39:24.548Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3066
- **ID:** TL-2026-3066
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 47 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Bitdefender Labs (reported by BleepingComputer on 2026-10-08) describes Midnight Mimosa as a malware framework present in the system partition of low-cost Android phones before the user first powers them on. Affected devices are built on MediaTek platforms (board k62v1_64_bsp / MT6762 observed) and include genuine budget brands (Doogee S200 X, Doogee Fire 3 Max, Cubot KINGKONG X), region-coded ODM builds (J10_EEA, A9_EEA, T13_EEA, Q6_EEA) and counterfeit flagship-named devices (S24/S25/S26 Ultra, i16/i17 Pro Max, Note 18 Ultra). Bitdefender's App Anomaly Detection flagged a suspicious system application; the campaign was observed on thousands of devices across 150+ countries over roughly two years, with Mexico, France, Italy, the United States, Germany, Brazil and Spain the most affected.

The enabler is a system app (com.android.system.lite, versionCode 900000, plus variants com.android.sys.prot, com.android.sys.gmsprot, com.android.sys.bcprot and, per BleepingComputer, com.android.non.szcz) signed with a platform key whose certificate is associated with Shenzhen Zediel Co., Ltd. (DN CN=ZED, O=ZED, L=ShenZhen, C=CN). Researchers stress this does not establish that the firmware vendor knowingly distributed the malware. The enabler runs as the system user and holds INSTALL_PACKAGES, DELETE_PACKAGES, GRANT_RUNTIME_PERMISSIONS, WRITE_SECURE_SETTINGS and MOUNT_UNMOUNT_FILESYSTEMS. Before installing payloads it runs 'pm disable com.android.vending' and re-enables Play afterwards, and it sets the installer package to com.android.vending without Play's frosting signature block to fake Google Play provenance. Manifest-declared capabilities also include Accessibility Service, Notification Access and SMS read/write.

A native library, libeasy.so, RC4-decrypts (key 'rc4@sec.com') the dropped framework cn.kw.lib.hex. Strings are protected with AES-128-CFB (keys derived as MD5 of fixed base64-looking constants). The framework contacts api.weatherlive.world (module config via /br_upgrade/upgradeV2/getConfigs, telemetry via /odborwer_dot/cm) and downloads modules from oss.showtimetool.com disguised as .png files. Stage-3 plugins include 'wz' (com.wz.sdk.DxFactory, ad fraud: fake impressions and clicks driven by a RemoteConfig object with silentPercent, notClickPercent, notClickInterval and tap-placement rate parameters, with auto-conversion reports after 60 seconds), 'earn' (com.earnsdk.lib.DxFactory, silent installation) and 'gogo' (com.gogo.third.lib.DxFactory, silent installer with WebView).

The proxyware component is the dropped app com.mobile.applock.en (EnLoaderLib v1.0.6). It registers a device UUID and fingerprint (Model#Release#SDK_INT#Build.ID#Brand), opens a raw TCP socket to {productId}.apple.{domain}:6000 (and 85.17.70.38:6000) and relays bytes full-duplex between the controller and target hosts, turning the phone into a residential proxy node. The same ad-fraud code appears in 13 apps on Google Play published under at least two developer accounts (fivedev, CPS Developer) with 13 distinct signing certificates; they masquerade as weather, file manager, app locker, OCR/picture-translate and audio editor utilities.

Bitdefender links the operation by shared infrastructure to earlier malware: Android.Joker.310.origin (2021, premium-SMS fraud, shared domain zhuifengzhe.top) and Android.Phantom.5 / Android.Click.429.origin (2025, dropper and click fraud). Because the enabler is platform-signed and lives in the system partition, standard uninstall does not work; removal needs firmware-level cleanup or ADB disabling. No CVE or CVSS applies. Attribution to a named actor is not established.

## MITRE ATT&CK

- T1474.003 Supply Chain Compromise: Compromise Software Supply Chain
- T1575 Native API
- T1655.001 Masquerading: Match Legitimate Name or Location
- T1629.003 Impair Defenses: Disable or Modify Tools
- T1406 Obfuscated Files or Information
- T1544 Ingress Tool Transfer
- T1604 Proxy Through Victim
- T1643 Generate Traffic from Victim
- T1407 Download New Code at Runtime
- T1630.002 Indicator Removal on Host: File Deletion
- T1418 Software Discovery
- T1426 System Information Discovery
- T1437.001 Application Layer Protocol: Web Protocols
- T1521.001 Encrypted Channel: Symmetric Cryptography
- T1509 Non-Standard Port
- T1646 Exfiltration Over C2 Channel

## Sources

- [Low-cost Android phones ship with residential proxy malware](https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/)
- [The phone was compromised before the user turned it on: the rise of Midnight Mimosa (Bitdefender Labs)](https://www.bitdefender.com/en-us/blog/labs/midnight-mimosa-malware)
- [Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones (Hackread)](https://hackread.com/midnight-mimosa-malware-preinstalled-android-phones/)
- [Some cheap Android phones come with malware in their firmware (Android Authority)](https://www.androidauthority.com/midnight-mimosa-malware-android-phones-3720493/)
- [Related: BadBox botnet expands to over 192,000 devices worldwide (Bitdefender)](https://bitdefender.in/badbox-botnet-expands-to-over-192000-devices-worldwide)
- [Related: Increased Android.BadBox2 malware infection (NG-CERT)](https://cert.gov.ng/advisories/increased-androidbadbox2-malware-infection)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3066
