Cheap copies of iPhone and Galaxy were infected at the factory – the Midnight Mimosa virus takes full control over smartphones Cheap copies of iPhone and Galaxy were infected at the factory – the Midnight Mimosa virus takes full control over smartphones

Cheap copies of iPhone and Galaxy were infected at the factory – the Midnight Mimosa virus takes full control over smartphones

Cybersecurity researchers have discovered a new campaign to distribute the malicious app Midnight Mimosa. It comes pre-installed on inexpensive Chinese smartphones – mostly copies of flagships.

Cheap copies of iPhone and Galaxy were infected at the factory – the Midnight Mimosa virus takes full control over smartphones

Image source: bitdefender.com

The Midnight Mimosa distribution campaign was discovered by experts from the company Bitdefender. The application is built into the device’s firmware, and removing it requires some effort. It was found on products from little-known manufacturers that imitate flagship smartphones. The names of such devices speak for themselves: S24 Ultra, S25 Ultra, S26 Ultra, i17 Pro Max, i16 Pro Max, 17 Pro Max and others. These devices can be classified as niche, but a certain demand for them remains. It is somewhat surprising that the list also includes rugged smartphones Doogee S200 X and Cubot Kingkong X, although they are produced by fairly well-known companies.

The Midnight Mimosa malware was detected directly in the firmware of these devices, meaning it was present in the system even before it was first turned on. It was not possible to find out at what stage of the smartphone’s life cycle the infection occurs. Midnight Mimosa works with system privileges, which allows the malware to secretly install new applications, remove existing ones, grant permissions, and even download code remotely.

Thanks to this, the application remains undetected. Before installing the main malicious payload, Midnight Mimosa disables Google Play, likely to avoid detection by the Google Play Store security system. With this level of access, attackers can do almost anything. The goal of the campaign is presumably to make a profit: hidden advertisements are displayed on infected devices, clicks are cheated, and smartphones are used as proxy nodes as part of a large botnet to carry out DDoS attacks.

Over two years, traces of the campaign were found on several thousand devices in more than 150 countries. The most infected devices were recorded in Mexico, France and Italy, followed by the USA, Germany, Brazil and Spain. There is no easy way to remove the malware. Midnight Mimosa is located in the system partition of the infected smartphone, so its removal requires either intervention at the firmware level or disabling via the ADB (Android Debug Bridge) interface. None of these options are suitable for the average user, so you will have to contact a specialist or purchase a new device.

If you notice an error, select it with the mouse and press CTRL+ENTER.

Leave a Reply

Your email address will not be published. Required fields are marked *