Low‑Cost Android Handsets Found Pre‑Installed with Residential Proxy Malware
Security researchers have uncovered a widespread campaign, dubbed "Midnight Mimosa," that embeds malicious code directly into the firmware of inexpensive Android smartphones, effectively turning the devices into covert residential proxies.
The unwanted software is not a downloadable app but part of the phone's core operating system, making it difficult for users to detect or uninstall. Once activated, the code can silently fetch additional applications, manipulate network traffic and generate fraudulent advertising clicks without the owner's knowledge.
According to the analysis, the malware communicates with remote command‑and‑control servers to receive instructions. It can reconfigure the device to act as a proxy, allowing attackers to route web requests through the phone’s IP address, which appears as a legitimate residential connection. This capability is valuable for evading detection in illicit activities such as ad fraud, credential stuffing and other forms of online abuse.
The compromised phones are being sold through popular e‑commerce platforms and third‑party retailers, often marketed as budget‑friendly options for emerging markets. While the exact number of affected units is still being assessed, the researchers estimate that thousands of devices may have left factories with the malicious firmware already embedded.
For consumers, the presence of such software poses significant privacy and security risks. Beyond the potential for unwanted data usage and battery drain, the covert proxy function can implicate owners in illegal online behavior, potentially leading to service bans or legal scrutiny.
Cybersecurity firms have warned manufacturers and distributors to improve supply‑chain vetting and urged users to purchase devices from reputable sources. Some experts recommend performing a full factory reset followed by flashing a clean firmware image, though this process may be beyond the technical comfort zone of most buyers.
The discovery adds to growing concerns about the integrity of low‑cost hardware and highlights the need for stronger regulatory oversight of mobile device manufacturing. Ongoing investigations aim to trace the origin of the malicious code and hold accountable any parties responsible for its distribution.
Comments (0)
Be the first to comment.
Join the discussion