$ techbeacon▋
Malware

Low‑Cost Android Handsets Discovered Preloaded with Midnight Mimosa Malware

Low‑Cost Android Handsets Discovered Preloaded with Midnight Mimosa Malware

Security researchers have identified a new wave of preinstalled malicious code, dubbed "Midnight Mimosa," on inexpensive Android smartphones that reach consumers with the malware already embedded in the device firmware.

The discovery, first reported by the cybersecurity outlet Hackread, shows that the threat is not limited to apps downloaded after purchase; instead, the malicious payload resides in the low‑level software that runs before the operating system boots. Once the phone is turned on, the hidden code can silently connect to remote command‑and‑control servers, harvest personal data, and potentially install additional unwanted programs.

Analysts say the affected devices are typically sold through online marketplaces and discount retailers, where price is a primary selling point and quality control may be lax. The phones often lack the branding of major manufacturers, making it harder for buyers to verify the provenance of the hardware. In many cases, the firmware is signed by a third‑party vendor that appears to have been compromised or is deliberately distributing compromised images.

Midnight Mimosa is not the first instance of supply‑chain malware targeting Android, but its presence on budget phones raises concerns about a broader ecosystem of low‑cost devices being used as vectors for espionage or financial fraud. Experts warn that users who purchase cheap smartphones without verifying the source may unwittingly expose themselves to data theft, unauthorized surveillance, or ransomware attacks.

Authorities and industry groups are urging consumers to buy from reputable sellers, check for official software updates, and run security scans before activating a new device. Meanwhile, manufacturers are being called upon to improve firmware signing practices and to implement stricter vetting of component suppliers. The ongoing investigation may lead to broader regulatory scrutiny of the global supply chain for mobile hardware, especially as demand for affordable smartphones continues to grow in emerging markets.

Source: Hackread
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related