Low-cost Android phones ship with residential proxy malware
Midnight Mimosa malware preinstalled on cheap Android phones enables ad fraud and residential proxy abuse.
Bitdefender reported Midnight Mimosa, malware embedded in the firmware of low-cost Android phones using MediaTek chipsets. Privileged apps masquerading as system packages can silently install software, temporarily disable the Play Store, and download modules from command-and-control servers. Cover apps generate fraudulent ad impressions in hidden windows, and an app-locker component can register phones as residential proxies. Thousands of devices in more than 150 countries were affected over about two years, including Doogee and Cubot models, and 13 Play Store apps shared the fraud code.