Thousands of cheap Android phones shipped with ad-fraud malware
Bitdefender found ad-fraud malware preinstalled in the firmware of thousands of cheap MediaTek-based Android phones sold across more than 150 countries.
Bitdefender's campaign, dubbed Midnight Mimosa, involves ad-fraud malware preinstalled in the firmware of thousands of low-cost, often white-label or counterfeit MediaTek-based Android phones sold through mainstream online marketplaces. The system-level app cannot be uninstalled, silently installs or removes applications, grants permissions, and downloads additional code. It deploys at least 32 disguised utility apps that generate fraudulent ad impressions via invisible windows and automated clicks, and 13 related apps were found on Google Play. Detections span more than 150 countries over roughly two years, led by Mexico, France and Italy; attribution remains unknown, though some firmware was signed with Shenzhen Zediel certificates.
- Malware ships preinstalled in firmware with system privileges and cannot be uninstalled
- Silently installs 32+ disguised utility apps committing ad fraud via invisible windows and automated clicks
- Temporarily disables Google Play Store during payload installation to evade detection
- Observed over two years across 150+ countries; Mexico, France and Italy lead detections
- Attribution unclear; some firmware signed with Shenzhen Zediel certificates
Full article627 words · extracted from therecord.media · click to collapse
Researchers have found malware preinstalled on thousands of cheap Android phones that can generate fraudulent ad revenue and potentially turn infected devices into parts of larger botnets. The campaign, dubbed Midnight Mimosa by Romania-based cybersecurity firm Bitdefender, affects devices from multiple brands sold worldwide that use chips made by Taiwanese semiconductor company MediaTek. “The malware ships preinstalled in the device firmware,” Bitdefender said in a report released Thursday. “It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.” At the center of the operation is a malicious Android application built into the firmware of affected phones before they are sold. The app runs with system-level privileges, allowing it to silently install or remove other applications, grant them permissions, and download and run additional code without the owner’s approval. The researchers said the campaign appears primarily designed to make money from infected devices through advertising and click fraud. The malware can also collect information about devices and installed apps and has capabilities that could allow infected phones to be incorporated into botnets. Over roughly two years, Bitdefender observed the malware on thousands of devices across more than 150 countries. Mexico, France and Italy accounted for the largest shares of detected devices, followed by the United States, Germany, Brazil and Spain. Many of the affected phones appear to be low-cost, white-label or counterfeit devices, including models designed to resemble better-known Samsung Galaxy phones and Apple iPhones. The researchers said the phones are sold through mainstream online marketplaces, with one device they examined costing about $180. The preinstalled malware does not generate fraudulent ad views itself. Instead, it secretly installs seemingly legitimate applications disguised as weather, note-taking, app-lock, file-management and other utilities. Those apps use legitimate advertising services to load real ads but can display them in invisible windows over other applications, registering ad impressions that users never actually see. Some components can also generate automated clicks. Researchers identified at least 32 disguised applications deployed by the preinstalled malware. Before installing some of those payloads, the malware temporarily disables the Google Play Store, potentially to evade detection, and turns it back on after the installation is complete. Bitdefender also found 13 apps available through Google Play that communicated with the same infrastructure and contained the same ad-fraud code. Unlike the preinstalled malware, the Play Store apps do not have powerful system privileges and provide genuine functions, such as weather information or QR-code scanning. But researchers said they could also display ads outside the apps, including when a user was not actively using the phone. Bitdefender has not determined who placed the malware on the devices or where in the supply chain it was introduced. Some affected firmware was signed with certificates bearing the name of Shenzhen Zediel, a Chinese company that develops and sells smart hardware and consumer electronics. Bitdefender said the certificates do not establish that the company created the malware, knowingly distributed it or was aware of its presence. Researchers said the malicious software could have been introduced by an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before the phones were sold. “The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones,” the researchers said. “One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards.” All about the ads
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.