Security researchers have identified a malware campaign, dubbed Midnight Mimosa, affecting low-cost Android smartphones. The malicious code is embedded in the device firmware, meaning it is present from the moment the phone is powered on.
The malware gives attackers the ability to silently install additional apps, commit ad fraud, and turn the device into a residential proxy. That proxy capability is particularly concerning because it lets criminal traffic appear to originate from ordinary home networks, making it harder to block.
Because the malware lives in firmware, it is difficult to remove with standard factory resets. Buyers of budget Android devices should be aware that the supply chain can be a vector for preinstalled threats.