← Blog · · df00tech

Low-Cost Android Phones Found Shipping With Pre-Installed Residential Proxy Malware

security-news campaign

What Happened

BleepingComputer reports a malware campaign dubbed "Midnight Mimosa" has been found on low-cost Android smartphones that ship with malicious software embedded directly in the device firmware. According to the report, the pre-installed malware allows attackers to silently install additional apps, conduct ad fraud, and turn infected devices into nodes in a residential proxy network.

Why It Matters

Firmware-level implants are harder to detect and remediate than app-layer malware — a factory reset may not remove them, since the malicious code lives below the user-installable app layer. Budget Android devices are widely deployed in cost-sensitive consumer and BYOD environments, so organizations with lax device-provisioning controls could unknowingly introduce compromised hardware onto networks. Devices repurposed as residential proxies can be used to mask the origin of credential stuffing, fraud, or other malicious traffic — potentially implicating the device owner's IP and network in abuse they didn't knowingly participate in.

What Defenders Should Watch For

  • Unexpected or persistent outbound connections to unfamiliar proxy/C2 infrastructure from mobile devices, especially low-cost or off-brand Android handsets.
  • Devices silently installing or updating apps without user-initiated Play Store activity.
  • Anomalous device-as-proxy traffic patterns (e.g., a mobile endpoint relaying traffic for sessions/destinations unrelated to its normal user behavior).
  • For BYOD/mobile fleets: inventory device makes/models against known-affected hardware as details emerge, and consider mobile threat defense (MTD) tooling capable of detecting firmware-level anomalies rather than relying solely on app-permission review.
  • Procurement hygiene: avoid unmanaged, ultra-low-cost Android devices for any use case touching corporate networks or sensitive accounts until more is known about the affected supply chain.

Developing Story

This is a net-new intelligence item still developing — specifics such as affected device manufacturers, scope of distribution, and full indicators of compromise were not detailed in the initial reporting available to us. We will continue monitoring for updates. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.