bleeping-computer · Crawled Oct 9, 2026

Low-cost Android phones ship with residential proxy malware

7 IoCs
Read original article ↗

AI Summary

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones, where malicious software is embedded directly into the firmware of devices using MediaTek chipsets. The malware, which operates with system-level privileges, enables silent app installation, ad fraud via fake utility apps, and turns infected devices into residential proxies. The campaign has affected thousands of devices across over 150 countries, with notable impact in Mexico, France, Italy, and the U.S., and persists through preinstalled system apps that cannot be uninstalled normally.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Package com.android.non.szcz Details →
Package com.android.system.lite Details →
Package com.android.sys.prot Details →
Package com.android.sys.gmsprot Details →
Package com.mobile.applock.en Details →
GitHub User fivedev Details →
GitHub User CPS Developer Details →