Minacce · 4 ore fa
Bitdefender ha trovato Midnight Mimosa su migliaia di Android basati su MediaTek, venduti già infettati e attivi prima del primo avvio. La compromissione non arriva dopo l’acquisto: è già dentro l’immagine del dispositivo, e questo rende inutile trattarla come un semplice problema di app o di configurazione.
Il malware gira con privilegi di sistema. Può installare altre app, concedere permessi, mostrare ads in finestre invisibili e, in alcuni casi, preparare il terreno per botnet e frodi pubblicitarie. La pulizia normale del telefono non rimuove il punto di persistenza, perché il problema sta sotto il livello dell’utente, nel firmware.
Per chi compra telefoni low-cost, white-label o contraffatti, la fiducia nel device non può fermarsi al boot. Se la supply chain è già compromessa, il rischio non resta sul singolo handset: si estende alla flotta, alla frode e all’eventuale abuso coordinato dei dispositivi.
2 fonti che coprono questa storia
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
The Record from Recorded Future
Thousands of cheap Android phones shipped with ad-fraud malware
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
Part of the PlainSec briefing for 2026-10-08