Bitdefender researchers have uncovered an Android malware campaign dubbed Midnight Mimosa, involving malicious software baked into the firmware of low-cost handsets from multiple brands that share the MediaTek platform. The campaign has been observed across roughly 150 countries. Unlike ordinary mobile malware, this one cannot be removed by the user — or even by a factory reset.
A payload the user never installed
According to the research, the malware arrives on the device's system partition before the first boot ever takes place. It combines its firmware-level foothold with device-administrator privileges, a pairing that lets it resist uninstall attempts, survive a factory reset, and operate largely outside the reach of user-space antivirus tools.
Once active, the code carries out click fraud on advertisements, silently drops additional applications onto the device, and enrols the handset into a proxy botnet — effectively renting out the victim's connection and processing power.
The failure is upstream of the user
Security researchers have long framed mobile malware as a hygiene problem: don't sideload, don't grant permissions, keep the OS updated. Midnight Mimosa breaks that framing. The user did nothing wrong; the device was never trustworthy to begin with. No amount of caution at the app layer can compensate for a system image that was compromised before it left the factory.
The economics help explain why the campaign spans so many geographies. Budget hardware operates on margins too thin to fund meaningful supply-chain auditing, which makes preinstallation a low-effort, high-yield model for attackers — and explains why several brands shipping MediaTek-based devices are affected without any single vendor's name dominating the story. Bitdefender describes the malware as platform-linked rather than brand-specific.
A blind spot for BYOD and MDM
For IT teams operating bring-your-own-device programmes, the case exposes a structural gap in mobile device management. MDM solutions verify what they can observe from the OS layer — app inventories, encryption status, OS patch level, screen-lock policy. All of those checks run on top of a firmware layer whose integrity MDM generally assumes rather than verifies. A device that passes every compliance check can still be a botnet node.
The practical mitigations therefore sit further up the stack and further down the supply chain: strict approved-device lists, hardware-backed Android Key Attestation checks to confirm the boot chain, and network-level inspection for the traffic patterns associated with proxy botnets.
Relevance for Hong Kong IT teams
As a general observation, Hong Kong's dense second-hand and grey-market handset trade — plus the prevalence of budget imports across the region — means supply-chain-tainted devices plausibly circulate here regardless of where the original sale occurred. Any organisation relying on employee-owned devices without attestation checks should treat this campaign as a reason to revisit procurement and enrolment policy. No regulator has, as of this writing, issued guidance specific to Midnight Mimosa.
This article is based on Bitdefender research summarised by Security Affairs; the original findings predate this publication date.
Bitdefender研究人員揭露了一個名為 Midnight Mimosa 的Android惡意軟件攻擊行動。惡意軟件被預先嵌入多個採用 MediaTek 平台的廉價品牌手機固件之中,目前已在全球約150個國家被觀測到。與一般流動惡意軟件不同,用戶無法將其移除——即使執行出廠重設(factory reset)亦無法清除。
用戶從未安裝的 payload
根據研究報告,惡意軟件在裝置首次開機啟動之前,便已存在於系統分區(system partition)之中。它將固件層級的據點與 device administrator 權限結合運用,令其得以抵禦卸載嘖試、在出廠重設後存活,並在很大程度上繞過用戶空間(user-space)防毒工具的偵測範圍。
惡意代碼啟動後,會針對廣告進行 click fraud(點擊詐騙),在裝置上靜默安裝額外應用程式,並把手機加入 proxy botnet—— effectively 將受害者的網絡連線及處理器運算力出租牟利。
問題根源不在用戶
流動惡意軟件長期以來被視為衛生習慣問題:不要 sideload 未經授權的應用、不要濫批權限、保持操作系統更新。Midnight Mimosa 徹底打破了這個框架。用戶並無任何過失;問題在於裝置從一開始就不可信。無論用戶在應用層面多麼小心,亦無法補救一個在離開出廠前已被入侵的 system image。
市場經濟結構有助解釋為何此攻擊行動遍布如此多個地區。廉價硬件的利潤微薄,根本不足以支撐有意義的供應鏈審計,使得預裝惡意軟件成為攻擊者成本低、回報高的模式——這也解釋了為何多個採用 MediaTek 平台設備的品牌同時受影響,而事件中沒有任何單一供應商佔據主導。Bitdefender 將此惡意軟件描述為與平台相關,而非針對特定品牌。
BYOD 與 MDM 的盲點
對於實行 bring-your-own-device(BYOD)計劃的 IT 團隊而言,此事暴露了流動設備管理(Mobile Device Management,MDM)的結構性漏洞。MDM 方案只能驗證其從 OS 層觀察得到的項目——應用程式清單、加密狀態、OS patch level、屏幕鎖定政策。然而所有這些檢查均運行於固件層之上,而 MDM 通常對固件層的完整性只是假設,而非實際驗證。一部通過所有合規檢查的裝置,仍然可能成為 botnet 節點。
因此,實際的緩解措施須在技術堆疊更上層及供應鏈更下游着手:實施嚴格的 approved-device list(核准設備名單)、以 hardware-backed Android Key Attestation 檢查確認 boot chain 完整性,以及在網絡層檢查與 proxy botnet 相關的流量模式。
對香港 IT 團隊的啟示
作為一項一般觀察,香港密集的二手及水貨手機市場,加上區內廉價進口手機盛行,意味着受供應鏈污染的裝置不論最初在哪裡售出,都有可能在本地流通。任何依賴員工自攜設備(BYOD)而沒有實施 attestation 檢查的機構,都應將此攻擊行動視為重新檢視採購及登記政策的契機。截至本文撰寫時,尚未有任何監管機構就 Midnight Mimosa 發出特定指引。
本文根據 Security Affairs 整理的 Bitdefender 研究報告撰寫;原始研究結果的發布日期早於本文刊發日期。
