Pre‑installed Residential Proxy Malware Discovered on Low‑Cost Android Phones in 150+ Countries
Researchers identified the 'Midnight Mimosa' campaign embedding system‑level proxy malware in the firmware of inexpensive Android devices, enabling silent app installs and ad fraud. The supply‑chain nature of the infection highlights the need for robust firmware integrity controls and continuous monitoring for audit readiness.
ADTP Breach Watch· October 8, 2026· BleepingComputer
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.
What happened
The Midnight Mimosa campaign embeds residential‑proxy malware into the firmware of low‑cost Android smartphones using MediaTek chipsets. The malware runs with system privileges, silently installs apps, conducts ad‑fraud, and can turn devices into proxy nodes. Thousands of devices in over 150 countries were affected over roughly two years.
Why it matters for trust and compliance
The incident underscores the importance of supply‑chain risk management and firmware integrity controls—key components of a continuous control‑assurance program that provides defensible evidence of due diligence.
Supply‑chain risk assessments become a required evidence point for audit readiness.
Continuous monitoring of firmware integrity supplies defensible proof of control effectiveness.
Who is affected
Low‑cost Android device manufacturersTelecom carriers and resellersEnd‑user consumers
Recommended actions
Validate firmware signatures and enforce secure update processes.
Conduct a supply‑chain risk assessment for OEM firmware practices.
Implement continuous monitoring of device behavior for anomalous traffic.
Document evidence of firmware integrity checks for audit purposes.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.