BREACH WATCH BRIEF High 📱 Threat intel

Pre‑installed Residential Proxy Malware Discovered on Low‑Cost Android Phones in 150+ Countries

Researchers identified the 'Midnight Mimosa' campaign embedding system‑level proxy malware in the firmware of inexpensive Android devices, enabling silent app installs and ad fraud. The supply‑chain nature of the infection highlights the need for robust firmware integrity controls and continuous monitoring for audit readiness.

SeverityHigh
Type📱 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Manufacturing & Industrial Low‑cost Android device manufacturers Telecom carriers and resellers End‑user consumers Third-Party Dependency
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

The Midnight Mimosa campaign embeds residential‑proxy malware into the firmware of low‑cost Android smartphones using MediaTek chipsets. The malware runs with system privileges, silently installs apps, conducts ad‑fraud, and can turn devices into proxy nodes. Thousands of devices in over 150 countries were affected over roughly two years.

Why it matters for trust and compliance

  • The incident underscores the importance of supply‑chain risk management and firmware integrity controls—key components of a continuous control‑assurance program that provides defensible evidence of due diligence.
  • Supply‑chain risk assessments become a required evidence point for audit readiness.
  • Continuous monitoring of firmware integrity supplies defensible proof of control effectiveness.

Who is affected

Low‑cost Android device manufacturers Telecom carriers and resellers End‑user consumers

Recommended actions

  1. Validate firmware signatures and enforce secure update processes.
  2. Conduct a supply‑chain risk assessment for OEM firmware practices.
  3. Implement continuous monitoring of device behavior for anomalous traffic.
  4. Document evidence of firmware integrity checks for audit purposes.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.