LIVE · cybersecurity feed
Live wire
malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

ZeroDay News ·

Source: HackRead

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

The Midnight Mimosa malware is reported to be present in the device's firmware, meaning it is deeply integrated into the operating system and persists across factory resets. This level of embedding makes it particularly difficult for end-users to detect or remove. Malware preinstalled in this manner can typically achieve high levels of privilege on the device, potentially allowing it to bypass standard Android security mechanisms. This could enable a range of malicious activities, from data exfiltration to remote control of the device.

The affected devices are described as "low-cost Android phones." This category often includes devices manufactured by a wide array of original equipment manufacturers (OEMs), sometimes for regional markets or as unbranded options. The supply chains for these types of devices can be complex and less transparent than those for premium brands, potentially creating opportunities for malicious actors to inject malware at various stages, such as during manufacturing, assembly, or distribution.

The mechanism of infection, being preinstallation, implies a compromise at an earlier stage of the device's lifecycle. This could occur if the firmware image itself is tampered with before being flashed onto the device, or if an insider at a manufacturing or distribution facility intentionally installs the malicious software. Such attacks are challenging to defend against from an end-user perspective, as the compromise exists before the user has any opportunity to secure the device.

Typical mitigation advice for consumers facing preinstalled malware is often limited. Users are generally advised to purchase devices from reputable vendors and authorized retailers. For devices already suspected of being compromised, a factory reset is often the first step, but in cases of firmware-level malware, this may not be sufficient. Advanced users might consider flashing a clean, verified firmware image if one is available and compatible, though this carries its own risks and is not feasible for all users.

The discovery of Midnight Mimosa highlights a persistent and evolving threat in the mobile device ecosystem: supply chain attacks. This class of attack underscores the importance of security throughout the entire lifecycle of a product, from design and manufacturing to distribution and end-of-life. As devices become increasingly integral to daily life, the integrity of their foundational software remains a critical concern for both consumers and the broader cybersecurity community.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

vulnerability

Chasing AMMYY at Splunk .conf

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network…

breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

cloud

Admin in the Loop: Firewalls and the Agentic SOC

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…