Cheap Android Phones Shipped With Ad-Fraud Malware Built Into Their Firmware
Researchers at Romania-based security firm Bitdefender have uncovered a campaign, named Midnight Mimosa, in which malware comes preinstalled on cheap Android phones. The affected devices come from multiple brands and use chips made by Taiwanese company MediaTek. Bitdefender says the malware is built into the phone's firmware, so it is present before the owner first switches the device on and cannot be uninstalled.
The malicious app runs with system-level privileges. This lets it silently install or remove other apps, grant them permissions, and download and run extra code without the owner's approval. It can also collect information about the device and its installed apps, and it has capabilities that could allow phones to be added to botnets. Over roughly two years, Bitdefender saw it on thousands of devices in more than 150 countries, with Mexico, France and Italy making up the largest shares, followed by the United States, Germany, Brazil and Spain.
Many of the phones appear to be low-cost, white-label or counterfeit models, including some designed to look like Samsung Galaxy phones and iPhones. They are sold through mainstream online marketplaces, and one examined device cost about $180. The preinstalled malware does not create fake ad views itself. Instead, it secretly installs apps disguised as weather, note-taking, app-lock and file-management utilities. These apps load real ads through legitimate advertising services but show them in invisible windows over other apps, registering impressions no one sees. Some components can also generate automated clicks.