News with an accent.

A hand holds a Samsung phone showing a screen of colorful app icons.
Privacy

Mexico tops list of malware preloaded on cheap Android phones

Midnight Mimosa ships in the firmware of phones with MediaTek chips and cannot be removed like an app; Bitdefender saw it on thousands of devices in more than 150 countries.

Bitdefender Labs published a report on Oct. 8 about Midnight Mimosa, malware that, according to the security firm, comes installed in the firmware of low-cost Android phones built on MediaTek processors. It detected the malware on thousands of unique devices in more than 150 countries over about two years. The report says Mexico, France and Italy lead the distribution, followed by the United States, Germany, Brazil and Spain.

Bitdefender does not publish a device total or percentages by country: the breakdown appears in a chart, not in the text. It is therefore not known how many of the affected phones are in Mexico.

Factory-installed malware is not a malicious app. It sits in the firmware and runs with system privileges, so there is no uninstall button. According to the report, it installs and removes apps, grants permissions and runs downloaded code without telling the owner. With decoy apps (weather, app lock, notes, text reader, files) it shows ads in hidden windows to generate ad fraud. BleepingComputer adds that it briefly switches off Google Play Store to dodge Google Play Protect and then turns it back on.

Which models the report names

  • Genuine: the Doogee S200 X and the Cubot KINGKONG X.
  • Lookalikes: devices with names that copy Samsung, Apple and Honor, such as S24, S25 and S26 Ultra, "i17 Pro Max", "Note 18 Ultra" and "Magic 15 MAX".

According to the firm, a model name only hints at possible spoofing and is not a reliable inventory.

Another component turns the phone into a residential proxy, a service that routes other people's traffic through an ordinary user's connection so it appears to come from a home. The command server accepted Bitdefender's test devices, but in the test it sent them no traffic destinations. Active forwarding remains unconfirmed.

Certificates attributed to Shenzhen Zediel Co., Ltd. sign part of the firmware, although Bitdefender says the malware also appears on many devices that do not use that firmware. BleepingComputer notes it is unclear whether that company took part, and how the code entered the supply chain is still unknown.

Cleaning a device requires modifying the firmware or disabling the component with ADB, Android's debugging tool, a procedure BleepingComputer considers hard for most people. Bitdefender argues that remediation cannot depend on uninstalling and that the lasting fix lies with the manufacturers and the stores that sell that firmware.

Two questions remain unanswered: whether Doogee and Cubot sell in Mexico through formal channels, and whether they or Shenzhen Zediel have responded to the report. There is also no published statement from Mexico's Secretaría Anticorrupción y Buen Gobierno, the CRT telecom regulator or the consumer agency Profeco. The whole finding rests on the report of the firm that discovered it.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)