Low-cost Android phones ship with residential proxy malware
Summary
A malware campaign named 'Midnight Mimosa' has been found pre-installed on low-cost Android phones. This malware allows attackers to install apps, conduct ad fraud, and transform the devices into residential proxies.
IFF Assessment
FOE
This campaign poses a significant risk to users by allowing unauthorized app installations, enabling ad fraud, and compromising device privacy and security by turning them into proxies for malicious activities.
Defender Context
This incident highlights the risks associated with low-cost devices and the potential for pre-installed malware. Defenders should be aware of the potential for compromised firmware and advise users to exercise caution when purchasing and setting up new, inexpensive devices, especially from less reputable manufacturers.