Reports say a malware campaign known as “Midnight Mimosa” is being found on certain low-cost Android smartphones with malicious software embedded in the devices’ firmware. Security researchers describe the malware as giving attackers system-level control on affected phones, enabling silent app installation and activities linked to ad fraud. The malware is also said to repurpose infected devices as “residential proxies,” allowing their network traffic to be used for other ends.

Multiple outlets report that the issue is not limited to apps installed by users. Instead, the malicious components are preinstalled or baked into the firmware, meaning devices may be compromised out of the box. While the core description is consistent across coverage, details of specific attack workflows and affected device models are presented at a high level, reflecting differences in how each outlet summarizes the investigation and mitigation guidance.

Overall, the reports highlight a supply-chain compromise affecting budget Android hardware, with risk stemming from the combination of preloaded persistence and attacker control over device behavior after purchase.