graphic of multiple phones
Image: Yianni Mathioudakis via Unsplash

Thousands of cheap Android phones shipped with ad-fraud malware

Researchers have found malware preinstalled on thousands of cheap Android phones that can generate fraudulent ad revenue and potentially turn infected devices into parts of larger botnets.

The campaign, dubbed Midnight Mimosa by Romania-based cybersecurity firm Bitdefender, affects devices from multiple brands sold worldwide that use chips made by Taiwanese semiconductor company MediaTek.

“The malware ships preinstalled in the device firmware,” Bitdefender said in a report released Thursday. “It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled.”

At the center of the operation is a malicious Android application built into the firmware of affected phones before they are sold. The app runs with system-level privileges, allowing it to silently install or remove other applications, grant them permissions, and download and run additional code without the owner’s approval.

The researchers said the campaign appears primarily designed to make money from infected devices through advertising and click fraud. The malware can also collect information about devices and installed apps and has capabilities that could allow infected phones to be incorporated into botnets.

Over roughly two years, Bitdefender observed the malware on thousands of devices across more than 150 countries. Mexico, France and Italy accounted for the largest shares of detected devices, followed by the United States, Germany, Brazil and Spain.

Many of the affected phones appear to be low-cost, white-label or counterfeit devices, including models designed to resemble better-known Samsung Galaxy phones and Apple iPhones. The researchers said the phones are sold through mainstream online marketplaces, with one device they examined costing about $180.

All about the ads

The preinstalled malware does not generate fraudulent ad views itself. Instead, it secretly installs seemingly legitimate applications disguised as weather, note-taking, app-lock, file-management and other utilities.

Those apps use legitimate advertising services to load real ads but can display them in invisible windows over other applications, registering ad impressions that users never actually see. Some components can also generate automated clicks.

Researchers identified at least 32 disguised applications deployed by the preinstalled malware. Before installing some of those payloads, the malware temporarily disables the Google Play Store, potentially to evade detection, and turns it back on after the installation is complete.

Bitdefender also found 13 apps available through Google Play that communicated with the same infrastructure and contained the same ad-fraud code.

Unlike the preinstalled malware, the Play Store apps do not have powerful system privileges and provide genuine functions, such as weather information or QR-code scanning. But researchers said they could also display ads outside the apps, including when a user was not actively using the phone.

Bitdefender has not determined who placed the malware on the devices or where in the supply chain it was introduced.

Some affected firmware was signed with certificates bearing the name of Shenzhen Zediel, a Chinese company that develops and sells smart hardware and consumer electronics. Bitdefender said the certificates do not establish that the company created the malware, knowingly distributed it or was aware of its presence.

Researchers said the malicious software could have been introduced by an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before the phones were sold.

“The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones,” the researchers said. “One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards.”

Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.