{"id":2100,"date":"2026-10-09T07:18:36","date_gmt":"2026-10-09T00:18:36","guid":{"rendered":"https:\/\/vncybers.vn\/ho-so-midnight-mimosa-android-nhiem-ma-doc-truoc-khi-bat-may\/"},"modified":"2026-10-09T07:18:36","modified_gmt":"2026-10-09T00:18:36","slug":"midnight-mimosa-android-phones-infected-before-first-boot","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/ho-so-midnight-mimosa-android-nhiem-ma-doc-truoc-khi-bat-may\/","title":{"rendered":"Midnight Mimosa Profile: Android Phones Infected Before First Boot"},"content":{"rendered":"<p><strong>Midnight Mimosa<\/strong> l\u00e0 chi\u1ebfn d\u1ecbch m\u00e3 \u0111\u1ed9c chu\u1ed7i cung \u1ee9ng \u0111\u01b0\u1ee3c Bitdefender c\u00f4ng b\u1ed1 ng\u00e0y 8\/10\/2026, nh\u1eafm v\u00e0o c\u00e1c \u0111i\u1ec7n tho\u1ea1i Android gi\u00e1 r\u1ebb s\u1eed d\u1ee5ng n\u1ec1n t\u1ea3ng MediaTek. Th\u00e0nh ph\u1ea7n \u0111\u1ed9c h\u1ea1i \u0111\u01b0\u1ee3c c\u00e0i s\u1eb5n trong firmware, ch\u1ea1y v\u1edbi \u0111\u1eb7c quy\u1ec1n h\u1ec7 th\u1ed1ng v\u00e0 c\u00f3 th\u1ec3 \u00e2m th\u1ea7m c\u00e0i \u1ee9ng d\u1ee5ng, gian l\u1eadn qu\u1ea3ng c\u00e1o ho\u1eb7c bi\u1ebfn \u0111i\u1ec7n tho\u1ea1i th\u00e0nh n\u00fat proxy d\u00e2n c\u01b0 tr\u01b0\u1edbc khi ch\u1ee7 s\u1edf h\u1eefu c\u00f3 c\u01a1 h\u1ed9i t\u1ef1 b\u1ea3o v\u1ec7.<\/p>\n<p>Unlike most Android malware that must trick users into downloading an APK or granting permissions, Midnight Mimosa is already present in the system partition when the device is sold. Bitdefender recorded thousands of devices in more than 150 countries over roughly two years, with the most detections in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. The true scale may be larger because the figures cover only devices visible to the company's technology.<\/p>\n<h2>An Infection That Starts Before the Box Is Opened<\/h2>\n<p>Cu\u1ed9c \u0111i\u1ec1u tra b\u1eaft \u0111\u1ea7u khi c\u01a1 ch\u1ebf App Anomaly Detection c\u1ee7a Bitdefender ph\u00e1t hi\u1ec7n g\u00f3i <code>com.android.system.lite<\/code> mang d\u00e1ng v\u1ebb th\u00e0nh ph\u1ea7n Android nh\u01b0ng li\u00ean t\u1ee5c c\u00e0i v\u00e0 g\u1ee1 nh\u1eefng \u1ee9ng d\u1ee5ng kh\u00f4ng li\u00ean quan. G\u00f3i n\u00e0y \u0111\u01b0\u1ee3c k\u00fd b\u1eb1ng ch\u1ee9ng ch\u1ec9 n\u1ec1n t\u1ea3ng, ch\u1ea1y d\u01b0\u1edbi t\u00e0i kho\u1ea3n h\u1ec7 th\u1ed1ng, kh\u00f4ng c\u00f3 bi\u1ec3u t\u01b0\u1ee3ng v\u00e0 kh\u00f4ng th\u1ec3 b\u1ecb g\u1ee1 b\u1eb1ng thao t\u00e1c th\u00f4ng th\u01b0\u1eddng.<\/p>\n<p>C\u00f9ng l\u00f5i m\u00e3 \u0111\u1ed9c c\u00f2n xu\u1ea5t hi\u1ec7n d\u01b0\u1edbi nhi\u1ec1u t\u00ean c\u00f3 v\u1ebb h\u1ee3p l\u1ec7 nh\u01b0 <code>com.android.sys.prot<\/code>, <code>com.android.sys.gmsprot<\/code> and <code>com.android.sys.bcprot<\/code>. Vi\u1ec7c \u0111\u1ed5i t\u00ean, b\u1ea3n d\u1ef1ng v\u00e0 ch\u1ee9ng ch\u1ec9 k\u00fd cho th\u1ea5y t\u00ean g\u00f3i ri\u00eang l\u1ebb kh\u00f4ng ph\u1ea3i ch\u1ec9 d\u1ea5u \u0111\u1ee7 tin c\u1eady; h\u00e0nh vi chung v\u00e0 chu\u1ed7i h\u1ea1 t\u1ea7ng m\u1edbi l\u00e0 y\u1ebfu t\u1ed1 li\u00ean k\u1ebft c\u00e1c m\u1eabu.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/10\/midnight-mimosa-inline.png\" alt=\"Midnight Mimosa payload delivery architecture on Android\" style=\"max-width:100%;height:auto\" \/><figcaption>SystemLite loads plugins and companion apps for ad fraud or proxy services. Source: Bitdefender.<\/figcaption><\/figure>\n<h2>System Privileges Enable Remote Code Loading<\/h2>\n<p>Th\u00e0nh ph\u1ea7n c\u00e0i s\u1eb5n c\u00f3 quy\u1ec1n c\u00e0i, x\u00f3a \u1ee9ng d\u1ee5ng, c\u1ea5p quy\u1ec1n th\u1eddi gian ch\u1ea1y v\u00e0 thay \u0111\u1ed5i thi\u1ebft l\u1eadp b\u1ea3o m\u1eadt m\u00e0 kh\u00f4ng c\u1ea7n t\u01b0\u01a1ng t\u00e1c. Logic nguy hi\u1ec3m \u0111\u01b0\u1ee3c gi\u1ea5u trong th\u01b0 vi\u1ec7n native <code>libeasy.so<\/code>; khi ho\u1ea1t \u0111\u1ed9ng, th\u01b0 vi\u1ec7n gi\u1ea3i m\u00e3 m\u1ed9t framework Java r\u1ed3i l\u1ea5y c\u1ea5u h\u00ecnh t\u1eeb m\u00e1y ch\u1ee7 \u0111i\u1ec1u khi\u1ec3n \u0111\u1ec3 t\u1ea3i c\u00e1c plugin DEX \u1edf giai \u0111o\u1ea1n ti\u1ebfp theo.<\/p>\n<p>Bitdefender identified at least 32 apps disguised as weather tools, app lockers, file managers, OCR utilities, audio editors, or icon customizers. Payloads are installed and removed in rotation, shortening their visibility in the app list, changing file fingerprints, and switching monetization modules while the persistent system component remains in place.<\/p>\n<h2>Disabling the Play Store to Evade Inspection<\/h2>\n<p>Ngay tr\u01b0\u1edbc khi c\u00e0i payload, m\u00e3 \u0111\u1ed9c t\u1ea1m v\u00f4 hi\u1ec7u h\u00f3a g\u00f3i Google Play Store <code>com.android.vending<\/code>, \u0111\u01b0\u1ee3c cho l\u00e0 nh\u1eb1m tr\u00e1nh Play Protect quan s\u00e1t qu\u00e1 tr\u00ecnh c\u00e0i \u0111\u1eb7t. Sau \u0111\u00f3 Play Store \u0111\u01b0\u1ee3c b\u1eadt l\u1ea1i; m\u1ed9t c\u01a1 ch\u1ebf d\u1ef1 ph\u00f2ng c\u0169ng kh\u00f4i ph\u1ee5c \u1ee9ng d\u1ee5ng khi ng\u01b0\u1eddi d\u00f9ng \u0111ang thao t\u00e1c \u0111\u1ec3 h\u1ea1n ch\u1ebf g\u00e2y nghi ng\u1edd.<\/p>\n<p>Some variants also alter installer records to make malicious apps look as though they came from Google Play. Researchers separately found 13 Google Play apps using the same ad-fraud code and communicating with Midnight Mimosa infrastructure. These store apps lack the firmware package's privileges but can still display ads outside their own interfaces.<\/p>\n<h2>From Ad Fraud to Residential Proxies<\/h2>\n<p>The main monetization model uses cover apps to load legitimate ads in invisible windows or automatically generate impressions and clicks. This shifts data, power, and device-wear costs to buyers while distorting the advertising ecosystem.<\/p>\n<p>A payload disguised as an app locker also includes a TCP proxy. After registering a device with a remote server, it can receive instructions to connect to a specified destination and relay traffic through the victim's IP address. Bitdefender confirmed that the control infrastructure still accepted registrations but observed no relay targets during testing, so it could not confirm specific attack traffic passing through test devices.<\/p>\n<p>Residential proxies are valuable to cybercriminals because traffic comes from real consumer connections, is difficult to distinguish from normal activity, and can support fraud, target scanning, or source concealment. The report also notes that Accessibility, Notification Access, and SMS permissions are available for remote activation, although researchers did not observe them being used in this campaign.<\/p>\n<h2>Unanswered Questions in the Supply Chain<\/h2>\n<p>Samples appeared on multiple low-cost devices, including model names associated with the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung or Apple products. Some XDA forum users reported suspicious apps reinstalling themselves after removal; in one case, newer official firmware brought the malware back while restoring an older version made it disappear.<\/p>\n<p>Some firmware was signed with certificates bearing the Shenzhen Zediel name, but Bitdefender stresses that this does not prove the entity participated in or knew about the malware installation. Tampering could have occurred at the device designer, firmware integrator, logistics partner, or another link. Public evidence is not sufficient to assign responsibility to a specific company.<\/p>\n<h2>What Should Users and Organizations Do?<\/h2>\n<ul>\n<li><strong>\u01afu ti\u00ean thi\u1ebft b\u1ecb c\u00f3 cam k\u1ebft c\u1eadp nh\u1eadt r\u00f5 r\u00e0ng:<\/strong> gi\u00e1 mua th\u1ea5p kh\u00f4ng b\u00f9 \u0111\u01b0\u1ee3c r\u1ee7i ro khi firmware kh\u00f4ng minh b\u1ea1ch ho\u1eb7c nh\u00e0 s\u1ea3n xu\u1ea5t thi\u1ebfu k\u00eanh h\u1ed7 tr\u1ee3 b\u1ea3o m\u1eadt.<\/li>\n<li><strong>Ki\u1ec3m tra d\u1ea5u hi\u1ec7u b\u1ea5t th\u01b0\u1eddng:<\/strong> l\u01b0u l\u01b0\u1ee3ng n\u1ec1n, pin hao nhanh, qu\u1ea3ng c\u00e1o ngo\u00e0i \u1ee9ng d\u1ee5ng, Play Store b\u1ecb t\u1eaft ho\u1eb7c \u1ee9ng d\u1ee5ng l\u1ea1 t\u1ef1 xu\u1ea5t hi\u1ec7n l\u00e0 c\u00e1c t\u00edn hi\u1ec7u c\u1ea7n \u0111i\u1ec1u tra.<\/li>\n<li><strong>C\u1eadp nh\u1eadt t\u1eeb ngu\u1ed3n ch\u00ednh th\u1ee9c \u0111\u00e3 \u0111\u01b0\u1ee3c x\u00e1c minh:<\/strong> v\u1edbi model \u0111\u01b0\u1ee3c nh\u00e0 s\u1ea3n xu\u1ea5t x\u00e1c nh\u1eadn c\u00f3 b\u1ea3n v\u00e1, sao l\u01b0u d\u1eef li\u1ec7u r\u1ed3i c\u00e0i firmware s\u1ea1ch. Kh\u00f4i ph\u1ee5c c\u00e0i \u0111\u1eb7t g\u1ed1c c\u00f3 th\u1ec3 kh\u00f4ng hi\u1ec7u qu\u1ea3 n\u1ebfu m\u00e3 \u0111\u1ed9c n\u1eb1m trong ph\u00e2n v\u00f9ng h\u1ec7 th\u1ed1ng.<\/li>\n<li><strong>C\u00e1ch ly thi\u1ebft b\u1ecb nghi nhi\u1ec5m:<\/strong> kh\u00f4ng d\u00f9ng cho ng\u00e2n h\u00e0ng, MFA, email doanh nghi\u1ec7p ho\u1eb7c truy c\u1eadp m\u1ea1ng n\u1ed9i b\u1ed9; \u0111\u1ed5i th\u00f4ng tin \u0111\u0103ng nh\u1eadp t\u1eeb m\u1ed9t thi\u1ebft b\u1ecb tin c\u1eady.<\/li>\n<li><strong>Qu\u1ea3n tr\u1ecb thi\u1ebft b\u1ecb doanh nghi\u1ec7p:<\/strong> d\u00f9ng MDM \u0111\u1ec3 ch\u1eb7n model kh\u00f4ng \u0111\u01b0\u1ee3c ph\u00ea duy\u1ec7t, theo d\u00f5i g\u00f3i h\u1ec7 th\u1ed1ng v\u00e0 ph\u00e1t hi\u1ec7n k\u1ebft n\u1ed1i C2 ho\u1eb7c proxy b\u1ea5t th\u01b0\u1eddng.<\/li>\n<\/ul>\n<p>Technical users may reduce risk by disabling malicious packages through ADB, but this is not a universal remedy and may destabilize the device. A reliable fix requires cleaned firmware, and devices without patches should no longer be used for sensitive activity.<\/p>\n<h2>Lessons from the Midnight Mimosa Profile<\/h2>\n<p>Midnight Mimosa shows that the mobile trust model can fail at the factory: platform signatures and system privileges intended to protect the OS become an operator's advantage when firmware is compromised. Installation-time app scanning is not enough; continuous behavior monitoring and firmware provenance must become part of supply-chain controls.<\/p>\n<p>In the budget-device market, transparency about firmware integrators, signing certificates, update schedules, and vulnerability disclosure channels matters as much as hardware specifications. Buyers and organizations should treat phones with unclear supply chains as untrusted devices, especially when they serve as authentication factors or gateways to work data.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Bitdefender and BleepingComputer<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Midnight Mimosa l\u00e0 chi\u1ebfn d\u1ecbch m\u00e3 \u0111\u1ed9c chu\u1ed7i cung \u1ee9ng \u0111\u01b0\u1ee3c Bitdefender c\u00f4ng b\u1ed1 ng\u00e0y 8\/10\/2026, nh\u1eafm v\u00e0o c\u00e1c \u0111i\u1ec7n tho\u1ea1i Android gi\u00e1 r\u1ebb s\u1eed d\u1ee5ng n\u1ec1n t\u1ea3ng MediaTek. Th\u00e0nh ph\u1ea7n \u0111\u1ed9c h\u1ea1i \u0111\u01b0\u1ee3c c\u00e0i s\u1eb5n trong firmware, ch\u1ea1y v\u1edbi \u0111\u1eb7c quy\u1ec1n h\u1ec7 th\u1ed1ng v\u00e0 c\u00f3 th\u1ec3 \u00e2m th\u1ea7m c\u00e0i \u1ee9ng d\u1ee5ng, gian l\u1eadn qu\u1ea3ng [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2099,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[70],"tags":[929,677,147,927,928,926,930,151],"class_list":["post-2100","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ho-so","tag-ad-fraud","tag-android-malware","tag-bitdefender","tag-firmware-malware","tag-mediatek","tag-midnight-mimosa","tag-mobile-supply-chain","tag-residential-proxy"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2100"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2100\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2099"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}