Pre-baked firmware malware targets budget Android devices in 150+ countries
Summary
A new form of pre-baked firmware malware has been detected on budget Android devices across more than 150 countries, highlighting significant security vulnerabilities in the supply chain. This malware often stems from alterations made during the manufacturing or distribution phases, allowing attackers to maintain persistent system-level access to the devices. Once embedded, such threats can withstand attempts at removal, including app uninstallation and certain firmware updates, due to their deep integration within the device's system components.
Analysis
Android: Android is Google's open-source mobile operating system based on the Linux kernel, widely used across smartphones, tablets, and other devices from multiple manufacturers. The platform forms the core environment for the pre-baked firmware malware campaign that embeds malicious components directly into budget devices at the system level. This incident underscores supply chain vulnerabilities affecting Android hardware produced with MediaTek chipsets. Supply Chain Risk: Preinstalled malware campaigns on Android devices often originate from modifications during manufacturing or distribution stages, granting attackers persistent system-level access. Malware Persistence: Firmware-embedded threats on Android devices can evade removal attempts, including app uninstallation and certain firmware updates, due to deep integration as system components.
Categories
tech
Related sources
- https://mediasat.info/en/2026/10/09/malware-found-preinstalled-on-thousands-of-cheap-android-phones/
- https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
- https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/
- https://www.webpronews.com/midnight-mimosa-preinstalled-malware-turns-budget-android-phones-into-silent-profit-engines/
- https://hackread.com/midnight-mimosa-malware-preinstalled-android-phones/
- https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins
- https://gbhackers.com/gemini-powered-malware/
- https://androidworld.nl/nieuws/deze-goedkope-android-telefoons-hebben-malware-uit-de-doos/
- https://cybersecuritynews.com/category/android/