Thirteen Google Play apps tied to Midnight Mimosa, malware researchers found preinstalled on knockoff Android phones, were still available Thursday on Google Play, according to Bitdefender, which published research on the phones the same day.
The apps carry the same ad-fraud code also delivered by malware baked into the firmware of knockoff phones. Those phones carry model names such as “i17 Pro Max,” “i16_Pro_Max,” “S25 Ultra” and “S24 Ultra,” imitating flagship handsets from Apple and Samsung.
Bitdefender found Midnight Mimosa on more than 10,000 phones. “None are real Samsung, Motorola or Google phones,” said Silviu Stahie, a security analyst at Bitdefender.
Explore This Story: Table of Contents
Bitdefender reports that the infected phones double as residential proxies, letting paying customers route traffic through unsuspecting owners’ connections. Security Point Break went further. The four domains that control Midnight Mimosa’s proxy component match domains Google tied to IPIDEA, which it called the world’s largest residential proxy network.
Down the Rabbit Hole
In January, Google’s Threat Intelligence Group reported that it took legal action to take down the domains IPIDEA used to control infected devices. It appears to have worked. Verisign registration records reviewed by Security Point Break show three of those domains have pointed to sinkholes run by the nonprofit Shadowserver Foundation since Feb. 21, and the fourth resolves through the same servers. The phones still call home, and only the sinkhole answers.
A sinkhole is a server that takes over a criminal domain, logs each infected device that checks in and sends back no instructions. It’s a partial win for defenders. The domains are hard-coded into firmware owners can’t remove, so the phones will keep calling for as long as they’re in use. The sinkhole neutralizes the proxy threat. The ad fraud runs on different servers, and it continues.
What’s Still Running
Bitdefender’s report outlines a more troubling find. The same ad-fraud code isn’t confined to knockoff phones. It’s also on Google Play.
The Play apps lack the baked-in system access of their firmware cousins, but Bitdefender calls them “dangerous nonetheless.” They push ads outside the app even when the phone sits idle, and they report to the same servers that control the malware, giving the operators a line into phones that never ran the firmware.
On the knockoff phones, the same code goes further, according to Bitdefender. It draws ads in invisible windows over other apps, hides them from screenshots, fakes taps and pulls new code from the operators on demand.
The point is to rip off advertisers. Advertisers pay each time an ad is shown or clicked. The malware makes sure both happen with no one watching: the ad loads in a window the owner can’t see, a fake tap registers the click, and the ad network pays the app that hosts the ad. Those are the cover apps the malware installs, and the operators collect. Advertisers are billed for ads no person ever saw.
They aren’t sideloaded fakes. Bitdefender says they are genuine Play builds that passed Google’s review, signed with 13 different certificates.
Still Available, 1.4 Million Downloads Later
All 13 were still available at 3:30 p.m. ET Thursday, according to their store listings. Each of the apps total download ranges add up to more than 1.4 million. App names, according to Bitdefender, are: Daily Weather, Lock & Hide, App Icon DIY, QuickText Extractor and Audify. Daily Weather alone lists more than 1 million.
Bitdefender said it notified Google, which is investigating. Google did not respond to a request for comment by publication time.
Five of the Play apps share package names with apps the malware silently installs on infected phones, a match Security Point Break found by cross-checking Bitdefender’s lists. On the phones, the malware can hand those apps privileges no store app can get. Bitdefender found the phone-installed copy of Daily Weather using one. On Google Play, they’re ordinary downloads.
SPB Exclusive: What Bitdefender’s Report Doesn’t Say
Bitdefender’s report lists the four domains that control the phones’ proxy app. It doesn’t say who they belong to.

Security Point Break compared them against Google’s January report on IPIDEA. All four appear there as command-and-control for EarnSDK, the toolkit Google says IPIDEA’s operators use to pay developers who turn devices into proxy exits. The overlap runs deeper than the domains. Bitdefender’s proxy installer is named “earn” and built on a code library called com.earnsdk.lib. The device fingerprint it sends home uses the same “#*#”-separated format as the EarnSDK sample in Google’s report.
The evidence points to the malware’s operators selling infected phones’ bandwidth into IPIDEA. It does not show IPIDEA built the malware. Bitdefender ties the malware itself to an operator whose lineage it traces, through Dr.Web research, to the Joker malware family in 2021.
Why this matters: Bitdefender’s report documents the phones’ proxy software but not who was buying the bandwidth. Matching its indicators to Google’s report answers that: IPIDEA, a network Google says more than 550 threat groups used in a single week, including groups from China, North Korea, Iran and Russia.

It also shows Google’s January action reached a supply line built into phone firmware, something neither company’s report says. The sinkhole also gives defenders a free tripwire. The criminals can no longer use the four domains, but infected phones still call them. Search your network’s DNS logs for them; any device that shows up is almost certainly infected.
SPB Exclusive: Registered in the Same Second, Sinkholed the Same Day
Verisign registration records show the three .com domains were registered in the same second on June 6, 2025, a batch registration consistent with a single operator. On Feb. 21, 2026, three weeks after Google’s report, all three moved to the Registrar of Last Resort Foundation, which holds domains taken from criminal operations, with Shadowserver sinkhole nameservers. The .in domain, v46wd6uramzkmeeo[.]in, resolves through the same sinkhole servers.
Bitdefender’s report describes the proxy server at 85.17.70.38 as live and accepting new devices. Security Point Break’s DNS lookups Thursday found that address in the server pool answering for Shadowserver’s sinkhole. In Bitdefender’s own test, the device enrolled and received no instructions, which is consistent with a sinkhole. Bitdefender said its research team, based in Romania, will say on Friday when the test ran.
The operators don’t appear to have moved. The newest proxy plugin Bitdefender documented is dated December 2025, two months before the sinkhole.
SPB Exclusive: Six Developer Accounts, Not Two
Bitdefender’s report says the 13 Play apps were published under “at least two” developer accounts. Their store listings show six: cps, fivedev, ailin, lissa, InfinityApps Production and ATS Agro Tecnosul Seguranca. One app, QR Pocket, was updated Sept. 28, 10 days before Bitdefender published.
Not a New Playbook
Midnight Mimosa is the latest entry in a crowded market. In January, Google said it saw more than 550 threat groups, including groups from China, North Korea, Iran and Russia, use IPIDEA exit nodes in a single week to mask password-spraying and break-ins. Google called the residential proxy business a “gray market” that thrives on deception.
Kaspersky has traced the supply side all year. In February it found the Keenadu backdoor built into tablet firmware during manufacturing and tied it to the BADBOX, Triada and Vo1d botnets. In August it found a BADBOX-linked proxy botnet spreading through the update software in Android car head units. Kaspersky calls preinstalled malware “a distinct market with significant competition.”
[SPB LINKS: Your Doorbell Is Somebody Else’s Cybercrime Tool; Your Employee’s Side Hustle Could Be Your New Attack Surface]
For Defenders
- Check the signature, not the install source. Bitdefender says the malware labels sideloaded apps as coming from Google Play. A missing Google signature exposes the fake.
- Block api.weatherlive[.]world, the malware’s ad-fraud control server.
- Replace infected phones rather than trying to clean them. The malware can’t be uninstalled, and Bitdefender says removal takes a firmware fix or disabling the app over ADB.