Bitdefender Uncovers 'Midnight Mimosa' Malware Preinstalled on Low-Cost Android Phones

3 min read
Source: BleepingComputer
Bitdefender Uncovers 'Midnight Mimosa' Malware Preinstalled on Low-Cost Android Phones
Photo: BleepingComputer
TL;DR

Bitdefender researchers identified a widespread malware campaign named 'Midnight Mimosa' that is preinstalled in the firmware of low-cost Android devices. The malware, which runs with system-level privileges, cannot be uninstalled by users and is designed to generate revenue through ad fraud and by turning devices into residential proxies for botnets. The infection affects thousands of devices across over 150 countries, primarily targeting cheap, white-label, or counterfeit phones using MediaTek chipsets.

Key points

  • The malware is embedded directly into the device firmware before sale, granting it system-level privileges to silently install and remove apps.
  • It generates revenue by deploying disguised apps that perform ad fraud and by registering infected devices as residential proxies for botnets.
  • The campaign has affected thousands of devices in over 150 countries, with the highest concentrations in Mexico, France, Italy, the US, Germany, Brazil, and Spain.
  • Removal is difficult for average users, requiring technical interventions like Android Debug Bridge (ADB) or firmware-level cleanup.
  • The malware temporarily disables the Google Play Store to evade detection during the installation of malicious payloads.

Background

This incident follows a trend of compromised hardware entering consumer hands. In August 2026, researchers warned that streaming devices like the SuperBox S7 Pro could be hijacked to form residential proxy networks, similar to the proxy capabilities found in the Midnight Mimosa campaign. Additionally, recent Android malware strains like RatHat and RemControl have exploited accessibility permissions and AI to target banking users, highlighting the ongoing risks of compromised mobile devices and the importance of verifying device authenticity.

How outlets are covering it

Bitdefender, the primary researcher, emphasized the technical depth of the malware, noting its ability to load arbitrary code and its presence in 13 separate Google Play apps. They highlighted the difficulty of removal and the potential for the malware to be used for DDoS attacks. BleepingComputer focused on the supply chain aspect, noting that the malware was found on devices with model names associated with legitimate manufacturers like Doogee and Cubot, as well as counterfeit Samsung and Apple products. The Record from Recorded Future highlighted the financial motivation, noting that the malware is a way to recoup costs on extremely cheap hardware. Cybersecurity Insiders focused on the consumer impact, warning that preinstalled malware is difficult to remove and urging users to purchase from trusted retailers.

Why it matters

This campaign demonstrates a significant shift in malware distribution, moving from user-initiated downloads to preinstalled firmware infections. It highlights the vulnerabilities in the supply chain for low-cost electronics and the difficulty for consumers to detect and remove such threats. The widespread nature of the campaign, affecting devices in over 150 countries, underscores the global scale of the issue and the potential for large-scale botnet operations.

What to watch

Consumers are advised to check for unfamiliar apps on their devices and to install security updates from manufacturers. Bitdefender and other security firms are likely to continue monitoring the campaign and may release tools or guidance for removing the malware. Manufacturers of affected devices may face pressure to address the issue and provide clean firmware updates.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer