Threats · 4h ago
Bitdefender found Midnight Mimosa preinstalled in the firmware of thousands of cheap Android phones from multiple brands, with detections in more than 150 countries. The phones use MediaTek chips, and the malware is on the device before first boot, so the owner starts with an infected system app rather than a clean handset.
The malicious app runs with system privileges, which lets it quietly install other apps, grant permissions, and fetch more code. It then uses fake utility apps and invisible ad windows to generate ad fraud, and Bitdefender says the same infrastructure could also support botnet enrollment.
For anyone buying low-cost, white-label, or counterfeit Android devices, the trust break is in the supply chain: uninstalling apps or scanning the operating system does not remove a component that was baked into firmware. The exposure sits with every handset that shares that device image, plus any downstream fraud or botnet activity it can support.
2 sources covering this story
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
The Record from Recorded Future
Thousands of cheap Android phones shipped with ad-fraud malware
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
Part of the PlainSec briefing for 2026-10-08