Threats · 4h ago

Midnight Mimosa shipped inside cheap Android phones

Bitdefender found Midnight Mimosa preinstalled in the firmware of thousands of cheap Android phones from multiple brands, with detections in more than 150 countries. The phones use MediaTek chips, and the malware is on the device before first boot, so the owner starts with an infected system app rather than a clean handset.

The malicious app runs with system privileges, which lets it quietly install other apps, grant permissions, and fetch more code. It then uses fake utility apps and invisible ad windows to generate ad fraud, and Bitdefender says the same infrastructure could also support botnet enrollment.

For anyone buying low-cost, white-label, or counterfeit Android devices, the trust break is in the supply chain: uninstalling apps or scanning the operating system does not remove a component that was baked into firmware. The exposure sits with every handset that shares that device image, plus any downstream fraud or botnet activity it can support.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories