Security researchers found the Midnight Mimosa malware preinstalled in the firmware of low-cost Android phones observed in more than 150 countries. The campaign gives attackers system-level control before a customer downloads an app or completes the phone’s setup, creating a supply-chain risk for affected devices.
Why the malware is difficult to remove
Bitdefender researchers found the malware on multi-brand Android devices built on MediaTek platforms. It uses system-like package names, including com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Because the components run with elevated privileges and are installed in the system partition, Android’s normal uninstall process cannot remove them.
The malware can silently install and remove applications, grant permissions, load remotely supplied code, and collect information about the device and installed applications. Before installing some additional payloads, it temporarily disables the Google Play Store and then re-enables it. Bitdefender said this behavior may help the malware evade Google Play Protect during installation.
Ad fraud and proxy abuse
Midnight Mimosa appears primarily designed to generate criminal revenue. Its operators can deploy disguised weather, file-manager, app-lock, OCR, note, and audio-editor applications that display hidden advertisements or automatically interact with ads. The campaign also includes a proxy component that can relay traffic through infected phones, potentially concealing the source of other activity.
Bitdefender identified at least 32 disguised applications in the firmware-based infection chain. Researchers also found 13 Google Play applications containing the same advertising-fraud code and communicating with Midnight Mimosa infrastructure. Those applications did not have the same elevated privileges as the preinstalled system components.
Bitdefender observed thousands of affected devices over approximately two years. Mexico and France had the highest observed concentrations, followed by Italy, the United States, Germany, Brazil, and Spain. Researchers said they could not determine where in the manufacturing or distribution process the firmware was modified.
What Android owners should do
- Check the phone’s exact model and firmware version against the manufacturer’s support information. BleepingComputer reported affected devices associated with names including Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products.
- Install any official firmware update supplied by the manufacturer, then restart the phone and review applications that appear without permission.
- Run Google Play Protect and a reputable mobile-security scan. Repeatedly reappearing applications, unexplained advertisements, and unusual battery or data use are warning signs.
- If a suspicious system application remains after an official update, contact the manufacturer or retailer. Bitdefender said remediation may require firmware-level cleanup or disabling the component with Android Debug Bridge, which can be difficult for many users.
The incident shows why app-store security alone cannot protect a phone compromised before it reaches its owner. Buyers should consider the manufacturer’s update history and support options, not only the device’s price and specifications.
References
- Townsend, K. (2026, October 9). Pre-baked firmware malware hits budget Android devices in 150+ countries. SecurityWeek. https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/
- Gozob, A. M., & Baciu, A. (2026, October 8). The phone was compromised before the user turned it on: The rise of Midnight Mimosa. Bitdefender Labs. https://www.bitdefender.com/en-us/blog/labs/midnight-mimosa-malware
- Abrams, L. (2026, October 8). Low-cost Android phones ship with residential proxy malware. BleepingComputer. https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/
