Cheap Android phones shipped with preinstalled Midnight Mimosa
Bitdefender found Midnight Mimosa preinstalled on thousands of cheap MediaTek Android phones, enabling ad fraud and residential proxies in over 150 countries.
Bitdefender Labs disclosed on October 8, 2026 Midnight Mimosa, malware preinstalled in the firmware of thousands of low-cost, often white-label or counterfeit MediaTek-based Android phones sold through mainstream online marketplaces. Platform-signed system packages such as com.android.system.lite and com.android.sys.gmsprot cannot be uninstalled, silently install or remove apps, grant accessibility, notification, and SMS permissions on demand, spoof installer data, and download code while temporarily disabling the Google Play Store. Operators drop at least 32 disguised utility apps that create fraudulent ad impressions in hidden windows with automated clicks, and an app-locker component can register phones as residential proxies, with command-and-control disguised as a weather API; 13 related Google Play apps under at least two developer accounts share that infrastructure. Detections cover more than 150 countries over about two years, led by Mexico, France, and Italy, including Doogee S200 X and Cubot KINGKONG X, some of which were reinfected by updates. Attribution is unknown, though some firmware was signed with Shenzhen Zediel certificates, and the three reports agree without material contradictions.
- Bitdefender disclosed Midnight Mimosa on October 8, 2026: malware preinstalled in firmware on thousands of low-cost, often white-label or counterfeit MediaTek Android phones sold via mainstream marketplaces.
- Platform-signed packages including com.android.system.lite and com.android.sys.gmsprot cannot be uninstalled; they can silently install or remove apps, grant accessibility, notification, and SMS permissions on demand, spoof installer data,…
- The malware temporarily disables the Google Play Store during payload installation and deploys at least 32 disguised utility apps that create fraudulent ad impressions in hidden windows with automated clicks.
- An app-locker component can register phones as residential-proxy nodes; command-and-control is disguised as a weather API.
- Thirteen Google Play apps under at least two developer accounts share the same servers and fraud code.
- Detections span more than 150 countries over roughly two years, led by Mexico, France, and Italy; named models include Doogee S200 X and Cubot KINGKONG X, and some updates reinfected phones.
- Attribution is unknown; some firmware was signed with Shenzhen Zediel certificates.
Coverage timelineoldest first · each row is one article
- · 10h agoThe phone was compromised before the user turned it on: the rise of Midnight Mimosa
Bitdefender Labs· 76
Bitdefender found preinstalled Midnight Mimosa malware on low-cost Android phones, enabling fraud, proxies, and remote control.
- · 10h agoThousands of cheap Android phones shipped with ad-fraud malware
The Record· 58
Bitdefender found ad-fraud malware preinstalled in the firmware of thousands of cheap MediaTek-based Android phones sold across more than 150 countries.
- · 4h agoLow-cost Android phones ship with residential proxy malware
BleepingComputer· 74