Bitdefender Labs disclosed on October 8, 2026, that it had found malware baked into the firmware of thousands of low-cost Android phones. Dubbed Midnight Mimosa, the operation has been running for roughly two years and touched devices in more than 150 countries, including the United States. The malware sits in the phone’s system partition before the owner ever powers it on, and it cannot be removed through Android’s normal uninstall process. Here is what Midnight Mimosa does, which phones are affected, and what you can do about it.
Quick answer: Midnight Mimosa is a malware framework preinstalled in the firmware of budget Android phones built around MediaTek chips. It runs with system-level privileges, silently installs ad-fraud apps, steals device data, and can turn infected phones into residential proxy nodes. It was discovered by Bitdefender and is not attributed to any known threat actor.
What Midnight Mimosa actually is
Unlike ordinary Android malware that tricks you into installing a bad app, Midnight Mimosa arrives with the phone. Bitdefender’s App Anomaly Detection technology flagged a suspicious system application named com.android.system.lite that was quietly installing and removing other applications in the background. Digging deeper, researchers found it was one piece of a larger malware framework: a platform-signed system app that downloads additional modules from command-and-control servers and carries them out with full system privileges.
Because the app is signed as part of the Android platform, the operating system treats it as trusted. Variants of the core component use package names like com.android.sys.prot and com.android.sys.gmsprot, all designed to look like legitimate system packages. That trust is the whole game: with platform-level privileges, the malware can install and remove apps, grant sensitive permissions, and execute remotely downloaded code without any user interaction.
How the malware makes money
Ad fraud through disguised cover apps
Bitdefender identified approximately 32 payload applications distributed through the framework. These look like ordinary utilities: weather apps, file managers, app lockers, OCR tools, and audio editors. Instead of showing ads honestly, the apps load genuine ads through a legitimate ad SDK inside invisible windows, registering fraudulent impressions and clicks the owner never sees.
The evasion is deliberate. Before silently installing its payloads, the malware temporarily disables the Google Play Store app (com.android.vending) so Google Play Protect cannot catch the installation, then switches the store back on afterward. Some variants even rewrite Android’s recorded installer information so the malicious apps look as if they were installed through Google Play.
Turning phones into residential proxies
The second revenue stream is more concerning. Bitdefender found a malicious application disguised as an app locker (com.mobile.applock.en) containing a TCP proxy component that registers infected devices with a remote command server. From there, operators can instruct the phone to connect to chosen hosts and forward traffic through it.
In practice, that means an infected phone could relay someone else’s internet traffic, concealing the true origin of attacks or letting strangers reach devices on the owner’s home network. Bitdefender confirmed the proxy command infrastructure was operational and accepting device registrations, though in testing its registered device was never sent relay targets, so it remains unclear whether operators are actively forwarding traffic right now.
Data collection and the Play Store connection
Researchers also found 13 Android applications distributed through the Google Play Store that carried the same ad-fraud code and communicated with Midnight Mimosa infrastructure. These were published under 13 different signing certificates and at least two developer accounts, identified as fivedev and CPS Developer. Unlike the preinstalled component, the Play Store apps lack system privileges, but they can still display ads outside their interface, even when the phone is not in use. The researchers also confirmed the malware framework collects device information and is capable of botnet integration.
Which phones are affected
The infected devices are low-cost Android handsets built on MediaTek platforms. Bitdefender found the malware on phones carrying model names from legitimate budget manufacturers, including the Doogee S200 X, Doogee Fire 3 Max, and Cubot KINGKONG X, as well as region-coded builds such as J10_EEA and Q6_EEA. Many affected phones are white-label or outright counterfeit products sold through online marketplaces, some mimicking Samsung flagships with names like S25 Ultra and others copying Apple designs labeled i17 Pro Max.
Geographically, Bitdefender observed the campaign on thousands of unique devices across more than 150 countries over about two years, with the highest victim counts in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. The presence of the United States in the top five is notable: this is not a problem confined to emerging markets.
Real-world victims had already noticed something was wrong. In an XDA forums post cited by Bitdefender, owners of Cubot and Doogee phones reported suspicious applications that repeatedly reinstalled themselves after removal. One Doogee Fire 3 Max owner reported that an official firmware update appeared to introduce the malware, which disappeared after restoring older firmware and returned when the update was reinstalled. Some users said manufacturers later released firmware updates that resolved the infections, but the manufacturers have not publicly explained how the malicious software got into their firmware in the first place. Researchers found firmware signed with certificates associated with Chinese manufacturer Shenzhen Zediel, but Bitdefender was explicit that it is unclear whether the company was involved in the campaign.
Why removing it is so difficult
Because Midnight Mimosa lives in the device’s system partition with platform signing, a factory reset will not remove it. Clearing the device requires firmware-level cleanup or disabling the malicious component through Android Debug Bridge (ADB), both of which are unrealistic for most phone owners. As Bitdefender put it, the durable fix sits with the vendors and marketplaces that ship and sell the affected firmware.
Supply-chain compromises of this kind are becoming a pattern. Criminals are finding creative ways to tamper with software and hardware before it reaches the buyer, from the Tensorlake npm supply-chain compromise earlier this month to the PoeLLM malware campaign that hid infrastructure commands in a GitHub poem. Midnight Mimosa shows the same playbook applied to hardware: tamper upstream, and the victim never has to click anything.
How to check whether your phone is infected
If you bought a suspiciously cheap Android phone, especially one with an unfamiliar brand or a flagship-style model name, a few checks are worth your time:
- Open Settings, go to Apps, enable Show system apps, and look for packages named
com.android.system.lite,com.android.sys.prot, orcom.android.sys.gmsprot. On a legitimate phone, none of these should exist. - Watch for apps you never installed, especially weather tools, app lockers, OCR utilities, or file managers that reappear after you remove them.
- Check your mobile data usage and battery statistics for unexplained activity. Ad fraud and proxy traffic run in the background.
- Run a scan with Google Play Protect and a reputable third-party antivirus, keeping in mind that the malware actively tries to evade detection.
What to do if your phone has Midnight Mimosa
If you find signs of the infection, start with the seller: request a clean firmware update or a return under warranty, since the fault lies with the device itself. If no clean firmware exists, an advanced user can disable the malicious system component via ADB, but this carries real risk of breaking the device, so most people should seek professional help instead. If neither option is available, treat the phone as untrusted: do not sign into banking, email, or work accounts on it, and consider replacing it.
For future purchases, buy from reputable retailers and established manufacturers, verify the brand and model on the maker’s official website before ordering, and be skeptical of current-generation flagship specs at a fraction of the real price. A deal that looks too good to be true is exactly the price point Midnight Mimosa targets. And if you bought a budget phone recently, check that it is receiving real security updates: abandoned firmware is a warning sign on its own, as the missed patches behind the FBI’s recent PeopleSoft breach demonstrated. Keeping devices updated is still the simplest defense, even when the threat arrives in the box.
Frequently asked questions
What is Midnight Mimosa?
Midnight Mimosa is a malware framework discovered by Bitdefender in October 2026. It is preinstalled in the firmware of low-cost Android phones, runs with system privileges, silently installs ad-fraud apps, collects device data, and can turn phones into residential proxy nodes.
Can I remove Midnight Mimosa with a factory reset?
No. The malware lives in the phone’s system partition with platform-level signing, so a factory reset leaves it intact. Removal requires firmware-level cleanup or disabling the component via ADB, and the realistic fix is a clean firmware update from the vendor.
Does Midnight Mimosa affect iPhones or flagship Android phones?
No. The campaign targets low-cost Android devices built on MediaTek chipsets, including budget brands and counterfeit flagship-named phones. iPhones and genuine flagship Android devices are not affected.
How do I check if my phone has Midnight Mimosa?
Look in your system apps for packages like com.android.system.lite, com.android.sys.prot, or com.android.sys.gmsprot. Also watch for unfamiliar apps that reinstall themselves after removal, and scan the device with Google Play Protect plus a reputable antivirus.
Is it still safe to buy a cheap Android phone?
It can be, if you buy from established brands and reputable retailers and verify the model on the manufacturer’s official site. Avoid unknown sellers, listings that hide the real manufacturer, and flagship specs at absurdly low prices. Check that the phone actually receives security updates.
Who is behind Midnight Mimosa?
Bitdefender has not attributed the campaign to any threat actor. It remains unclear at what stage of the manufacturing and distribution chain the firmware was tampered with, though the investigation noted firmware signed with certificates associated with Shenzhen Zediel without assigning blame.
