Midnight Mimosa Malware Found Preinstalled on Cheap Android Phones
Bitdefender found Midnight Mimosa ad-fraud malware preinstalled on thousands of MediaTek-based Android phones across 150+ countries, with 32 disguised payload apps.

Executive Summary
Bitdefender has documented a preinstalled Android malware campaign, tracked as Midnight Mimosa, that ships inside the firmware of thousands of low-cost Android phones built on MediaTek chips and sold worldwide. The malware runs with system-level privileges, cannot be uninstalled by the device owner, and is present before the phone is first powered on, according to a Bitdefender report released Thursday.
Over roughly two years of telemetry, the Romania-based security firm observed the malware on thousands of devices across more than 150 countries. Mexico, France, and Italy accounted for the largest shares of detections, followed by the United States, Germany, Brazil, and Spain. The campaign's primary monetization appears to be advertising and click fraud, though Bitdefender said the malware also has capabilities that could allow infected phones to be enrolled into botnets.
Technical Analysis
The Midnight Mimosa implant is a malicious Android application baked into device firmware before sale. Because it executes with system-level privileges, it can silently install or remove other applications, grant permissions to those applications, and download and run additional code without the owner's approval. Bitdefender described the malware as effectively permanent from the user's perspective: "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled."
The implant does not generate fraudulent ad impressions itself. Instead, it silently installs seemingly legitimate utility applications — disguised as weather, note-taking, app-lock, and file-management tools — that load real ads through legitimate advertising services. Those apps then render the ads in invisible windows layered over other applications, registering impressions the user never sees. Some components can also generate automated clicks. Bitdefender identified at least 32 disguised applications deployed by the preinstalled malware.
Before installing some payloads, the malware temporarily disables the Google Play Store, a step the researchers assess is intended to evade detection, and re-enables it once installation completes. Bitdefender separately found 13 apps distributed through Google Play that communicated with the same command-and-control infrastructure and carried the same ad-fraud code. Unlike the firmware-resident implant, those Play Store apps lack system privileges and provide genuine functionality — weather information, QR-code scanning — but can still display ads outside the app, including when the phone is idle.
The affected hardware is dominated by low-cost, white-label, and counterfeit devices, including models styled to resemble better-known Samsung Galaxy and Apple iPhone products. Bitdefender said the phones are sold through mainstream online marketplaces; one device the researchers examined cost about $180. All affected devices observed by Bitdefender use MediaTek chips.
Attribution remains unresolved. Bitdefender has not determined who placed the malware on the devices or at which point in the supply chain it was introduced. Some affected firmware was signed with certificates bearing the name of Shenzhen Zediel, a Chinese company that develops and sells smart hardware and consumer electronics. Bitdefender explicitly stated the certificates do not establish that the company created, knowingly distributed, or was aware of the malware. The researchers said the implant could have been introduced by an original device manufacturer, a firmware integrator, a logistics partner, or another intermediary before the phones reached buyers.
Mitigations & Recommendations
Midnight Mimosa cannot be removed through normal user actions because it resides in firmware and runs with system privileges. Defenders and buyers should treat affected devices as untrusted hardware rather than attempting endpoint-level remediation.
Practical measures supported by the source material:
- Avoid unbranded and counterfeit Android hardware. Bitdefender attributes the campaign's economics to extremely cheap hardware whose margins are recovered through post-sale software monetization. White-label devices styled after Samsung Galaxy or Apple iPhone models were overrepresented in detections.
- Treat MediaTek-based, sub-$200 Android phones from unverified sellers as suspect. All devices Bitdefender observed in this campaign used MediaTek chips, and the phones were sold through mainstream online marketplaces.
- Do not rely on Play Store removal or factory reset. The implant is present in firmware before first boot, so neither action removes it.
- Monitor for anomalous ad activity and Play Store state changes. The malware temporarily disables the Google Play Store before installing some payloads; unexpected Play Store outages or ad impressions attributed to a device that was idle are consistent with the described behavior.
- For enterprises issuing low-cost Android hardware to staff, prefer devices from vendors with verifiable firmware supply chains. Bitdefender has not identified the injection point, so provenance verification is the only control that addresses the described threat model.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
