Pull to refresh
Logo
Low-cost Android phones ship with firmware malware that enables ad fraud and proxy abuse

Low-cost Android phones ship with firmware malware that enables ad fraud and proxy abuse

New Capabilities

Bitdefender's 'Midnight Mimosa' campaign ran about two years across 150 countries before discovery

Yesterday: Bitdefender publishes Midnight Mimosa findings

Overview

Updated 1 hour ago

Some low-cost Android phones arrive with malware already in the firmware. Bitdefender researchers named the campaign 'Midnight Mimosa' after finding it on devices that run MediaTek chipsets, where it can silently install and remove apps, grant itself permissions, and load arbitrary code from a remote server.

The malware also turns each infected phone into a residential proxy, relaying other people's network traffic through the owner's connection. Because it sits in the system partition, users can't uninstall it; Bitdefender observed the campaign for roughly two years across more than 150 countries before publishing its findings.

Why it matters

A cheap Android phone can arrive already compromised, quietly earning attackers ad-fraud revenue and routing their traffic through your home connection.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

150+
Countries with infected devices
Highest victim counts in Mexico, France, Italy, the US, Germany, Brazil, and Spain.
~2 years
Campaign observation window
Bitdefender observed infections across roughly a two-year span.
32
Disguised payload apps deployed
Fake AppLock, weather, file-manager, icon-tool, OCR, and audio-editor apps.
13
Google Play apps sharing campaign infrastructure
Apps under at least two developer accounts communicate with the same command servers.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Organizations Involved

Timeline

1 event Latest: Yesterday
  1. Bitdefender publishes Midnight Mimosa findings

    Latest Research disclosure

    Researchers document preinstalled firmware malware on low-cost Android phones across 150+ countries.

Scenarios

1

Supply chain source identified, vendors ship firmware fix

Unlikely Resolves by Q2 2027

Discussed by: Bitdefender researchers, who note the injection point could be an ODM, firmware integrator, or logistics partner

Bitdefender or another researcher traces the malware to a specific party in the manufacturing or distribution chain. Affected brands like Doogee and Cubot issue firmware updates that remove the system app, and marketplaces pull the infected devices from sale.

2

Google removes 13 linked Play Store apps

Possible Resolves by Jan 31, 2027

Discussed by: Bitdefender, which flagged the apps as dangerous despite limited privileges

Google reviews the flagged apps, finds they share command-and-control infrastructure with Midnight Mimosa, and removes them from the Play Store. The firmware malware remains on already-sold devices, but attackers lose a legitimate distribution channel for payload apps.

3

Campaign continues largely unaddressed

Likely Resolves by End of 2027

Discussed by: Bitdefender, noting remediation is unrealistic for most owners and fixes sit with vendors

No vendor acts, the malware stays on sold devices, and the operators keep installing and removing payloads to evade detection. The campaign expands to additional low-cost models as supply chain participants fail to change practices.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

Late 2023

BadBox (2023-2024)

Researchers at Human Security found malware preinstalled on cheap Android TV boxes and phones sold through online marketplaces. The malware ran ad fraud and turned devices into residential proxies for relaying malicious traffic.

Then

Google disrupted the operation in part by cutting off communication channels, and some distribution networks were shut down.

Now

Established the pattern of budget Android hardware being compromised somewhere in the supply chain for ad fraud and proxy abuse.

Why this matters now

Midnight Mimosa follows the same playbook: firmware-level compromise of low-cost devices, monetized through ad fraud and residential proxy relay.

2016-2017

Triada (2016-2017)

Security firm Dr. Web found the Triada trojan embedded in the firmware of budget Android phones. The malware rooted devices, intercepted messages, and ran ad fraud with system-level privileges.

Then

The infection was traced to firmware distributed to multiple cheap phone brands, and Google tightened Play Protect enforcement.

Now

Became one of the first widely documented cases of Android malware arriving preinstalled, showing that system partition access is the most durable infection.

Why this matters now

Triada demonstrated that firmware-level malware on budget devices is neither new nor easily removed; Midnight Mimosa shows the model has matured to include proxy botnets.

Sources

(6)