Malware capable of generating ad revenue and integrating devices into botnets has been discovered preinstalled on thousands of low-cost Android phones running MediaTek chips across more than 150 countries.
System-Level Privileges Built into Firmware
The malicious operation relies on an Android application embedded directly into the firmware during manufacturing or distribution. Because the app executes with system-level privileges, it can silently install and remove other software, grant permissions, and execute unauthorized code. Bitdefender tracked the malware over a two-year window, identifying affected units across more than 150 countries. Mexico, France, and Italy registered the highest volume of detections, followed by the United States, Germany, Brazil, and Spain.
The impacted hardware primarily consists of low-cost, white-label, or counterfeit devices, including models styled after Samsung Galaxy and Apple iPhones. One device examined by researchers cost roughly $180 on mainstream online marketplaces. Some of the affected firmware carried digital certificates featuring the name of Shenzhen Zediel, a Chinese smart hardware and consumer electronics developer. Researchers emphasized that the presence of these certificates does not prove the company built the malware, distributed it knowingly, or understood it was present. The software could have been introduced by original device manufacturers, firmware integrators, or logistics partners.
Malware drops disguised apps to generate invisible ad impressions
Rather than generating fraudulent ad views directly, the preinstalled malware acts as a delivery mechanism. It silently drops at least 32 disguised utilities onto the device, including weather trackers, note-taking apps, file managers, and app locks. These secondary applications load real advertisements via legitimate ad services but display them inside invisible windows layered over other programs. This technique registers ad impressions that users never witness, while certain components also execute automated click fraud.
To avoid detection, the core malware temporarily disables the Google Play Store prior to deploying select payloads, reactivating the store once installation finishes. Bitdefender also uncovered 13 separate applications hosted on the official Google Play Store that communicated with the same command infrastructure and shared identical ad-fraud routines. Unlike the firmware-level threat, these Play Store utilities offered genuine functions like QR-code scanning and weather reporting, yet still possessed the ability to push advertisements during periods of device inactivity.
Cheap mobile hardware creates incentives for back-end monetization
The ubiquity of extremely inexpensive mobile hardware creates an economic incentive for back-end monetization. As Bitdefender noted regarding the broader market, low-cost or counterfeit phones are frequently subsidized post-sale through software designed to generate continuous ad revenue. With thousands of devices compromised globally, the incident highlights persistent supply-chain vulnerabilities in white-label Android manufacturing, where system partitions remain accessible to malicious actors before the point of sale.