Pre-Installed “Midnight Mimosa” Malware Found on Budget Android Phones Worldwide

Thousands of Budget Smartphones Sold in Over 150 Countries Infected with Midnight Mimosa Malware

Security researchers at Bitdefender discovered a pre-installed firmware malware campaign named Midnight Mimosa affecting thousands of Android smartphones across more than 150 countries, including Germany, France, Italy, and the United States, as reported by diepresse.com on October 10, 2026. The malicious software operates with system-level privileges without requiring user interaction. Over the past two years, Bitdefender identified several thousand infected devices, with researchers noting that affected smartphones were observed particularly frequently in Mexico, followed by France and Italy, alongside Brazil and Spain.

The malicious payload targets low-cost devices built on MediaTek hardware platforms. Researchers identified infected models from brands such as Doogee and Cubot, alongside counterfeit replicas imitating flagship devices like Samsung’s Galaxy S24, S25, and S26 series, plus Apple iPhone models, according to Futurezone. An analyzed counterfeit device cost roughly 180 US dollars, AD HOC NEWS noted. Additionally, established online marketplaces circulate numerous fake devices sold under designations including S24 Ultra, S25 Ultra, S26 Ultra, i17 Pro Max, i16_Pro_Max, and 17_Pro_Max.

System-Level Firmware Integration and Hidden Operation

Unlike traditional trojans that arrive via downloaded files, Midnight Mimosa is embedded directly into the device firmware prior to the user’s first setup. This deep integration makes detection and removal nearly impossible for standard users, ComputerBase explained. The malware works unnoticed in the background.

The core infrastructure engages in ad fraud by running background advertisements and simulating clicks to generate fraudulent revenue. To accomplish this, the system software automatically downloads, installs, and removes dozens of disguised payload applications, including weather apps and file managers, according to Futurezone. The system app downloads at least 32 disguised payload apps masquerading as weather applications, note programs, OCR services, or audio editors. These hidden tools harvest device data and user statistics to keep the ad-network traffic looking legitimate. Beyond ad fraud, the compromised devices can be incorporated into a botnet, and the malware is capable of reading SMS messages and sending them on behalf of affected users.

Google Play Protect Bypass and Infrastructure Mechanisms

A sophisticated evasion technique allows the firmware component to interact directly with core Android security services. The malicious system component temporarily deactivates Google Play Protect before installing secondary payloads, then reactivates the security feature immediately afterward to avoid detection, as reported by ComputerBase.

Pre-Installed "Midnight Mimosa" Malware Found on Budget Android Phones Worldwide
Photo: CHIP

Parallel investigations uncovered 13 separate applications hosted on the official Google Play Store that shared infrastructure and ad-fraud code with the firmware campaign, distributed via developer accounts named fivedev and CPS Developer, AD HOC NEWS reported. These store-downloaded apps lack system-level privileges but exhibit identical ad-injection behaviors outside their primary user interfaces. The applications found on Google Play were signed with different certificates while communicating with the same server.

Supply Chain Vulnerabilities and Regulatory Warnings

Investigators found hardware certificates from a Shenzhen-based manufacturer on several compromised devices, but Bitdefender stated that the exact origin point within the manufacturing and logistics supply chain remains unconfirmed, according to diepresse.com. Security analysts suggest the campaign operators intend to rent out the resulting botnet infrastructure to other criminal syndicates, Futurezone noted.

Pre-Installed "Midnight Mimosa" Malware Found on Budget Android Phones Worldwide
Photo: Futurezone

Regulatory authorities have responded to the widespread circulation of these compromised imports. The Bundesnetzagentur advised consumers to exercise extreme caution regarding abnormally low pricing on online marketplaces originating outside the European Union, pointing out that third-party logistics firms operating within Europe typically assume no legal liability for non-compliant hardware, CHIP reported. Because standard debugging tools like the Android Debug Bridge or firmware flashing are required to clear the infection, Bitdefender recommends replacing affected devices entirely, according to ComputerBase.

Don't Waste Money! 💸 Get These 5 Budget Android Phones in 2026 Instead
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Brazil files lawsuit against Shell over 2024 floods