Science & Tech · Cybersecurity · 8 hrs ago
Preinstalled malware found on low-cost Android phones in 150 countries
Bitdefender researchers found a campaign called Midnight Mimosa affecting some low-cost Android phones that use MediaTek platforms.
The malware is built into the phone’s firmware, so it is present before the owner first turns the device on and cannot be removed.
It can install and remove apps, grant permissions and download code without the owner’s knowledge.
The researchers say the campaign has been seen in 150 countries.
The operators can make money through fake ad clicks and by using infected phones as residential proxy relays.
The malware can also install apps disguised as ordinary tools, such as weather apps and file managers.
Bitdefender says its security technology detected the threat by spotting unusual behavior, but no further response or next steps are described.
Bitdefender researchers found preinstalled Android malware on low-cost phones using MediaTek platforms.
The malware is built into device firmware and may be impossible for users to remove.
The campaign, called Midnight Mimosa, has been seen in 150 countries.
The malware can install and remove apps, grant permissions and download code without users’ knowledge.
Bitdefender says the campaign appears mainly financially motivated, including through ad fraud and proxy services.
- Who
- Bitdefender researchers discovered the campaign.
- What
- Midnight Mimosa is preinstalled Android malware that can control infected phones and install apps without users’ knowledge.
- When
- Not stated.
- Where
- It has been seen in 150 countries.
- Why
- Bitdefender says it appears mainly financially motivated, including through ad and click fraud and proxy services.
This story does not have two clearly opposing sides.
This scheme is likely designed mainly to generate revenue. The operators carry out ad and click fraud, collect device and installed-app information, and turn infected devices into residential-proxy relay nodes, making them zombies in botnets.
The larger the botnet, the more money they can charge.
This story does not have a timeline yet.
- Campaign name
- Midnight Mimosa
- Affected devices
- Low-cost phones using MediaTek platforms
- Geographic reach
- 150 countries
- Malware package found
- com.android.system.lite
- Disguised apps
- At least 32 different apps











