Midnight Mimosa malware is drawing attention to a difficult Android security problem: what happens when a phone is already compromised before its owner even turns it on?
Security researchers at Bitdefender Labs uncovered a malware campaign affecting low-cost, multi-brand Android devices built on MediaTek platforms. The malicious component is embedded directly in the firmware, giving it system-level privileges from the moment the device is first powered on.
Bitdefender said the campaign has been active for roughly two years and was observed on thousands of devices across more than 150 countries. The malware can silently install and remove applications, grant permissions, load additional code from remote servers and turn infected phones into revenue-generating nodes for ad fraud and residential proxy activity.
Midnight Mimosa Malware Comes Preinstalled in Android Firmware
Unlike a typical Android infection, Midnight Mimosa does not depend on the user downloading a suspicious APK or clicking a malicious link.
The core component is already present in the device firmware. Bitdefender first identified it under the package name com.android.system.lite, but later found the same malware core using several other system-like names across different builds.
The package is platform-signed and runs with privileged Android permissions. That allows it to install and remove software without showing the normal confirmation prompts users would expect.
It can also grant permissions to other applications and load additional code supplied remotely by its command-and-control infrastructure.
That combination makes the malware particularly difficult to detect through normal user behavior. By the time the owner reaches the Android home screen, the compromised system component may already be running in the background.
Thousands of Devices Were Seen in More Than 150 Countries
Bitdefender telemetry linked Midnight Mimosa to thousands of devices distributed across more than 150 countries.
The researchers observed some of the largest concentrations in Mexico, France and Italy, with additional activity in the United States, Germany, Brazil and Spain. Devices also appeared across parts of Africa, Southeast Asia and the Middle East.
The wide geographic spread suggests the affected phones may have reached customers through multiple distribution channels and online marketplaces rather than through a single regional seller.
However, this does not mean that all low-cost Android phones or all MediaTek-based devices are affected. Bitdefender’s findings apply to the devices and firmware builds observed during its investigation.
How the Malware Controls an Infected Phone
The preinstalled system component acts as the foundation of a larger malware ecosystem.
After contacting remote infrastructure, it can retrieve configuration data and load additional plugins. Bitdefender found that these plugins could silently deploy a rotating collection of at least 32 disguised applications.
Some were made to resemble ordinary weather apps, AppLock utilities, file managers, OCR tools, icon customization software and audio editors.
Behind those ordinary-looking names, the malware could support several activities, including:
- Silent installation and removal of applications
- Automatic permission granting
- Remote loading of additional code
- Hidden advertising activity
- Automated ad clicks
- Collection of device and installed-app information
- Residential proxy and botnet activity
The visible payload applications may appear and disappear over time, while the privileged system component remains installed underneath them.
Ad Fraud Appears to Be a Major Part of the Operation
Bitdefender believes monetization is one of the main goals behind the campaign.
The malware can install applications carrying legitimate advertising software development kits, then manipulate how those apps display advertisements and register clicks.
Researchers documented hidden ad windows, synthetic clicks and automated interaction events designed to make fraudulent activity look more like normal user behavior.
The system-level component itself does not need to display the ads. Instead, it controls the installation and behavior of other applications that act as the revenue-generating layer of the operation.
Compromised Phones Can Become Residential Proxy Nodes
Advertising fraud is not the only way the operators can profit from infected devices.
Bitdefender also found payloads capable of turning phones into residential proxy relay nodes.
A residential proxy routes internet traffic through a real consumer device and its IP address. That traffic can appear to websites and online services as if it originated from an ordinary household or mobile user.
When thousands of compromised phones are connected in this way, they can form part of a much larger botnet infrastructure.
Bitdefender noted that such infrastructure could potentially be rented or abused for other activities, including distributed denial-of-service operations. That does not mean every Midnight Mimosa device was observed carrying out DDoS attacks, but the underlying capability increases the potential value of the infected device network.
Midnight Mimosa Disables Google Play During Some Installs
One of the more unusual techniques documented in the campaign involves temporarily disabling the Google Play Store while additional applications are installed.
Bitdefender found that malware plugins could disable the com.android.vending package immediately before performing a silent installation, then enable it again after the process completed.
The researchers described this as a Play Protect evasion technique because the Play Store hosts the on-device scanning component used during application installation.
Google Play Protect normally checks apps when they are installed and periodically scans Android devices for potentially harmful applications. Google says it may warn users, disable suspicious apps or remove harmful software when detected.
By temporarily disabling the Play Store package during installation, Midnight Mimosa creates a short period in which that normal protection is not available.
The Malware Can Also Fake an App’s Installation Source
Bitdefender found another technique that makes the infection harder to investigate.
Some samples were able to record Google Play as the apparent source of an application even when the software had not actually been distributed through Google Play.
This means investigators cannot rely only on the recorded installer name when deciding whether an application genuinely came from Google’s store.
The researchers compared those apps with Google’s server-applied Play signature information to determine whether their claimed origin was legitimate.
13 Related Applications Were Found on Google Play
The campaign was not limited to malware that arrived inside phone firmware.
Bitdefender also identified 13 applications published on Google Play that contained the same ad-fraud family code and communicated with infrastructure connected to the wider Midnight Mimosa ecosystem.
Those applications were spread across at least two developer accounts and 13 separate signing certificates.
There is an important distinction, however: the Google Play versions did not have the same system-level privileges as the malware preinstalled in the firmware.
They were connected through shared code and infrastructure, but they could not perform all of the privileged actions available to the firmware component.
Some Devices Used Misleading Model Names
During the investigation, some affected phones reported model strings resembling well-known flagship Android devices.
Bitdefender warned that those names should not be taken as proof that genuine flagship phones from those manufacturers were compromised.
Low-cost or counterfeit devices can report misleading model information, including names designed to imitate much more expensive hardware.
The researchers also saw higher-volume model identifiers associated with budget devices such as the Doogee S200 X and Cubot KINGKONG X.
Those observations are useful for understanding how the malware appears in the field, but they should not be treated as evidence that a particular manufacturer intentionally installed the malware.
Who Added Midnight Mimosa to the Firmware?
That remains one of the biggest unanswered questions.
Bitdefender found that firmware on some affected devices had been signed using certificates bearing the name Shenzhen Zediel.
However, the researchers explicitly cautioned that this does not establish that the certificate owner knowingly participated in the malware deployment.
The malicious component could have entered the supply chain at several points, including an original design manufacturer, firmware integrator, logistics partner or another intermediary.
Bitdefender said identifying the party responsible would require information beyond the scope of its technical investigation.
Why Users Cannot Simply Uninstall the Malware
For affected users, one of the most difficult parts of Midnight Mimosa is persistence.
The main component is installed as a privileged system application inside the firmware. As a result, it cannot be removed in the same way as an ordinary Android app.
Bitdefender said remediation may require replacing the firmware with a trusted build or using Android Debug Bridge tools to disable the malicious package.
Those are not straightforward recovery steps for an average phone owner.
That is why firmware-level infections create a different security problem from ordinary mobile malware: the permanent fix often depends on the device vendor or another party in the hardware and firmware supply chain.
What Android Users Can Do
There is no indication that every inexpensive Android phone is affected by Midnight Mimosa. Still, the campaign shows why the source of a device matters as much as the apps installed on it.
Users can reduce their exposure by purchasing devices from trusted retailers and established manufacturers, keeping Android and firmware updates current, and being cautious about unknown phones sold with unrealistic specifications at unusually low prices.
Google recommends keeping Play Protect enabled and regularly installing Android and security updates. Its official Android malware removal guidance also recommends checking for potentially harmful software when a device begins behaving unexpectedly.
Warning signs can include unexplained app installations, unusual mobile data usage, unexpected battery drain or applications that repeatedly return after being removed.
Organizations managing large Android fleets may also need behavioral mobile security tools, because traditional app scanning alone may not be enough when a threat is embedded in firmware.
Midnight Mimosa Is a Supply-Chain Security Problem
The most important lesson from Midnight Mimosa is that Android malware does not always begin with a user mistake.
In this case, the malicious component can already be part of the phone before the buyer opens the box.
It has system privileges, can silently install other software, can interfere with normal security scanning during installation and can receive new code from remote infrastructure.
That makes the campaign a mobile supply-chain security issue rather than a conventional malicious-app infection.
For more coverage of threats that affect devices at a deeper system level, read our Device Security Audit 2026 guide.
Frequently Asked Questions
What is Midnight Mimosa malware?
Midnight Mimosa is an Android malware campaign documented by Bitdefender. Its core component was found preinstalled in the firmware of some low-cost Android devices, where it operates with system-level privileges.
How many devices are affected?
Bitdefender observed thousands of devices associated with the campaign across more than 150 countries. The research does not provide a complete worldwide victim count.
Can Midnight Mimosa be removed like a normal Android app?
No. The main component is installed as a privileged system application and cannot be removed using the normal Android uninstall process.
Does Midnight Mimosa affect every MediaTek Android phone?
No. The research covers specific affected devices and firmware builds observed by Bitdefender. It does not indicate that all MediaTek-powered Android devices are compromised.
Were related apps found on Google Play?
Yes. Bitdefender identified 13 Google Play applications containing related ad-fraud code and communicating with infrastructure associated with the same ecosystem. Those apps did not have the same privileged access as the firmware-based malware.
Final Thoughts
Midnight Mimosa shows how difficult mobile security becomes when the compromise starts inside the device supply chain.
A user can avoid suspicious links, install apps carefully and keep normal Android protections enabled, yet still receive a phone containing a malicious privileged component from the moment it is switched on.
For consumers and businesses, the incident reinforces the importance of trusted device suppliers, transparent firmware chains and security monitoring that looks at what applications actually do, not only where they came from.




