Bitdefender said its researchers identified Midnight Mimosa, a malware campaign running on low-cost, multi-brand Android devices built on MediaTek platforms. The malware is embedded in device firmware, meaning affected phones can arrive compromised before the owner installs an app or signs into an account.
Bitdefender disclosed the campaign on October 8, 2026 and updated its report on October 9, 2026. The company said the core infection chain is a persistent, platform-signed system application that appears under system-like package names such as com.android.system.lite, com.android.sys.prot and com.android.sys.gmsprot.
Because the component runs with system-level privileges, Bitdefender said it can silently install and remove apps, grant permissions and load remote code. Normal app uninstall controls do not remove the core component, which lives in the system partition.
Across the family, Bitdefender said it observed the campaign on thousands of devices in more than 150 countries over roughly two years. The highest concentrations in its telemetry were Mexico, France and Italy, followed by the United States, Germany, Brazil and Spain. The report does not provide a full public list of affected retail listings or a Canada-specific device count.
The affected devices appear to come from the bargain and white-label market
The report points to low-cost, white-label and counterfeit-style Android phones rather than mainstream flagship devices. Bitdefender listed model strings that included region-coded builds such as J10_EEA and A9_EEA, counterfeit flagship names such as S24 Ultra and S25 Ultra, and budget rugged model strings including S200 X from Doogee and KINGKONG X from Cubot.
That list should not be read as a complete affected-device list or as proof that every device sold under those names is infected. Bitdefender described the model strings as evidence of a distribution mechanism: phones in this segment can pass through firmware builders, original design manufacturers, resellers and marketplaces before reaching buyers.
Bitdefender said some affected firmware was signed with certificates bearing the name Shenzhen Zediel, but the company cautioned that this does not prove Shenzhen Zediel created, distributed or knew about the malware. The report said the point of insertion remains unclear and may involve an ODM, firmware integrator, logistics partner or another intermediary.
How the malware makes money
Midnight Mimosa is primarily described as a revenue operation. Bitdefender said the preinstalled system app deploys a rotating set of at least 32 disguised apps, including apps posing as weather tools, file managers, app locks, OCR utilities and audio editors.
Those payload apps can generate hidden ad impressions and automated clicks. Some also enroll the device as a residential-proxy relay node, which can route other people’s traffic through the infected phone’s internet connection.
That proxy function is more than a nuisance. The FBI warned in March 2026 that residential proxies can hide command-and-control traffic, support phishing and account takeover activity, create fake accounts and make criminal traffic appear to come from ordinary home or small-business connections.
Play Protect can be bypassed during the install step
Bitdefender said the malware temporarily disables the Google Play Store package, com.android.vending, before silently installing payload apps, then re-enables it afterward. The company assessed that this was probably intended to prevent Google Play Protect from detecting the installation.
Bitdefender also found 13 Google Play apps carrying the same ad-fraud family markers and communicating with related infrastructure. The Play-distributed apps did not have the same system privileges as the preinstalled firmware component, according to Bitdefender, but they could still display ads outside their own interfaces.
Google’s Play Protect documentation says the service checks apps before download, scans devices for harmful apps and may disable or remove harmful apps. Installing apps from Google Play, avoiding suspicious APKs and keeping Play Protect enabled remain good habits, but they do not fully address malware that is already part of an affected device’s system image.
Why certification and device source matter
Google says Play Protect certified devices have passed Android compatibility testing and are eligible to include licensed Google apps. The Android certification page also says certified devices are required to ship without preinstalled malware and include Google Play Protect.
Certification is not a guarantee that every future app or update is safe. It is still a useful baseline when buying Android hardware, especially low-cost devices from online marketplaces. Google says devices that are not Play Protect certified may not be secure, may not receive Android system or app updates and may include Google apps that are not licensed.
Extra scrutiny is warranted when a device has an unusually low price, a confusing brand or model name, generic packaging, missing certification, unofficial app stores, or promotional claims built around free streaming or unlocked content. Those patterns also match FBI warnings around compromised Android-based devices and residential proxy abuse.
What phone owners and small businesses can do now
- Check Play Protect certification before keeping a bargain Android device. Google places the status in the Google Play Store app under the profile icon, Settings and About.
- Keep Google Play Protect enabled. Google says Play Protect is on by default and recommends keeping it on.
- Install system and security updates from the device maker. Updates can address device issues, though firmware-level malware may require more than a routine app removal.
- Treat repeated unknown app installs as a warning sign. Apps that return after removal, unexplained ad activity, disabled Play Store behavior, or suspicious network traffic should be investigated.
- Do not rely on a factory reset if firmware malware is confirmed. Bitdefender said removal requires firmware-level cleanup or disabling the malicious component with ADB, which is not realistic for many owners.
- Keep unmanaged bargain devices off work networks. For small businesses, guest Wi-Fi, network segmentation and device policies can limit exposure from uncertified or unknown Android hardware.
For a personal phone suspected of shipping with firmware malware, the most practical path may be returning the device, seeking an official firmware fix from the manufacturer or replacing it with a Play Protect certified model from a trusted retailer.
The larger pattern
Midnight Mimosa is not the first Android-based device malware story to center on low-cost hardware, ad fraud and residential proxies. In July 2025, Google said BadBox 2.0 had compromised more than 10 million uncertified devices running Android Open Source Project software and used preinstalled malware for ad fraud and other digital crimes. The FBI also warned in 2025 that BADBOX 2.0 involved devices compromised before purchase or during setup.
The new report extends that concern from Android TV boxes and other connected devices into smartphones. Inexpensive Android phones are not automatically unsafe, but the seller, certification status and firmware update path now deserve the same attention as suspicious apps.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







