Skip to content
Some Cheap Android Phones Are Shipping with Pre

Some Cheap Android Phones Are Shipping with Pre

Androidheadlines • October 8, 2026

A new malware campaign has been spotted by Bitdefender’s security researchers. It’s referred to as ‘Midnight Mimosa’, and it’s running on low-cost, multi-brand Android devices built on MediaTek platforms.

Midnight Mimosa malware ships on cheap MediaTek-based Android devices

What’s interesting is that the malware ships pre-installed in the device firmware. That’s particularly concerning. Bitdefender found multiple system packages involved, though that varies from one device to the .

The malware activates when the phone is switched on for the very first time, and no… it cannot be uninstalled. It runs with system-level privileges that allow it to “silently install and remove apps, grant permissions, and load arbitrary code supplied remotely.”

Generating revenue streams is the main goal

Needless to say, this scheme is designed to generate revenue. Bitdefender says that the “operators carry out ad and click fraud, collect device and installed-app information, and turn infected devices into residential-proxy relay nodes, making them zombies in botnets.”

This also enables them to use devices for DDoS attacks, as they’re part of botnets. The larger the botnet, the more money they can charge.

It is also noted that the system app itself does not register the fraudulent impressions and clicks. The revenue engine is driven by the dropper cover apps , which include real-looking weather, app-lock, note, and OCR apps.

The goal is to load an invisible window on top of apps that registers ads being shown. This system app – com.android.system.lite – was the first one identified by Bitdefender. That’s just the tip of the iceberg, though.

Quite a few system-looking files are laced with malware

Bitdefender identified the same malware core shipping under a rotating set of system-sounding names, including com.android.sys.prot, com.android.sys.gmsprot, and com.android.sys.bcprot. Each of them is a different build, carrying different signing certificates.

What was also discovered is that 13 apps currently present in the Google Play Store communicate with the same servers that control this malware. You can check out the full report here .

Extracted Entities

Attack Types (2)

Campaigns (1)

Platforms (1)