Skip to content
Malware Preinstalled on Thousands of Cheap Android Phones

Malware Preinstalled on Thousands of Cheap Android Phones

First seen 8 Oct 2026, 16:41 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 17:35 UTC
  • •Midnight Mimosa malware is preinstalled on low-cost Android devices, making it unremovable.
  • •The malware generates revenue through ad fraud and can turn devices into botnets.
  • •Thousands of affected devices have been identified across over 150 countries.

Bitdefender has identified a malware campaign named Midnight Mimosa affecting low-cost Android phones built on MediaTek platforms. The malware is preinstalled in the firmware, granting it system-level access to install and remove applications without user consent. It primarily generates revenue through ad fraud and can turn infected devices into botnets. The malware has been observed on thousands of devices across over 150 countries, with significant detections in Mexico, France, and Italy. Notably, the malware can disable the Google Play Store temporarily to evade detection during payload installation. Researchers found at least 32 disguised applications associated with the malware, which utilize legitimate advertising services to generate fake ad impressions. The campaign raises concerns about the security of low-cost smartphones, especially counterfeit devices resembling popular brands. Currently, the malware cannot be uninstalled by users, leaving them vulnerable.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Bitdefender reports Midnight Mimosa malware
Bitdefender disclosed the discovery of the Midnight Mimosa malware affecting low-cost Android phones, highlighting its ad fraud capabilities.
Therecord.Media
2026-10-08
Malware identified in multiple countries
The malware has been detected on thousands of devices across more than 150 countries, with significant numbers in Mexico, France, and Italy.
Hackread

More articles in this cluster (5)

Following this threat?

Track MediaTek in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which devices are affected by Midnight Mimosa?
The malware affects various low-cost Android devices built on MediaTek platforms, including counterfeit models resembling popular brands.
Can users remove the Midnight Mimosa malware?
No, the malware is preinstalled in the firmware and cannot be uninstalled by users.
What should users do if they suspect their device is infected?
Users should consider replacing their device, as there is currently no way to remove the malware.