Androidheadlines Malware Preinstalled on Thousands of Cheap Android Phones
Article Content
- •Midnight Mimosa malware is preinstalled on low-cost Android devices, making it unremovable.
- •The malware generates revenue through ad fraud and can turn devices into botnets.
- •Thousands of affected devices have been identified across over 150 countries.
Bitdefender has identified a malware campaign named Midnight Mimosa affecting low-cost Android phones built on MediaTek platforms. The malware is preinstalled in the firmware, granting it system-level access to install and remove applications without user consent. It primarily generates revenue through ad fraud and can turn infected devices into botnets. The malware has been observed on thousands of devices across over 150 countries, with significant detections in Mexico, France, and Italy. Notably, the malware can disable the Google Play Store temporarily to evade detection during payload installation. Researchers found at least 32 disguised applications associated with the malware, which utilize legitimate advertising services to generate fake ad impressions. The campaign raises concerns about the security of low-cost smartphones, especially counterfeit devices resembling popular brands. Currently, the malware cannot be uninstalled by users, leaving them vulnerable.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track MediaTek in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected by Midnight Mimosa?
Can users remove the Midnight Mimosa malware?
What should users do if they suspect their device is infected?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…