Midnight Mimosa: cheap Android phones ship ad-fraud malware

Midnight Mimosa: cheap Android phones ship ad-fraud malware

Thousands of low-cost Android phones sold around the world reached their owners with ad-fraud malware already baked into the firmware, according to Bitdefender. The Romania-based security firm calls the campaign Midnight Mimosa.

The affected devices come from several brands and all run on chips from MediaTek, the Taiwanese semiconductor company. Bitdefender says the malware is present before the buyer turns the phone on for the first time, and it cannot be removed.

"The malware ships preinstalled in the device firmware," the company said in a report published Thursday. "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled."

A system app with full control

The core of the operation is a malicious Android app placed in the firmware before the phones are sold. Because it runs with system-level privileges, it can quietly install and uninstall other apps, grant them permissions, and fetch and execute extra code. The owner is never asked for approval.

Bitdefender says the main goal appears to be making money through advertising and click fraud. The malware can also gather details about the device and the apps installed on it. Researchers note that it has capabilities that could let attackers pull infected phones into botnets.

Over about two years, the firm detected the malware on thousands of devices in more than 150 countries. Mexico, France and Italy had the largest shares of detections. The United States, Germany, Brazil and Spain came next.

Many of the phones appear to be cheap white-label or counterfeit models, including some built to look like Samsung Galaxy phones and Apple iPhones. They are sold through mainstream online marketplaces. One device the researchers examined cost about $180.

Invisible ads and fake utilities

The preinstalled app does not produce fake ad views on its own. Instead, it silently installs other apps that look harmless, posing as weather tools, note-taking apps, app lockers, file managers and similar utilities.

These apps pull real ads from legitimate advertising services. They can then show them in invisible windows layered over other apps, so ad impressions are recorded even though the user never sees anything. Some components can also produce automated clicks.

Bitdefender counted at least 32 disguised apps pushed by the preinstalled malware. Before installing some of them, the malware switches off the Google Play Store, likely to avoid detection, and turns it back on when the installation is done.

The researchers also found 13 apps on Google Play that talked to the same infrastructure and carried the same ad-fraud code. These apps lack system privileges and do offer real features, such as weather forecasts or QR-code scanning. However, they could also show ads outside the app, including at times when the phone was not in active use.

Unclear origin

Bitdefender has not identified who planted the malware or at which point in the supply chain it was added.

Some of the affected firmware was signed with certificates carrying the name of Shenzhen Zediel, a Chinese company that develops and sells smart hardware and consumer electronics. Bitdefender stressed that the certificates do not show the company built the malware, knowingly distributed it or knew it was there.

According to the researchers, the code could have been inserted by an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before the phones went on sale.

"The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones," the researchers said. "One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards."

Our Take

Midnight Mimosa shows that the price tag of a phone can hide a business model. When malware sits in the firmware with system privileges, the usual advice - install apps only from trusted stores, keep the device patched - offers limited protection. Even the monthly fixes Google ships, such as the Android October 2026 update, depend on vendors that may be part of the problem. Features like Android 17 Advanced Protection also assume the base system can be trusted.

For readers, the practical lesson is to treat unusually cheap look-alike phones from marketplaces with suspicion, especially in corporate settings. The botnet capabilities suggest the risk may go beyond ad fraud. It is worth watching whether marketplaces and Google act on these findings, and whether the source in the supply chain is ever identified.