Some bargain Android phones come with a gift nobody asked for: malware installed before the box is even opened.
Security researchers at Bitdefender have uncovered Midnight Mimosa, an ad-fraud operation affecting low-cost Android devices built on MediaTek platforms. According to the researchers, malicious components embedded in device firmware can operate with elevated privileges, making them difficult for owners to detect or remove.
“It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled,” Bitdefender said in its report.
The researchers reported infections across thousands of devices in more than 150 countries over roughly two years. The findings raise concerns about the security of devices that may be compromised before consumers ever use them.
Invisible ads pay the operators
Midnight Mimosa makes money by secretly installing seemingly ordinary applications, including weather tools, app lockers, note-taking utilities and image-text recognition apps.
These applications use legitimate advertising software to load real ads, but the malware can display them in invisible windows and register fraudulent impressions and clicks. Bitdefender identified at least 32 disguised applications associated with the operation.
Bitdefender also observed the malware temporarily disabling the Google Play Store before installing certain payloads and restoring it afterward. The researchers suggested this behavior could help interfere with Google's app-scanning protections, although the precise effect on Play Protect should not be assumed without further evidence.
Beyond advertising fraud, some components can turn infected phones into residential proxies, routing outside traffic through victims' internet connections. That could help operators conceal the origins of malicious activity or use compromised devices in larger botnets.
Some components can also register infected devices with residential proxy infrastructure, potentially allowing outside traffic to be routed through victims' internet connections. Bitdefender confirmed that the infrastructure accepted device registrations, but its tests did not establish that newly registered devices were actively relaying traffic.
Google Play apps add another route
The threat is not limited to phones infected during manufacturing. Bitdefender found 13 applications on Google Play that communicated with the same infrastructure and contained related advertising-fraud code.
Those apps offer genuine functionality, but can also display advertisements outside their interfaces, including when users are not actively using them. Unlike the firmware-level component, they lack the elevated privileges needed to silently install other applications.
Bitdefender has not established who introduced Midnight Mimosa into affected firmware. Some devices used firmware signed with certificates bearing the name of Shenzhen Zediel, but the researchers said this does not prove the company created, knowingly distributed or knew about the malware.
Cheap hardware, expensive consequences
The campaign exposes a weakness in the usual advice to avoid suspicious downloads and stick to official app stores. Neither precaution can protect buyers from malware already embedded in a phone's operating system.
Ultra-cheap devices and counterfeit handsets imitating popular Samsung and Apple models are among those identified in the research. When hardware passes through multiple manufacturers, firmware integrators and distributors, identifying who introduced malicious code can also become difficult.
For device makers and retailers, the findings raise questions about firmware verification and accountability throughout the supply chain. A phone can appear functional and arrive with familiar apps while carrying hidden software that benefits someone other than its owner.
What users can do if their phone is affected
Owners cannot reliably remove Midnight Mimosa through the normal uninstall process because its core component resides in the system partition. Bitdefender says remediation may require firmware-level cleanup or disabling the component through Android Debug Bridge (ADB), a technical procedure unsuitable for many users.
Buyers should be wary of suspiciously cheap phones advertised with flagship specifications, especially counterfeit models purchased through unfamiliar sellers. Buying from authorized retailers and checking a device's exact model and software support can reduce exposure, although neither guarantees that its firmware is clean.
If a device repeatedly installs unwanted apps or displays unexplained advertisements, contact the manufacturer or seller and consider seeking help from a reputable mobile security specialist. Users who suspect a serious compromise should avoid entering sensitive information until the device has been assessed.
The larger challenge is that consumers may have little way of detecting malware installed before purchase. Preventing these infections ultimately depends on stronger firmware security and oversight across the device supply chain.
Other news: A new authentication report found that 43% of cybersecurity professionals still use passwords at work, despite 87% being familiar with passkeys.





