Android Phones Found With Malware Already Installed Before Purchase

Bitdefender uncovered Midnight Mimosa malware preinstalled on low-cost Android phones, enabling hidden ad fraud and raising device supply-chain security concerns.

Oct 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Some bargain Android phones come with a gift nobody asked for: malware installed before the box is even opened.

Security researchers at Bitdefender have uncovered Midnight Mimosa, an ad-fraud operation affecting low-cost Android devices built on MediaTek platforms. According to the researchers, malicious components embedded in device firmware can operate with elevated privileges, making them difficult for owners to detect or remove.

“It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled,” Bitdefender said in its report.

The researchers reported infections across thousands of devices in more than 150 countries over roughly two years. The findings raise concerns about the security of devices that may be compromised before consumers ever use them.

Invisible ads pay the operators

Midnight Mimosa makes money by secretly installing seemingly ordinary applications, including weather tools, app lockers, note-taking utilities and image-text recognition apps.

These applications use legitimate advertising software to load real ads, but the malware can display them in invisible windows and register fraudulent impressions and clicks. Bitdefender identified at least 32 disguised applications associated with the operation.

Bitdefender also observed the malware temporarily disabling the Google Play Store before installing certain payloads and restoring it afterward. The researchers suggested this behavior could help interfere with Google's app-scanning protections, although the precise effect on Play Protect should not be assumed without further evidence.

Beyond advertising fraud, some components can turn infected phones into residential proxies, routing outside traffic through victims' internet connections. That could help operators conceal the origins of malicious activity or use compromised devices in larger botnets. 

Some components can also register infected devices with residential proxy infrastructure, potentially allowing outside traffic to be routed through victims' internet connections. Bitdefender confirmed that the infrastructure accepted device registrations, but its tests did not establish that newly registered devices were actively relaying traffic.

Advertisement

Google Play apps add another route

The threat is not limited to phones infected during manufacturing. Bitdefender found 13 applications on Google Play that communicated with the same infrastructure and contained related advertising-fraud code.

Those apps offer genuine functionality, but can also display advertisements outside their interfaces, including when users are not actively using them. Unlike the firmware-level component, they lack the elevated privileges needed to silently install other applications.

Bitdefender has not established who introduced Midnight Mimosa into affected firmware. Some devices used firmware signed with certificates bearing the name of Shenzhen Zediel, but the researchers said this does not prove the company created, knowingly distributed or knew about the malware.

Cheap hardware, expensive consequences

The campaign exposes a weakness in the usual advice to avoid suspicious downloads and stick to official app stores. Neither precaution can protect buyers from malware already embedded in a phone's operating system.

Ultra-cheap devices and counterfeit handsets imitating popular Samsung and Apple models are among those identified in the research. When hardware passes through multiple manufacturers, firmware integrators and distributors, identifying who introduced malicious code can also become difficult.

For device makers and retailers, the findings raise questions about firmware verification and accountability throughout the supply chain. A phone can appear functional and arrive with familiar apps while carrying hidden software that benefits someone other than its owner.

Advertisement

What users can do if their phone is affected

Owners cannot reliably remove Midnight Mimosa through the normal uninstall process because its core component resides in the system partition. Bitdefender says remediation may require firmware-level cleanup or disabling the component through Android Debug Bridge (ADB), a technical procedure unsuitable for many users.

Buyers should be wary of suspiciously cheap phones advertised with flagship specifications, especially counterfeit models purchased through unfamiliar sellers. Buying from authorized retailers and checking a device's exact model and software support can reduce exposure, although neither guarantees that its firmware is clean.

If a device repeatedly installs unwanted apps or displays unexplained advertisements, contact the manufacturer or seller and consider seeking help from a reputable mobile security specialist. Users who suspect a serious compromise should avoid entering sensitive information until the device has been assessed.

The larger challenge is that consumers may have little way of detecting malware installed before purchase. Preventing these infections ultimately depends on stronger firmware security and oversight across the device supply chain.

Other news: A new authentication report found that 43% of cybersecurity professionals still use passwords at work, despite 87% being familiar with passkeys.

Aminu Abdullahi

Aminu Abdullahi

Content Writer

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. His work has appeared in publications including TechRepublic, eWEEK, Channel Insider, Geekflare, Enterprise Networking Planet, eSecurity Planet, CIO Insight, and Webopedia. With a technical background in computer science, he specializes in translating complex technology topics into clear, accessible content for business leaders and decision-makers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.