Cybersecurity researchers have uncovered a malware campaign called Midnight Mimosa that comes preinstalled in the firmware of thousands of low-cost Android devices, potentially exposing users to malicious activity before they even turn on their phones.
According to Bitdefender researchers, the campaign was observed over more than two years across thousands of unique devices in more than 150 countries. Mexico, France, Italy, the United States, and Germany were the five most affected countries.
The malware has been found on some Android devices powered by MediaTek chips, including phones sold under misleading names that make them appear to be premium flagship models. Once active, the malicious component can silently install and uninstall applications, grant permissions, generate fraudulent advertising activity, and execute malicious code.
Researchers also warned that some infected devices could be used as residential proxies, allowing attackers to route internet traffic through victims’ connections as part of a botnet. This could enable malicious activities to appear as though they are coming from ordinary household internet connections.
The investigation also identified 13 malicious apps that had been distributed through Google Play. According to Bitdefender, the preinstalled malware could temporarily disable the Google Play Store, allowing it to install additional malicious applications while attempting to evade Google Play Protect.
Removing the infection can be particularly difficult because the malware is embedded in the device firmware rather than installed like a regular application. Bitdefender said effective cleanup may require firmware-level remediation or disabling the malicious component through Android Debug Bridge (ADB), a technical process that is beyond the capabilities of many ordinary users.
The researchers warned that buying an unusually cheap smartphone can carry additional risks, particularly when a device is advertised as a current-generation flagship at a price that seems too good to be true. Unknown sellers, unclear manufacturer details, and misleading product listings can make it harder for buyers to determine what they are purchasing.
However, the researchers stressed that low-cost Android devices are not inherently unsafe. The greater concern is the possibility of compromised firmware and the lack of transparency surrounding certain manufacturers and sellers.
The campaign has not been attributed to a specific threat actor, and investigators have not established exactly when or how the devices became compromised during manufacturing or distribution.
Some affected firmware was signed using certificates associated with Shenzhen Zediel, which appears to be connected to Zedi Technology, a Chinese company involved in designing smart hardware and motherboards for Rockchip processors. However, researchers have not established whether the company was involved in, or aware of, the malware deployment.
“How these certificates ended up on those phones — and whether the certificate owner was involved in or aware of the malware deployment — remains unclear,” the researchers said.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The discovery follows the BADBOX 2.0 botnet campaign, which was reported to have infected more than one million Android devices worldwide using malware preinstalled on inexpensive, off-brand hardware. The latest findings highlight the continuing security risks associated with compromised Android firmware and devices that reach consumers with malicious software already installed.



