Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Preinstalled Android Malware on Cheap MediaTek Phones Spotted: A Growing Concern for Mobile Security



Bitdefender has discovered a new campaign of preinstalled Android malware on cheap MediaTek phones, dubbed "Midnight Mimosa." The malware affects thousands of unique devices in 150 countries, generating revenue through ad and click fraud and turning infected devices into residential-proxy relay nodes. The campaign relies on Google Play to target Android users, and the malware's infrastructure has been linked to other malicious activities. As users cannot rely on app store checks or uninstalling the malware, it is essential to take immediate action to secure firmware and be aware of the risks associated with preinstalled malware.

  • Bitdefender has discovered a widespread campaign of preinstalled Android malware on cheap MediaTek phones.
  • The malware, dubbed "Midnight Mimosa," has been spotted in 150 countries and affects thousands of unique devices.
  • The malware is built into the device firmware and cannot be removed by the user.
  • The malware has system-level privileges, allowing it to install and remove apps, grant permissions, and download code without user knowledge.
  • The malware generates revenue through ad and click fraud, as well as by turning infected devices into residential-proxy relay nodes.
  • The affected phones often have fake models and are sold by budget brands such as Doogee and Cubot.
  • Clearing an infected phone is not possible through simple uninstallation, and requires firmware-level cleanup or disabling the component over ADB.



  • Bitdefender, a renowned cybersecurity firm, has recently discovered a concerning campaign of preinstalled Android malware on cheap MediaTek phones. The malware, dubbed "Midnight Mimosa," has been spotted in 150 countries, affecting thousands of unique devices over the past two years.

    The malware is built into the device firmware and cannot be removed by the user, making it a significant threat to mobile security. It has system-level privileges, allowing it to install and remove apps, grant permissions, and download code from a remote server without the user's knowledge. This gives its operators control over the infected devices, which can be used for various purposes, including building a large botnet.

    The malware is designed to generate revenue through ad and click fraud, as well as by turning infected devices into residential-proxy relay nodes. It can silently install at least 32 different apps disguised as useful tools, including app lockers, weather apps, file managers, icon tools, OCR tools, and audio editors. It also gives itself access to Android's Accessibility, Notification Access, and SMS read/write features.

    The malware's infrastructure has been linked to the Dr.Web's Android.Joker family and its Android.Phantom and Click families, which have been associated with other malicious activities. The campaign relies on Google Play to target Android users, with 13 apps published there talking to the same servers, under at least two developer accounts and 13 different signing certificates.

    The affected phones often have fake models, and some use fake codes that make them look like real Samsung devices. The two most common models are from budget brands: Doogee's S200 X and Cubot's KINGKONG X. The activity has a longer history, and the malware's core code and command server have been detected through shared domains.

    Clearing an infected phone isn't something an owner can do by uninstalling, as the root component sits in the system partition. It takes firmware-level cleanup or disabling the component over ADB, and neither is realistic for most people who own these phones. The durable fix sits with the vendors and marketplaces that ship and sell the affected firmware.

    Bitdefender considers preinstalled malware a separate category of threat, as users cannot rely on app store checks or simply uninstalling the malware. The cybersecurity firm emphasizes the importance of firmware-level cleanup or disabling the component over ADB to prevent the malware from causing further damage.

    In conclusion, the discovery of the Midnight Mimosa malware campaign highlights the growing concern for mobile security. The fact that the malware is preinstalled on cheap MediaTek phones, which are often sold without proper security measures, makes it a significant threat to users. It is essential for vendors and marketplaces to take immediate action to secure their firmware and for users to be aware of the risks associated with preinstalled malware.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Preinstalled-Android-Malware-on-Cheap-MediaTek-Phones-Spotted-A-Growing-Concern-for-Mobile-Security-ehn.shtml

  • https://securityaffairs.com/200759/malware/bitdefender-finds-preinstalled-android-malware-you-cant-uninstall-seen-in-150-countries.html


  • Published: Sun Oct 11 11:28:02 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us