A global malware campaign has been discovered infecting budget Android devices in over 150 countries, with thousands of unique affected devices spotted over the past two years. Dubbed “Midnight Mimosa” by researchers at Bitdefender, this pre-baked firmware malware is designed to fly under the radar while generating a significant return on investment for its operators.
The malware, which is present and active as soon as an infected device is turned on, has been observed granting system-level privileges to its operators. This allows them to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. In other words, the attackers have extensive control over affected devices from the get-go.
The primary purpose of Midnight Mimosa is ad fraud and automated click fraud, with infected devices being turned into part of a larger botnet. This type of operation can be rented out to other bad actors, making it a lucrative business for those behind the campaign. The researchers have observed that many thousands of click frauds over an extended period would provide a significant return on investment for the attackers.
Bitdefender’s analysis has revealed that the malware is preinstalled in devices built on MediaTek platforms, which are commonly used for low-cost Android devices. However, the campaign is not limited to preinstalled firmware alone. Thirteen apps published on Google Play were found carrying the same family markers as the dropped cover apps, indicating an additional distribution channel.
The infected apps, while not having the same privileged access as the preinstalled malware, are considered associated with the broader ecosystem and provide attackers with another means of spreading their malicious payload. What’s more, the malware has been observed disabling the Play Store before installing additional payload applications and then re-enabling it afterward – likely to avoid detection by Google’s scanner.
The discovery of Midnight Mimosa highlights the growing concern of supply-chain threats in the Android ecosystem. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse, and remote payload management. As such, device manufacturers and users must be vigilant in monitoring their devices for any suspicious activity.
To prevent falling victim to this type of attack, it’s essential to remain cautious when installing apps from unknown sources and to regularly update your operating system and security software. Additionally, being aware of the potential risks associated with low-cost Android devices can help you make informed purchasing decisions. By staying informed and taking proactive measures, we can reduce our vulnerability to such attacks and maintain a safer digital environment.
Source: SecurityWeek — 2026-10-09