Skip to content
TECH CEO Daily

Midnight Mimosa malware ships preinstalled on budget Android phones in 150+ countries

Bitdefender says low-cost and counterfeit Android phones carry firmware malware that cannot be uninstalled and can load new code remotely.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Bitdefender found Midnight Mimosa malware preinstalled in firmware of budget Android devices in more than 150 countries.
  • 2It runs with system-level privileges, cannot be uninstalled normally and can install apps and load code remotely.
  • 3Companies should restrict unvetted devices from corporate access and buy from known suppliers.

The news

Romanian security company Bitdefender has detailed a malware family it calls Midnight Mimosa that comes preinstalled in the firmware of budget Android devices, meaning a phone can be compromised before its owner turns it on. The Record reported on the research on October 8, 2026.

According to Bitdefender, as reported by SecurityWeek and The Record, the malware has been seen in more than 150 countries over roughly two years. The highest concentrations are in Mexico, France and Italy, followed by the United States, Germany, Brazil and Spain. Bitdefender observed thousands of unique affected devices. The affected phones are low-cost, white-label and counterfeit models built on MediaTek chip platforms, some designed to imitate Samsung Galaxy and Apple iPhone models, The Record said.

The malware runs with system-level privileges, which let it silently install and remove apps, grant permissions and load code supplied remotely, Bitdefender said in its report, as quoted by SecurityWeek. Because it sits in the firmware as a persistent system app, owners cannot remove it through a normal uninstall. Bitdefender said it was on the phone before the owner switched it on for the first time.

Its main business is fraud. The Record reported that the malware deploys at least 32 disguised apps, posing as weather, note-taking or file-management tools, which display invisible ads to generate fake impressions and clicks and collect device and app information. Bitdefender said infected devices could also be pulled into botnets. SecurityWeek reported that the malware disables the Google Play Store during its own installations to avoid detection by Play Protect, Google's built-in malware scanner.

Bitdefender also found 13 associated apps on the Google Play Store signed with separate certificates, according to both outlets. The firm published a list of indicators of compromise, technical fingerprints that security teams can use to spot infections. Neither outlet reported a response from Google or MediaTek.

The numbers

Countries with affected devices
150+
Observation period
About two years
Disguised apps deployed
At least 32
Related apps found on Google Play
13

Why CEOs should care

For CISOs and IT leaders, the lesson is that a device can be untrustworthy from the factory, so endpoint checks that assume a clean starting point are not enough. Companies with bring-your-own-device (BYOD) programs should ask whether their mobile device management can block unknown or counterfeit models from reaching email, chat and corporate apps, and whether it checks device attestation, a hardware-backed signal that the operating system has not been tampered with.

For procurement and CFOs, cheap hardware has a hidden cost. Buying phones, tablets or rugged handhelds from white-label suppliers to save money can bring firmware nobody in the company has vetted. Ask suppliers for the firmware source and update policy, prefer models in Google's certified device programs, and keep a record of which models are in the fleet so affected batches can be found quickly.

Marketing leaders should note the ad-fraud angle too. Invisible ads and automated clicks from infected devices inflate impressions that advertisers pay for. Ask ad partners how they filter traffic from known fraudulent device populations.

The bigger picture

Preinstalled malware is a supply chain problem that end users cannot fix on their own: a factory reset does not remove code that lives in the firmware. As businesses hand out more low-cost devices for frontline workers, delivery drivers and kiosks, the attack surface extends to manufacturers and resellers the security team may never have heard of. Bitdefender's finding that related apps also reached Google Play shows the same operators work through both the official store and the factory.

What’s next

Watch for responses from Google and MediaTek, any takedown of the 13 Play Store apps, and whether retailers pull affected counterfeit or white-label models from sale.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

BitdefenderAndroidMidnight MimosaMediaTekMobile security

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.