Skip to content
Droid ToolsDroid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/Midnight Mimosa malware comes preinstalled on low-cost MediaTek Android phones
News

Midnight Mimosa malware comes preinstalled on low-cost MediaTek Android phones

Midnight Mimosa malware comes preinstalled on low-cost MediaTek Android phones
Robert Haba
Oct 9, 20263 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →

Bitdefender uncovered Midnight Mimosa, a campaign where low-cost MediaTek-based Android devices ship with malware preinstalled in firmware, used for ad fraud and botnets across 150+ countries. The same ad-fraud code also appeared in 13 Google Play apps, and the malware has been seen briefly disabling the Play Store to dodge Play Protect.

0%
Share on XFacebookBluesky
Follow on Google
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Bitdefender has discovered and analyzed a campaign dubbed Midnight Mimosa, in which malware comes preinstalled in the firmware of low-cost Android devices built on MediaTek platforms. The infection is persistent, runs as a pre-installed firmware system app, and can’t be removed through normal uninstall procedures. Anyone who switches on an affected device finds the malware already present, unseen, and available to any bad actor who can control it remotely through its command-and-control (C2) server.

There’s a large global market for low-cost Android devices, and the attackers behind Midnight Mimosa are servicing that demand with compromised hardware.

midnight mimosa malware

What the malware can do

The potential scale of this kind of C2-controlled infection is substantial. Bitdefender’s report states: “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets.”

Midnight Mimosa focuses on ad fraud, automated click fraud, and turning each device into one small component of a much larger botnet. That makes sense for a campaign trying to stay under the radar with an army of infected devices: many thousands of fraudulent clicks over time would give any bad actor a healthy return on investment, and botnets are described as a hot commodity that can be rented out to other attackers – the bigger the botnet, the bigger the bounty.

Reach and scale

Over the past two years, Bitdefender has observed thousands of unique affected devices across more than 150 countries, with no single country or region dominating distribution. Mexico and France lead, followed by Italy, the US, Germany, Brazil, and Spain, with Western Europe and the Americas standing out regionally. The report doesn’t indicate how much money Midnight Mimosa’s operators have actually made, but it does include an extensive list of indicators of compromise (IoCs) to help prevent further infections.

bitdefender midnight mimosa

Google Play apps and Play Protect evasion

Bitdefender also found 13 apps on Google Play, spread across two developer accounts with separate signing certificates, that contained the same Midnight Mimosa ad-fraud code. As the researchers put it: “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself.” Those Play Store apps don’t have the same privileged access as the preinstalled malware, but they’re considered part of the broader ecosystem, giving attackers an additional distribution channel.

You May Also Like
Recommended
1

Galaxy S27 Ultra display could fix the Privacy Display trade-offs

Galaxy S27 Ultra display could fix the Privacy Display trade-offs
2

WhatsApp’s Restricted Chat blocks linked devices from accessing a conversation

whatsapp restricted chat
3

Pixel Search teardown reveals unfinished Gemini-powered suggestions feature

Pixel Search teardown reveals unfinished Gemini-powered suggestions feature

Whether preinstalled or loaded from Google Play, the malware has been seen disabling the Play Store before installing additional payload applications, then re-enabling it afterward, probably to avoid detection by Play Protect. The researchers note: “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install. The malicious install happens in a window where Google’s scanner is switched off.”

Bitdefender’s researchers describe Midnight Mimosa as best understood as a supply-chain threat, where malware is largely integrated into an Android device before it’s sold. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse, and remote payload management, giving attackers extensive control over affected devices from the very beginning.

Source:Bitdefender
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#android#bitdefender#budget#malware#mediatek#midnight#mimosa
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Next Story in News

Galaxy S27 Ultra display could fix the Privacy Display trade-offs

The Galaxy S27 Ultra display may avoid the compromises that held back its predecessor, according to a PhoneArena opinion piece. The writer cites an industry insider who said during a Q&A session on X (formerly Twitter) that Samsung is going to improve the display quality that suffered on the Galaxy S26 Ultra. What went wrong […]

→

Latest Stories

Galaxy S27 Ultra display could fix the Privacy Display trade-offs01

Galaxy S27 Ultra display could fix the Privacy Display trade-offs

02

Huawei Mate 90 Pro – review – launches in China with a 12,000-nit display and 6600mAh battery

03

Google Messages may remove the SMS/MMS-only toggle for RCS chats

04

WhatsApp’s Restricted Chat blocks linked devices from accessing a conversation

Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Google’s Pixel Referral Program is back with 10% off and Store credit

Deal
Google’s Pixel Referral Program is back with 10% off and Store credit

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare
Recommended stories

Continue reading

More from this category →
Galaxy S27 Ultra display could fix the Privacy Display trade-offs
NewsOct 8, 2026

Galaxy S27 Ultra display could fix the Privacy Display trade-offs

The Galaxy S27 Ultra display may avoid the compromises that held back its predecessor, according to a PhoneArena opinion piece. The writer cites an industry insider who said during a Q&A session on X (formerly Twitter) that Samsung is going to improve the display quality that suffered on the Galaxy S26 Ultra. What went wrong […]

By Robert Haba
whatsapp restricted chat
NewsOct 7, 2026

WhatsApp’s Restricted Chat blocks linked devices from accessing a conversation

WhatsApp is testing a new way to keep selected conversations off a person's linked devices, such as a laptop, tablet, or secondary phone. The company is expanding Advanced Chat Privacy with a new restriction that limits a chat to each participant's primary phone, and renaming the setting to Restricted Chat to make its purpose clearer. […]

By Robert Haba
Pixel Search teardown reveals unfinished Gemini-powered suggestions feature
NewsOct 7, 2026

Pixel Search teardown reveals unfinished Gemini-powered suggestions feature

Google built Pixel Search to save users from digging through their phone to find an app, email, photo, and more, and it now appears to be pushing that idea a step further by trying to figure out what to do with the results it surfaces. An APK teardown of Pixel Search version 1.0.983036833 by Android […]

By Robert Haba
Galaxy 27 series
NewsOct 6, 2026

Exynos 2700 enters mass production, but the Galaxy S27 Ultra’s chip is still undecided

The Exynos 2700 has reportedly entered volume production at Samsung, with output running more than 10% above the Exynos 2600's as the Galaxy S27 Pro joins the lineup. The Galaxy S27, S27+, and Pro are expected to carry the Exynos 2700 in Korea and Europe, with that rollout coming alongside reports that the Galaxy S27 […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.