Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on.

Listen to this article

0:00 —

Press play to start listening

Bitdefender researchers uncover Midnight Mimosa malware preinstalled on low-cost MediaTek Android phones enabling ad fraud and proxyware activity.

Cybersecurity researchers at Bitdefender have identified a campaign dubbed Midnight Mimosa affecting multiple low-cost Android phone brands built on MediaTek platforms, allowing operators to install apps, grant permissions and load code without the owner’s consent.

The infection happens below the normal app-installation layer. In its research shared with Hackread.com, Bitdefender notes that “every user-facing defense had already been bypassed” by the time the phone was switched on.

Midnight Mimosa Malware Found Preinstalled on Android Phones
Example online listing for a low-cost “S25 Ultra” Android phone. Researchers found Midnight Mimosa on counterfeit and budget Android devices, including phones using similar reported names (Source: Bitdefender)

Malware Hidden as a System Component

The malware hides in system packages such as com.android.system.lite and com.android.sys.prot. Because they run with Android system privileges, users cannot normally remove them.

A native library called libeasy.so decrypts another component and connects to api.weatherlive.world to download more code. The malware can then install or remove apps without asking the user and give those apps additional permissions.

Bitdefender also found Accessibility and Notification Access being turned on and off automatically, but did not see the malware use either feature for malicious activity.

The main activity observed was not data theft but monetization. The malware uses ad fraud and proxyware, while its privileged access gives operators a way to change or expand the payloads later.

For context, proxyware turns a device’s internet connection into a relay for other traffic, often making that traffic appear to come from the infected user’s IP address.

Play Protect Evasion and Hidden Ad Fraud

Before installing a payload, the malware temporarily disables the Google Play Store package, com.android.vending, and restores it afterward. Bitdefender assessed that this may create a window for payload installation while avoiding normal Play Protect checks.

The malware can also make a sideloaded app appear to have been installed from Google Play, even though it lacks the cryptographic “frosting” marker found on genuine Play apps. Bitdefender found payloads such as com.mobile.applock.en, which uses EnLoaderLib v1.0.6 and connects to a proxy network over TCP port 6000. Another payload, com.mobile.applock.wt, contains an ad-fraud module.

The malware also installs apps for functions such as weather, AppLock, notes and OCR. These apps use legitimate advertising SDKs, but the malware can run ads in the background and generate fake impressions and clicks without the user seeing them.

Thousands of Devices in 150+ Countries

Bitdefender observed thousands of infected devices in more than 150 countries. Affected hardware included counterfeit phones reporting names such as “S25 Ultra” and “i17 Pro Max,” along with budget models including the Doogee S200 X and Cubot KINGKONG X.

Midnight Mimosa Malware Found Preinstalled on Android Phones
Bitdefender’s country distribution chart for infected Midnight Mimosa devices over a two-year window. Mexico, France, Italy and the United States were among the most affected countries (Source: Bitdefender)

The same adfraud code was also found in 13 Google Play apps, showing that the operation was not limited to preinstalled firmware.

A platform certificate used by com.android.system.lite was associated with Shenzhen Zediel Co., Ltd. However, Bitdefender said this does not prove the company inserted or knowingly distributed the malware. The point where the malware entered the supply chain remains unknown.

For buyers, the problem is that a normal factory reset or uninstall may not be enough. Midnight Mimosa sits in system-level firmware, so affected devices may require trusted firmware replacement, vendor remediation or replacement of the phone itself.

(Featured Photo by Andrey Matveev on Pexels)

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts