Midnight Mimosa: preinstalled Android malware in 150 countries
firmware system app on cheap MediaTek Android phones

Midnight Mimosa: preinstalled Android malware in 150 countries

Bitdefender has documented a firmware malware campaign it calls Midnight Mimosa. The code is already on the phone before the owner powers it on, and a normal uninstall does not remove it.

What happened

The malware is a platform-signed system app on low-cost, multi-brand Android devices built on MediaTek chipsets. Package names rotate. One early sample was com.android.system.lite, labeled System, with no launcher icon. The same core has shipped as com.android.sys.prot, com.android.sys.gmsprot, and com.android.sys.bcprot.

It can silently install and remove apps, grant permissions, and load code from a remote server. The money side is hidden ad fraud and click fraud, plus use of the phone as a residential proxy node. Over about two years Bitdefender has seen thousands of unique devices in more than 150 countries. Mexico and France lead, followed by Italy, the United States, Germany, Brazil, and Spain.

Bitdefender also found 13 Google Play apps, under at least two developer accounts, carrying the same ad-fraud code. Those Play apps do not have the firmware app's privileges, but they talk to the same control servers. Where in the supply chain the firmware copy is inserted is still not established.

Who is affected

Buyers of very cheap Android handsets, including counterfeit flagship lookalikes whose reported model strings do not match the hardware. A factory reset will not clear a ROM implant.

  • Staff phones bought outside normal procurement, site spares, and handsets issued by a vendor are the practical risk.
  • South Africa is not in the published top detection list. That does not make a grey-market handset safe.
  • Play Store copies are a second path, with less privilege than the preinstalled system app.

What to do now

Do not enroll a no-name or counterfeit Android handset into company email, VPN, or operational-technology remote access. Replace it.

  • If a handset is already in use and you cannot prove the firmware, remove corporate accounts and treat the device as untrusted.
  • On managed phones, check for system packages named com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot, and com.android.sys.bcprot.
  • A factory reset is not a cleanup. The implant is in the firmware image.

Source: Bitdefender, The phone was compromised before the user turned it on: the rise of Midnight Mimosa.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9
command injection on the primary domain controller emulator