Tidavo
Latest
Others

Further sections will be listed here.

Bitdefender uncovers uninstallable Android malware on cheap phones

Security researchers have identified a persistent threat hidden in device firmware across many countries.

11 Oct 2026

#Bitdefender #Android #Midnight Mimosa #MediaTek #Shenzhen Zediel #Google Play

Bitdefender found a campaign called Midnight Mimosa involving preinstalled Android malware. The security firm discovered it on low-cost phones that use MediaTek platforms. This malware is built into the device firmware before the owner turns on the phone for the first time. It cannot be removed by standard uninstall methods.

The infection has appeared in more than 150 countries over roughly two years. Top locations included Mexico, France and Italy, followed by the United States and Germany. Thousands of unique devices were affected globally during this period.

The malware holds system-level privileges that allow it to install and remove apps without permission. It can grant sensitive permissions like Accessibility and Notification Access silently. This gives its operators full control over the infected devices for various purposes.

Experts believe the scheme is mainly designed to generate revenue through malicious means. Operators conduct ad and click fraud while collecting device information from the phones. They also turn the infected devices into residential-proxy relay nodes for botnets.

Bitdefender spotted this threat through behavior rather than a known signature file. A tool called App Anomaly Detection flagged a package named com.android.system.lite as suspicious. It looked like a core system component but acted in ways standard software does not.

The system component drops cover apps onto the phone to hide its activity. These include tools that look like weather forecasts or app lockers loaded with real ads. An invisible window registers clicks while the user sees a legitimate application.

A native library decrypts a hidden framework which fetches code from a remote server. This setup allows the malware to update itself with new payloads without notice. Files often use misleading extensions like .o or .png to avoid detection during offline analysis.

Many affected devices are counterfeit models that borrow names from flagship brands. Examples include fake versions of iPhone Pro Max and Samsung Ultra series devices. The two most common real models were budget phones from Doogee and Cubot.

Firmware on some phones uses certificates signed by a group linked to Shenzhen Zediel. Researchers confirmed these certificates were used but could not establish how the malware got there. Other infected phones likely had the code added by manufacturers or logistics partners.

Bitdefender linked this infrastructure to older malware families dating back to 2021. Clearing an infected phone is not possible for a standard owner because the root component sits in the system partition. The durable fix requires firmware-level cleanup or actions by vendors and marketplaces.

Security Affairs