Bitdefender finds 'Midnight Mimosa' firmware malware on budget Android phones
Security researchers at Bitdefender say firmware on low-cost Android devices using MediaTek chipsets has been shipping with malware that grants system-level control, enabling silent app installs, ad fraud, and turning phones into residential proxies. The campaign has affected thousands of devices across more than 150 countries over roughly two years, hitting models from Doogee and Cubot as well as phones impersonating Samsung and Apple products.
GoKawiil's interpretation of the reporting above, not reported fact.
Because the malware is embedded at the firmware level with system privileges, it can survive factory resets and reappear even after official updates, as one Doogee Fire 3 Max owner described experiencing. The unresolved question of how tampering entered the supply chain raises broader concerns about trust in low-cost device manufacturing and distribution, according to Bitdefender's findings and user reports on XDA forums.
- Malware dubbed 'Midnight Mimosa' was found embedded in firmware of budget MediaTek-based Android phones.
- Thousands of devices in over 150 countries were affected, with Mexico, France and Italy among the hardest hit.
- It remains unclear who introduced the malware into the supply chain or at what stage it occurred.
Samsung Galaxy A15 Unlocked Smartphone — If you're shopping for a budget Android phone, steer clear of obscure low-cost brands with murky supply chains and opt for a reputable manufacturer instead. The Samsung Galaxy A15 offers solid everyday performance with the trust of official software updates and security patches, avoiding the risks highlighted in this malware campaign.
See Samsung Galaxy A15 Unlocked Smartphone on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-08
Published there as: “Low-cost Android phones ship with residential proxy malware”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.