Bitdefender Labs has published research on a malware campaign it calls Midnight Mimosa. The malware is built into the firmware of low-cost Android phones that use MediaTek chips, so it is on the device before the buyer turns it on. Bitdefender says it cannot be uninstalled.

What Bitdefender found

  • Scale: Bitdefender saw the campaign on thousands of unique devices in more than 150 countries over about two years. Mexico, France and Italy led, followed by the United States, Germany, Brazil and Spain.
  • Core: a platform-signed system app, com.android.system.lite, that can silently install and remove apps and grant them permissions.
  • Discovery: Bitdefender Mobile Security's App Anomaly Detection flagged that app for acting like a system component without behaving like one.
  • Money: Bitdefender describes ad fraud and proxyware. Infected phones can become residential-proxy nodes in botnets.
  • Google Play: Bitdefender also found 13 apps on Google Play that talk to the same servers. It says they do not have the rights that make the preinstalled package so powerful.

Genuine or counterfeit

The answer depends on the model. Bitdefender says many affected models are counterfeit devices that borrow flagship names. Its examples include the names "i17 Pro Max" and "S25 Ultra". It points to free-text strings such as "S25 Ultra" and "Note 18 Ultra" that it says a genuine unit would not report, and says the campaign spoofs real model codes on devices that are not Samsung. It says most affected devices are likely visual clones of real phones.

Two of the highest-volume models are different. Bitdefender calls the Doogee S200 X and the Cubot KINGKONG X "genuine, named brands", with model strings associated with each maker. It does not say those units are counterfeit.

Bitdefender saw some firmware signed with certificates bearing the name Shenzhen Zediel. It says this does not show the company made the malware or knew about it.

Where the phones were sold

Bitdefender says counterfeit flagship devices are offered on a mainstream marketplace. It does not name that marketplace, and this article does not name one either. It says the counterfeit and budget names point to an ODM ecosystem sold globally through online marketplaces.

How to check your phone

Bitdefender's research gives no step-by-step check for owners. It lists the package names to look for: com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot and com.android.sys.bcprot.

Google's Play Protect help page gives one step to confirm the scanner is on. Open the Google Play Store app, tap your profile icon, tap Play Protect, then Settings, and check that "Scan apps with Play Protect" is on. Google recommends keeping it on.

Play Protect is not a full answer here. Bitdefender says the malware disables the Play Store around some installs, which removes the scanner for those installs.

If you find it

Bitdefender says uninstalling is not the fix. "Clearing the device requires firmware-level cleanup or disabling the component over ADB, and neither is realistic for most people who own these phones." It says the durable fix sits with the vendors and marketplaces that ship and sell the firmware.

What is not known

  • Who put the malware in the firmware, and at which stage. Bitdefender says this is unclear.
  • Whether the Shenzhen Zediel certificate holder was involved. Bitdefender says it is unclear.
  • Which marketplace sells the affected phones. Bitdefender does not name one.
  • Google's response. PCMag reports that Google did not immediately respond to its request for comment, and that Zedi did not immediately respond either.

Why it matters

Preinstalled malware skips the usual checks. Bitdefender writes that every user-facing defense assumes the owner is in the loop at installation. A platform-signed system app removes the owner from that loop, which means the buyer may never have a chance to see it.