SecurityWidely confirmed5 publishers3 min readPublished Updated
Cheap MediaTek-based Android phones reach buyers with ad-fraud malware already in the firmware
Bitdefender found ad-fraud malware preinstalled in the firmware of thousands of cheap MediaTek-based Android phones in more than 150 countries. The implant cannot be uninstalled, so the point of purchase is where a buyer can keep it out.
The Watch · Security desk

What happened
- The firmware app runs with system-level privileges and can silently install or remove apps, grant them permissions, and download and run new code without the owner's approval.
- Before installing some of its payloads, the malware switches off the Google Play Store and turns it back on once the install is finished.
- Bitdefender also found 13 apps on Google Play that talked to the same infrastructure and carried the same ad-fraud code.
- Many affected phones are low-cost white-label or counterfeit models, some made to resemble Samsung Galaxy phones and iPhones, sold on mainstream marketplaces; one cost about $180.
- The insertion point is still unknown: Bitdefender has not determined who placed the malware or where in the supply chain it entered.
Why it matters
- decision Companies that let staff and contractors work from self-bought Android phones have to decide whether to restrict which models and sellers are allowed, since this implant is running before any store-side check.
- exposure On a work phone, the installed-app inventory the malware collects would include whatever corporate tools the owner added, before the operator pushes anything new.
- constraint With the insertion point unknown and the signing certificates not proof of authorship, procurement teams cannot block a single supplier by name.
No exploit is involved, because the access ships with the hardware [2]. "The malware ships preinstalled in the device firmware," Bitdefender said in a report released Thursday. "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled." [2]
For now that access is spent on advertising [3]. The firmware app does not produce fraudulent ad views itself [14]. It plants apps posing as weather, note-taking, app-lock and file-management utilities [14]. Those apps load real ads from legitimate ad services into invisible windows over other applications, registering impressions the owner never sees [15]. Some components also generate automated clicks [15]. Separately, the malware collects information about the device and its installed apps, and Bitdefender found capabilities that could pull infected phones into botnets [3]. Because the firmware app can download and run additional code without approval, the operator decides what an infected phone does next [4].
App-store scanning arrives too late to catch this [2][6]. Bitdefender counted at least 32 disguised payload apps [16], and it said the Play Store shutdown during some installs is potentially meant to evade detection [6]. The store is also a second channel for the same operation. The 13 Play apps tied to its infrastructure [7] lack system privileges and offer real functions such as weather or QR-code scanning [9]. They could still show ads outside the apps, the researchers said, including when the owner was not using the phone [9].
Midnight Mimosa, as Bitdefender named the campaign, is a sustained operation [1]. Bitdefender tracked it for roughly two years; the biggest shares of detected devices were in Mexico, France and Italy, with the United States, Germany, Brazil and Spain next [5]. The researchers stated the business model themselves. "The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones," they said. "One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards." [17]
The common hardware across the affected brands is a MediaTek chip [8]. The insertion points Bitdefender named as possible sit later in the chain: an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before sale [12]. Certificates used to sign some of the affected firmware carry the name of Shenzhen Zediel, a Chinese maker and seller of smart hardware and consumer electronics [11]. According to Bitdefender, those certificates are not proof that the company built the malware, distributed it knowingly or was aware of it [11]. The evidence ties the implant to the low-cost, white-label and counterfeit tier of the market [13]. It does not show that MediaTek-based phones as a group are compromised [8][12].
What to watch
- A named insertion point, such as a specific manufacturer, firmware integrator or logistics partner, would let buyers screen by supplier instead of by whole device tier.
- Any sign the operator uses the download-and-run capability to push botnet components or collection beyond device and app inventories.
- Whether Google pulls the 13 Play apps and whether the marketplaces selling the Galaxy and iPhone lookalikes delist them.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption25
- Hype gap+15
- Incentives35
- Confidence60
Perspective Coverage
5 publishers- Builder
- Builder 27%
- Operator
- Operator 55%
- Investor
- Investor 18%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Romania-based Bitdefender found malware preinstalled on thousands of cheap Android phones that can generate fraudulent ad revenue and potentially turn infected devices into parts of botnets; it dubbed the campaign Midnight Mimosa.
ReportedSupportedSource: Bitdefender, via The Record4 sources— create a free account to open themView cited source - [2]
"The malware ships preinstalled in the device firmware," Bitdefender said in a report released Thursday. "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled."
ReportedSupportedSource: Bitdefender report, quoted by The Record4 sources— create a free account to open themView cited source - [3]
The campaign appears primarily designed to make money through advertising and click fraud; the malware can also collect information about devices and installed apps and has capabilities that could allow infected phones to be incorporated into botnets.
ReportedSupportedSource: Bitdefender researchers, via The Record4 sources— create a free account to open themView cited source - [4]
The malicious app built into the firmware runs with system-level privileges, allowing it to silently install or remove other applications, grant them permissions, and download and run additional code without the owner's approval.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [5]
Over roughly two years, Bitdefender observed the malware on thousands of devices across more than 150 countries; Mexico, France and Italy accounted for the largest shares of detected devices, followed by the United States, Germany, Brazil and Spain.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [6]
Before installing some payloads, the malware temporarily disables the Google Play Store, potentially to evade detection, and turns it back on after the installation is complete.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [7]
Bitdefender found 13 apps available through Google Play that communicated with the same infrastructure and contained the same ad-fraud code.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [8]
The campaign affects devices from multiple brands sold worldwide that use chips made by Taiwanese semiconductor company MediaTek.
ReportedSupportedSource: Bitdefender, via The Record2 sources— create a free account to open themView cited source - [9]
The Play Store apps do not have powerful system privileges and provide genuine functions such as weather information or QR-code scanning, but researchers said they could display ads outside the apps, including when a user was not actively using the phone.
ReportedSupportedSource: Bitdefender researchers, via The Record3 sources— create a free account to open themView cited source - [10]
Bitdefender has not determined who placed the malware on the devices or where in the supply chain it was introduced.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [11]
Some affected firmware was signed with certificates bearing the name of Shenzhen Zediel, a Chinese company that develops and sells smart hardware and consumer electronics; Bitdefender said the certificates do not establish that the company created the malware, knowingly distributed it or was aware of its presence.
ReportedSupportedSource: Bitdefender, via The Record3 sources— create a free account to open themView cited source - [12]
Researchers said the malicious software could have been introduced by an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before the phones were sold.
ReportedSupportedSource: Bitdefender researchers, via The Record3 sources— create a free account to open themView cited source - [13]
Many affected phones appear to be low-cost, white-label or counterfeit devices, including models designed to resemble Samsung Galaxy phones and Apple iPhones, sold through mainstream online marketplaces; one examined device cost about $180.
ReportedSupportedSource: Bitdefender researchers, via The Record2 sources— create a free account to open themView cited source - [14]
The preinstalled malware does not generate fraudulent ad views itself; it secretly installs seemingly legitimate applications disguised as weather, note-taking, app-lock, file-management and other utilities.
ReportedSupportedSource: Bitdefender, via The Record2 sources— create a free account to open themView cited source - [15]
The disguised apps use legitimate advertising services to load real ads but can display them in invisible windows over other applications, registering impressions users never see; some components can also generate automated clicks.
ReportedSupportedSource: Bitdefender, via The Record2 sources— create a free account to open themView cited source - [16]
Researchers identified at least 32 disguised applications deployed by the preinstalled malware.
ReportedSupportedSource: Bitdefender, via The Record2 sources— create a free account to open themView cited source - [17]
"The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones," the researchers said. "One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards."
ReportedSupportedSource: Bitdefender researchers, quoted by The Record2 sources— create a free account to open themView cited source
Sources
5 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comLow-cost Android phones ship with residential proxy malware
1 article · October 8, 2026
- dev.toMidnight Mimosa: Malware Preinstalled in Android Firmware for Ad Fraud and Residential Proxying
1 article · October 8, 2026
- scworld.comMalware preinstalled on cheap Android phones generates ad fraud
1 article · October 9, 2026
- securityweek.comPre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
1 article · October 9, 2026
- therecord.mediaThousands of cheap Android phones shipped with ad-fraud malware
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Android MalwareFollow
- Residential Proxies & Geo-TargetingFollow
- Ad FraudFollow
- Software supply chain attacksFollow
Entities
- MediaTekFollow
- Midnight MimosaFollow
- Google PlayFollow
- BitdefenderFollow
- CUBOTFollow
- DoogeeFollow
- Shenzhen ZedielFollow