Skip to content

SecurityWidely confirmed5 publishers3 min readPublished Updated

Cheap MediaTek-based Android phones reach buyers with ad-fraud malware already in the firmware

Bitdefender found ad-fraud malware preinstalled in the firmware of thousands of cheap MediaTek-based Android phones in more than 150 countries. The implant cannot be uninstalled, so the point of purchase is where a buyer can keep it out.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Cheap MediaTek-based Android phones reach buyers with ad-fraud malware already in the firmware
Generated illustration

What happened

  • The firmware app runs with system-level privileges and can silently install or remove apps, grant them permissions, and download and run new code without the owner's approval.
  • Before installing some of its payloads, the malware switches off the Google Play Store and turns it back on once the install is finished.
  • Bitdefender also found 13 apps on Google Play that talked to the same infrastructure and carried the same ad-fraud code.
  • Many affected phones are low-cost white-label or counterfeit models, some made to resemble Samsung Galaxy phones and iPhones, sold on mainstream marketplaces; one cost about $180.
  • The insertion point is still unknown: Bitdefender has not determined who placed the malware or where in the supply chain it entered.

Why it matters

  • decision Companies that let staff and contractors work from self-bought Android phones have to decide whether to restrict which models and sellers are allowed, since this implant is running before any store-side check.
  • exposure On a work phone, the installed-app inventory the malware collects would include whatever corporate tools the owner added, before the operator pushes anything new.
  • constraint With the insertion point unknown and the signing certificates not proof of authorship, procurement teams cannot block a single supplier by name.

No exploit is involved, because the access ships with the hardware [2]. "The malware ships preinstalled in the device firmware," Bitdefender said in a report released Thursday. "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled." [2]

For now that access is spent on advertising [3]. The firmware app does not produce fraudulent ad views itself [14]. It plants apps posing as weather, note-taking, app-lock and file-management utilities [14]. Those apps load real ads from legitimate ad services into invisible windows over other applications, registering impressions the owner never sees [15]. Some components also generate automated clicks [15]. Separately, the malware collects information about the device and its installed apps, and Bitdefender found capabilities that could pull infected phones into botnets [3]. Because the firmware app can download and run additional code without approval, the operator decides what an infected phone does next [4].

App-store scanning arrives too late to catch this [2][6]. Bitdefender counted at least 32 disguised payload apps [16], and it said the Play Store shutdown during some installs is potentially meant to evade detection [6]. The store is also a second channel for the same operation. The 13 Play apps tied to its infrastructure [7] lack system privileges and offer real functions such as weather or QR-code scanning [9]. They could still show ads outside the apps, the researchers said, including when the owner was not using the phone [9].

Midnight Mimosa, as Bitdefender named the campaign, is a sustained operation [1]. Bitdefender tracked it for roughly two years; the biggest shares of detected devices were in Mexico, France and Italy, with the United States, Germany, Brazil and Spain next [5]. The researchers stated the business model themselves. "The internet is flooded with extremely cheap, and sometimes straight-up counterfeit, Android phones," they said. "One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards." [17]

The common hardware across the affected brands is a MediaTek chip [8]. The insertion points Bitdefender named as possible sit later in the chain: an original device manufacturer, a firmware integrator, a logistics partner or another intermediary before sale [12]. Certificates used to sign some of the affected firmware carry the name of Shenzhen Zediel, a Chinese maker and seller of smart hardware and consumer electronics [11]. According to Bitdefender, those certificates are not proof that the company built the malware, distributed it knowingly or was aware of it [11]. The evidence ties the implant to the low-cost, white-label and counterfeit tier of the market [13]. It does not show that MediaTek-based phones as a group are compromised [8][12].

What to watch

  • A named insertion point, such as a specific manufacturer, firmware integrator or logistics partner, would let buyers screen by supplier instead of by whole device tier.
  • Any sign the operator uses the download-and-run capability to push botnet components or collection beyond device and app inventories.
  • Whether Google pulls the 13 Play apps and whether the marketplaces selling the Galaxy and iPhone lookalikes delist them.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption25
Hype gap+15
Incentives35
Confidence60

Perspective Coverage

5 publishers
Builder
Builder 27%
Operator
Operator 55%
Investor
Investor 18%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Romania-based Bitdefender found malware preinstalled on thousands of cheap Android phones that can generate fraudulent ad revenue and potentially turn infected devices into parts of botnets; it dubbed the campaign Midnight Mimosa.

    ReportedSupportedSource: Bitdefender, via The Record4 sources— create a free account to open themView cited source
  2. [2]

    "The malware ships preinstalled in the device firmware," Bitdefender said in a report released Thursday. "It's on the phone before the owner switches it on for the first time, and it can't be uninstalled."

    ReportedSupportedSource: Bitdefender report, quoted by The Record4 sources— create a free account to open themView cited source
  3. [3]

    The campaign appears primarily designed to make money through advertising and click fraud; the malware can also collect information about devices and installed apps and has capabilities that could allow infected phones to be incorporated into botnets.

    ReportedSupportedSource: Bitdefender researchers, via The Record4 sources— create a free account to open themView cited source

Sources

5 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 8, 2026

    Low-cost Android phones ship with residential proxy malware
  2. dev.to

    1 article · October 8, 2026

    Midnight Mimosa: Malware Preinstalled in Android Firmware for Ad Fraud and Residential Proxying
  3. scworld.com

    1 article · October 9, 2026

    Malware preinstalled on cheap Android phones generates ad fraud
  4. securityweek.com

    1 article · October 9, 2026

    Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
  5. therecord.media

    1 article · October 8, 2026

    Thousands of cheap Android phones shipped with ad-fraud malware

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories