Overview
- Bitdefender researchers found a firmware‑level malware campaign they call Midnight Mimosa installed on multiple low‑cost Android models that use MediaTek chips.
- The malicious code activates at first boot, runs with Android system privileges, can load remote code, and cannot be removed by normal uninstalls or factory resets.
- Operators use invisible 'cover' apps and system‑sounding packages to generate ad and click fraud, collect device and app data, and turn infected phones into residential‑proxy nodes for botnets.
- The operation hides under rotating system package names and temporarily disables Play Store checks to sideload payloads, and researchers linked 13 apps on Google Play to the same control servers.
- Thousands of devices across many countries appear affected, and full remediation will likely require coordinated action from device makers, MediaTek, and Google or replacement of firmware or devices.