Bitdefender Labs says it has found malware built directly into the firmware of some low-cost Android phones. The researchers call it Midnight Mimosa, and it runs with system-level privileges on devices built around MediaTek platforms. Bitdefender counts thousands of affected handsets across more than 150 countries, including the United States, over roughly two years.

The core of it is a platform-signed system app named com.android.system.lite, with variants named com.android.sys.prot and com.android.sys.gmsprot. Because the app is signed as part of the platform, Android treats it as trusted. Bitdefender identified at least 32 disguised payload apps tied to the operation, plus 13 related apps on Google Play.
What it does once the phone is switched on
According to Bitdefender Labs, the component can install and remove apps silently. It can also grant itself permissions and pull down remote code. The researchers describe three uses: advertising and click fraud, data collection, and enrolling devices as residential-proxy nodes in a botnet.
One detail shows how deliberate the design is. Bitdefender says the malware temporarily disables the Play Store while it installs its payloads, then switches it back on afterwards. Because the store comes back, an owner has little reason to notice anything happened.
Bitdefender also reports the component is capable of abusing Accessibility, Notification Access and SMS permissions. It says it did not observe those specific capabilities being used in the activity it analyzed. That gap matters, and it should not be read as reassurance about what the operators could switch on later.
Where the affected phones are
The largest shares of detections sit in Mexico, France and Italy, per Bitdefender. The United States, Germany, Brazil and Spain follow.
The brand question is messier, and it deserves care. Bitdefender’s model-string telemetry points at Doogee devices identified as S200 X and Cubot devices identified as KINGKONG X. Firmware signed by a third party called Shenzhen Zediel Co., Ltd. was also observed on affected units. Bitdefender does not claim Doogee or Cubot knowingly shipped the malware, and it does not present Zediel’s role as proven.
There is a good reason to treat those names loosely. Many affected devices appear to be counterfeit or white-label units wearing fake flagship branding, including spoofed Galaxy and iPhone model names. A model string is self-reported by the firmware, so it can be faked as easily as the logo on the back.
Why you probably cannot remove it
The malware lives in the system partition, so uninstalling it the normal way does nothing. Bitdefender says cleaning an infected device requires firmware-level work, or disabling the component through ADB. It calls that unrealistic for most owners, and recommends that vendors and marketplaces fix the problem at the source.
That is the part worth sitting with. A buyer who paid very little for a phone has no practical way to detect this, and no realistic way to remove it. As of October 8, no vendor fix has been announced. The cost of the cheap handset gets paid later, in stolen bandwidth and harvested data.
How to judge your own risk
This research points at the bottom end of the market and at counterfeit units, not at mainstream flagships from established brands. A few practical signals:
- Price that does not add up: a phone advertising flagship specs for a fraction of a flagship price
- Borrowed model names: listings using a famous model name from a brand that does not actually make that phone
- Where it was bought: marketplace resellers and grey-import channels rather than the brand’s own store or an authorized retailer
Google’s install-side defenses have tightened recently, and Android’s new app install rules are already live. Those rules govern what gets installed on top of the system, though. Malware that ships inside the firmware starts out on the other side of that boundary.
Source: Bitdefender Labs, via Android Authority





