Back to Feed
MalwareOct 9, 2026

Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Midnight Mimosa malware campaign preinstalls on budget Android devices across 150+ countries via firmware.

Summary

Midnight Mimosa is a large-scale malware campaign discovered by Bitdefender that primarily targets low-cost Android devices built on MediaTek platforms by preinstalling malware in device firmware. The persistent system-level malware enables ad fraud, click fraud, and botnet deployment across thousands of devices in over 150 countries, with no single geographic concentration. The campaign also leverages 13 associated Google Play Store apps as an additional distribution vector.

Full text

There is a large global market for low-cost Android devices. Bad actors are aware and are servicing the demand through devices built on MediaTek platforms – but with malware preinstalled in the device firmware. When the recipient of such an affected device switches it on, the malware is present, unseen, and available to any bad actor who can control it remotely from its C2. It is a persistent, pre-installed firmware system app that cannot be removed by normal uninstall procedures. The campaign, dubbed Midnight Mimosa, was discovered and analyzed by Bitdefender. The potential for this type of malware infection controlled via the actor’s C2 is massive. “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” writes the Bitdefender report. Midnight Mimosa is focused on ad fraud, automated click fraud, and turning the device into a single component of a much larger botnet. This makes sense for a campaign seeking to fly under the radar with an army of soldiers. Many thousands of click frauds over a period of time would provide a healthy ROI for any bad actor. And botnets are described as a hot commodity that can be rented out to other bad actors. The bigger the botnet, the better the bounty. Over the last two years, Bitdefender has observed thousands of unique affected devices in more than 150 countries. No single country or region dominates distribution. Mexico and France lead, followed by Italy, US, Germany, Brazil and Spain. Regionally, Western Europe and the Americas stand out. The report gives no indication of the actual monetary gain achieved by the Midnight Mimosa operators but does provide an extensive list of IoCs to help prevent it.Advertisement. Scroll to continue reading. Bitdefender also found 13 apps on Google Play with separate signing certificates under two developer accounts and containing the same Midnight Mimosa ad-fraud code. “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself,” note the researchers. These Play Store apps do not have the same privileged access as the preinstalled malware, but are considered associated with the broader ecosystem, giving the attackers an additional distribution channel. Whether the malware is preinstalled or loaded from Play Store, it has been seen disabling the Play Store before installing additional payload applications and then re-enabling it afterward – probably to avoid detection by Play Protect. “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install,” note the researchers. “The malicious install happens in a window where Google’s scanner is switched off.” Midnight Mimosa is best considered as a supply-chain threat where malware is largely integrated into the Android device prior to sale. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse and remote payload management. Attackers have extensive control over affected devices from the get-go. Related: RatHat Android Trojan Uses AI for Automation Related: Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews Related: New BTMOB Android Malware Enables Full Device Takeover Related: Mirax RAT Targeting Android Users in Europe Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Hadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformSocial Engineering Detection Moves Into the Live ConversationSenate Passes Bipartisan Bill to Strengthen Healthcare Cybersecuritydoxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet MisadventuresmacOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD BackdoorZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass Latest News US Disrupts Chinese State-Sponsored Hacking ToolsAnthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityCitrix Urges Immediate Patching of Critical NetScaler VulnerabilityGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — Midnight Mimosa
  • mitre_attack — T1574.001
  • mitre_attack — T1444

Entities

Midnight Mimosa (campaign)Bitdefender (vendor)MediaTek (vendor)Android (technology)Google (vendor)