malware
Published 2026-10-08
Verified 2026-10-09

Bitdefender: Midnight Mimosa firmware malware on low-cost MediaTek Android phones (Doogee, Cubot and others) does ad fraud and residential-proxy botnet work; thousands of devices across 150+ countries

Bitdefender Labs (8 October 2026) describes Midnight Mimosa, malware preinstalled in the firmware of low-cost multi-brand Android phones built on MediaTek platforms so it is present before first boot and cannot be removed through normal uninstall. Platform-signed system packages (including com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot and related names) run as system, silently install and remove apps, grant permissions and load remote code. Cover apps (weather, app-lock, notes, OCR) drive ad and click fraud; the same framework can enrol devices as residential-proxy botnet nodes. Bitdefender observed thousands of devices across more than 150 countries over about two years, with the largest shares in Mexico, France and Italy, then the United States, Germany, Brazil and Spain. Model names associated with Doogee S200 X and Cubot KINGKONG X appear, as do phones impersonating major brands. Some affected firmware was signed with certificates bearing the name Shenzhen Zediel; Bitdefender does not claim that company knowingly planted the malware. Thirteen Google Play apps talking to the same C2 infrastructure were also found. Cleaning typically needs firmware replacement or ADB disable — unrealistic for most owners. Primary: Bitdefender Labs; wire: BleepingComputer.

Product
Low-cost MediaTek Android smartphones (firmware-preinstalled system packages; Doogee/Cubot model names cited)
Versions
n/a — firmware supply-chain malware; vendor firmware updates required where available
Exploited in Australia?
unknown
Patch to
Prefer phones from known supply chains. If you own an affected low-cost MediaTek device, check for a clean vendor firmware build or retire the handset for anything sensitive; factory reset will not remove system-partition malware. Enterprises: ban unapproved consumer Android devices on corporate networks and MDM-enrol only approved models.

Primary: Bitdefender Labs — The phone was compromised before the user turned it on: Midnight Mimosa (8 Oct 2026) · Vendor: Bitdefender Labs research report · BleepingComputer — Low-cost Android phones ship with residential proxy malware (8 Oct 2026)

tech network