- Bitdefender found ad-fraud malware preinstalled in the firmware of thousands of cheap Android phones across more than 150 countries. Owners cannot uninstall it.
- The phones passed through many hands before sale, and Bitdefender has not found who added the code. Buyers cannot see that chain.
- Check where staff phones came from, not just what runs on them. Buy only from authorized sellers.
Most security advice starts after the purchase. Install updates. Avoid shady apps. Think before you tap. The Midnight Mimosa campaign starts earlier. The harm was already on the phone when the box was opened.
Bitdefender, a Romanian cybersecurity firm, named the campaign in a report released Thursday. The Record covered it. The researchers found malware preinstalled on thousands of low-cost Android phones. Its main aim is to earn money from advertising fraud. It could also pull phones into botnets, which are networks of hijacked devices.
How the scheme works
At the core is a malicious app built into the phone's firmware. Firmware is the base software a device ships with. Bitdefender said the app runs with system-level privileges. That lets it install or remove other apps, grant them permissions, and download and run more code. The owner never has to approve any of it.
Bitdefender put it bluntly. The malware is on the phone "before the owner switches it on for the first time, and it can’t be uninstalled."
The preinstalled app does not commit the ad fraud itself. It quietly installs other apps that look harmless. They pose as weather, note-taking, app-lock and file-management tools.
The ads these apps show are real and come from normal ad providers. The trick is where they appear. The apps draw them in hidden windows on top of other apps. Advertisers are billed for views no person saw. Some components also fire off automated clicks.
The researchers noted one more detail. Before installing some of these payloads, the malware briefly turns off the Google Play Store. It switches the store back on afterward. Bitdefender said this may be a way to avoid detection.
The official store is part of the story
Bitdefender also found 13 apps on Google Play. They talked to the same infrastructure and carried the same ad-fraud code. These apps lack the system privileges of the preinstalled malware. They also do real work, such as weather or QR-code scanning.
The researchers said the apps could still show ads outside their own screens. That includes times when the user was not touching the phone.
So one operation reached victims by two routes. One was the factory. The other was the store most people trust.
Where the trail goes cold
Bitdefender has not determined who planted the malware. It also does not know where in the supply chain the code entered. The affected phones come from several brands and use MediaTek chips. The report does not blame the chipmaker.
Part of the affected firmware carries digital signing certificates in the name of Shenzhen Zediel, a Chinese consumer-electronics company. Bitdefender cautioned that the certificates do not prove the company wrote the malware, spread it on purpose, or knew it was there.
Any business that handled the phones before sale could have added the code, Bitdefender said. That includes the maker that built the device, the team that assembled its firmware, and shippers or other go-betweens.
That uncertainty matters to buyers. A phone passes through many hands before it reaches a customer. Each handoff is a place where code could be added. The buyer sees none of them.
The idea: a very low price has to be paid for somehow
The researchers offered a plain explanation. "One way to make the money back on hardware sold that cheaply is to load it with software that earns afterwards." Bitdefender did not prove this is why these phones were infected. It is still a useful way to read the case.
On that reading, the buyer of a deeply discounted phone may not be the only customer. The device becomes a small income stream for someone else. The owner pays for the hardware, then also supplies the screen, the battery and the network connection.
The infected phones tend to be bargain-bin devices: unbranded, generic or knock-offs. Some imitate the look of Samsung Galaxy phones and iPhones. They are sold on mainstream online marketplaces. One phone the researchers examined cost about $180.
Bitdefender watched the malware for roughly two years. Mexico, France and Italy had the largest shares of detected devices. The United States, Germany, Brazil and Spain followed.
Questions to put to your team
Do employees use personal phones for email, login codes or company chat? If so, does anyone know which models? An app with system privileges runs beneath the controls most users can see.
Does procurement buy phones only from authorized sellers? Does anyone check for off-brand or lookalike devices before they are issued? That includes phones given to field staff and contractors.
Does your device policy cover where a phone came from, not only what is installed on it? Could you spot an unapproved utility app on a managed device?
Security usually asks what a device does once it is in use. This case adds an earlier question: what was it carrying when it arrived?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.





