Researchers at Bitdefender have uncovered a malware campaign affecting low-cost Android smartphones that ship with malicious software baked into their firmware. The campaign, named Midnight Mimosa, has been active for approximately two years and has infected thousands of devices across more than 150 countries, with the highest number of victims in Mexico, France, Italy, the United States, Germany, Brazil, and Spain.
The malware is believed to have been introduced somewhere in the device supply chain. It remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred. The affected devices use MediaTek chipsets, and the malware resides in the system partition, granting it system-level privileges that allow it to silently install and remove applications, grant permissions, and execute remotely downloaded code without user interaction.
Bitdefender found the malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones that impersonate Samsung and Apple products. The malicious programs disguise themselves as legitimate Android system packages, using names such as com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Because the applications are signed and run with elevated privileges, they cannot be removed through Android's normal uninstall process.
Owners of Cubot and Doogee smartphones reported suspicious applications that reinstalled themselves after removal on an XDA forums discussion page. One Doogee Fire 3 Max owner said an official firmware update infected the device with the malware. The infection disappeared after restoring an older firmware version but returned when the update was installed again.
Some users reported that manufacturers released firmware updates that resolved the infections, but the manufacturers have not publicly explained how the malicious software was introduced.
Bitdefender identified approximately 32 applications distributed through the malware framework, which downloads additional modules from command-and-control servers to perform different malicious activities. The campaign was discovered when the company's App Anomaly Detection technology flagged a suspicious system application silently installing and removing other apps.