Skip to main content
Emerging ThreatsMalware & Ransomware

Android Phones Ship with Embedded Malware

Low-cost Android smartphone sits on cluttered electronics store shelf with other phones and packaging materials.

“The system app itself doesn’t register the fraudulent impressions and clicks,” Bitdefender researchers wrote — but the framework it dropped does, across thousands of low-cost Android phones in more than 150 countries over approximately two years.

Research findings from Bitdefender

Bitdefender discovered a persistent firmware-embedded malware campaign it names "Midnight Mimosa." The company says the operation affected thousands of devices in over 150 countries, with the highest counts of infected phones reported in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. The researchers traced infections to several device model names associated with legitimate manufacturers, including the Doogee S200 X and the Cubot KINGKONG X, and to phones impersonating Samsung and Apple products.

The discovery began when Bitdefender's App Anomaly Detection flagged a suspicious system application called com.android.system.lite that was silently installing and removing other applications. Follow‑up analysis showed that the flagged binary was part of a larger framework that could download and run additional modules from command‑and‑control (C2) servers.

How Midnight Mimosa operates inside device firmware

Midnight Mimosa is preinstalled in the device system partition — not delivered by a user-installed APK — giving its components system‑level privileges. The malware uses names that mimic legitimate Android system packages, including com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot. Because the packages are signed and run with elevated privileges, they cannot be removed through Android's normal uninstall process.

Bitdefender identified roughly 32 applications distributed through the framework. Many of these are disguised as benign utilities — weather apps, file managers, app lockers, OCR tools, and audio editors — and several load genuine ads through a legitimate ad SDK. The fraudulent monetization model relies on “dropped cover apps” that open invisible windows or automatically interact with ads to register impressions and clicks without the device owner's knowledge.

To evade detection, Midnight Mimosa temporarily disables the Google Play Store app (com.android.vending) before silently installing malicious apps, apparently to block Google Play Protect. After installations complete the malware re‑enables the Play Store. Some variants also manipulate Android's recorded installer information so a malicious app appears to have been installed via Google Play even though it was installed directly by the firmware component.

Residential proxy capability and command‑and‑control behavior

Beyond ad fraud, the framework contains code that can convert infected phones into residential proxies. Bitdefender points to one malicious package disguised as an app locker, com.mobile.applock.en, which implements a TCP proxy component that registers infected devices with a remote command server. Registered devices can receive instructions to connect to specified hosts and forward traffic, allowing attackers to route connections through the phone owner's internet link.

Bitdefender confirmed the proxy C2 infrastructure was operational and accepting device registrations during their testing. However, their newly registered device did not receive any relay targets in those tests, so researchers could not confirm active traffic forwarding in the wild at the time of analysis.

Distribution vectors: Play Store apps, firmware signatures, and forum reports

Bitdefender also found 13 Android applications on the Google Play Store that contained the same advertising‑fraud code and communicated with known Midnight Mimosa infrastructure. Those Play Store apps did not have system privileges and therefore could not silently install other apps, but they could display ads outside their user interface. The 13 Play Store apps were signed with 13 different certificates and came from at least two developer accounts identified as fivedev and CPS Developer.

In firmware samples, the researchers noted signatures using certificates associated with Shenzhen Zediel, but they said it remains unclear whether that company was involved in the campaign. Public reports on XDA forums by owners of Cubot and Doogee phones also aligned with the findings: forum users reported suspicious applications that repeatedly reinstalled after removal, and one Doogee Fire 3 Max owner said an official firmware update introduced the malware — which went away after restoring older firmware but returned when the update was reinstalled. Some manufacturers later released firmware updates that resolved infections, but the companies did not publicly explain how the malicious software had been introduced into affected firmware.

What this means for consumers, manufacturers, and advertisers

  • Consumers: Removal is difficult because the malicious components live in the system partition with elevated privileges. Bitdefender says cleanup requires firmware‑level remediation or disabling the component via Android Debug Bridge (ADB), a technical procedure many users will find complicated.
  • Manufacturers and supply‑chain managers: The campaign appears to have been introduced somewhere in the device supply chain, but Bitdefender's report does not identify who modified firmware or at what manufacturing or distribution stage that happened. Some vendors issued firmware updates that cured infections, yet public explanations about origin and responsibility have not been provided.
  • Advertisers and ad networks: The revenue engine behind Midnight Mimosa runs through legitimate ad SDKs embedded in cover apps that render ads invisibly or click them automatically. That pattern creates fraud that is difficult to detect because the displayed ad stacks are otherwise genuine.

Midnight Mimosa illustrates a blunt truth: when malicious code is soldered into firmware, the usual user‑level defenses are often powerless. Bitdefender's analysis maps the scope, the techniques, and the visible infrastructure — but it also leaves a central question open and stark: who altered these firmwares, and at which link in a fragmented supply chain did the compromise occur?

Original reporting