Malware & Threats
Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices.
![]()
By
|
October 9, 2026 (5:55 AM ET)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/) [+ Whatsapp](whatsapp://send?text=Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/) + Email

There is a large global market for low-cost Android devices. Bad actors are aware and are servicing the demand through devices built on MediaTek platforms – but with malware preinstalled in the device firmware.
When the recipient of such an affected device switches it on, the malware is present, unseen, and available to any bad actor who can control it remotely from its C2. It is a persistent, pre-installed firmware system app that cannot be removed by normal uninstall procedures.
The campaign, dubbed Midnight Mimosa, was discovered and analyzed by Bitdefender.
The potential for this type of malware infection controlled via the actor’s C2 is massive. “The malware runs with system-level privileges that allow it to silently install and remove apps, grant permissions, and load arbitrary code supplied remotely. This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” writes the Bitdefender report.
Midnight Mimosa is focused on ad fraud, automated click fraud, and turning the device into a single component of a much larger botnet. This makes sense for a campaign seeking to fly under the radar with an army of soldiers. Many thousands of click frauds over a period of time would provide a healthy ROI for any bad actor. And botnets are described as a hot commodity that can be rented out to other bad actors. The bigger the botnet, the better the bounty.
Over the last two years, Bitdefender has observed thousands of unique affected devices in more than 150 countries. No single country or region dominates distribution. Mexico and France lead, followed by Italy, US, Germany, Brazil and Spain. Regionally, Western Europe and the Americas stand out. The report gives no indication of the actual monetary gain achieved by the Midnight Mimosa operators but does provide an extensive list of IoCs to help prevent it.
Advertisement. Scroll to continue reading.
Bitdefender also found 13 apps on Google Play with separate signing certificates under two developer accounts and containing the same Midnight Mimosa ad-fraud code. “The campaign is not confined to preinstalled firmware. Thirteen applications published on Google Play were found carrying the same family markers as the dropped cover apps, in builds distributed by Play itself,” note the researchers.
These Play Store apps do not have the same privileged access as the preinstalled malware, but are considered associated with the broader ecosystem, giving the attackers an additional distribution channel.
Whether the malware is preinstalled or loaded from Play Store, it has been seen disabling the Play Store before installing additional payload applications and then re-enabling it afterward – probably to avoid detection by Play Protect. “Beyond suppressing the install prompt, the plugins blind Google Play Protect for the duration of the install,” note the researchers. “The malicious install happens in a window where Google’s scanner is switched off.”
Midnight Mimosa is best considered as a supply-chain threat where malware is largely integrated into the Android device prior to sale. The campaign is characterized by preinstalled persistence, system-level control, ad-fraud activity, proxy-network abuse and remote payload management. Attackers have extensive control over affected devices from the get-go.
Related : RatHat Android Trojan Uses AI for Automation
Related : Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Related : New BTMOB Android Malware Enables Full Device Takeover
Related : Mirax RAT Targeting Android Users in Europe
![]()
Written By
Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
More from Kevin Townsend
- Formula Predicts When AI Chatbots Are at Risk of Turning Bad
- Security Awareness Training Isn’t Dead, but It Needs a Rethink
- Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
- Social Engineering Detection Moves Into the Live Conversation
- Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
- doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
- macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
- Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Latest News
- OpenAI Fires 3 Safety Researchers in Dispute Over AI Risks
- In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years
- Google Domains Impacted by Recent ccTLD Hijacks
- Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- US Disrupts Chinese State-Sponsored Hacking Tools
- Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security
- Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

Trending
Daily Briefing Newsletter
Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
## Webinar: AI Is Accelerating Risk. Can Your IT Operations Keep Up?
October 14, 2026
Learn about Frontier Pace Governance: a practical approach to helping IT operations move at AI speed without sacrificing security, accountability, or operational discipline.
## Virtual Event: Zero Trust & Identity Strategies Summit 2026
October 14, 2026
Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.
People on the Move
Rapid7 has named Rik Ferguson as VP of Security Intelligence.
Cytactic has appointed Tim Brown as CSO.
Scott Simkin has joined Vega as CMO.
Expert Insights
## AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb)
## Four Cyber Threats Harboring Big Plans for the Future

- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin)
## Begin at the End: How to Enable Agentic Remediation

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael)
## “We Think the Security Control Is Working” Is No Longer Good Enough

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar)
## This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. (Matt Honea)
- + Flipboard + Reddit [+ Whatsapp](https://web.whatsapp.com/send?text=Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/) [+ Whatsapp](whatsapp://send?text=Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries https://www.securityweek.com/pre-baked-firmware-malware-hits-budget-android-devices-in-150-countries/) + Email
Popular Topics
Security Community
- Virtual Cybersecurity Events
- Webcast Library
- CISO Forum
- AI Risk Summit
- ICS Cybersecurity Conference
- Cybersecurity Newsletters
Stay Intouch
About SecurityWeek
News Tips
Got a confidential news tip? We want to hear from you.
Advertising
Reach a large audience of enterprise cybersecurity professionals
Daily Briefing Newsletter
Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox.
Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.
