Bitdefender researchers identify Midnight Mimosa malware on Android devices
- Security researchers at Bitdefender have identified a sophisticated malware campaign dubbed “Midnight Mimosa” that has infected thousands of Android smartphones across more than 150 countries.
- The scale of the infection spans a diverse range of low-cost Android hardware, with researchers noting that the malware is not limited to obscure brands.
- The malware is pre-installed on devices utilizing MediaTek chipsets.
Security researchers at Bitdefender have identified a sophisticated malware campaign dubbed “Midnight Mimosa” that has infected thousands of Android smartphones across more than 150 countries. The malicious code is embedded directly into the device firmware, allowing it to operate at the system level and persist even after factory resets. Over a period of approximately two years, the campaign has impacted thousands of units, with the highest concentration of victims recorded in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. In Germany specifically, 7.3 percent of the infected devices were identified.
Scope of the Midnight Mimosa Campaign
The scale of the infection spans a diverse range of low-cost Android hardware, with researchers noting that the malware is not limited to obscure brands. Bitdefender’s analysis indicates that the campaign has affected devices mislabeled as products from major manufacturers like Samsung and Apple, in addition to budget-friendly models such as the Doogee S200 X and Cubot KINGKONG X. Some devices were identified as counterfeit clones of premium models, including the Galaxy S24 Ultra or S26 Ultra, though genuine Samsung hardware remains unaffected. Other implicated models include the S25 Ultra and Nitro A65. While these devices are often marketed as robust or high-performance options, they are frequently sold via third-party platforms outside of the European Union, a trend that has prompted warnings from the German Federal Network Agency (Bundesnetzagentur) regarding the risks of purchasing electronics from non-EU retailers. The agency notes that third-party logistics providers in Europe often do not assume responsibility for products that fail to meet EU safety standards.
The malware is pre-installed on devices utilizing MediaTek chipsets. Because the malicious code is integrated into the firmware, the threat is present from the moment the device is powered on, making it significantly more difficult to remove than standard applications.

Technical Capabilities and System-Level Access
The “Midnight Mimosa” malware functions as a system component, granting it elevated privileges that bypass standard Android security protections. The malware is capable of reading and sending SMS messages, collecting device information, and incorporating the smartphone into a network of remotely controlled units. When installing additional malicious software, the compromised component can temporarily disable the security functions of Google Play Protect. The attackers leverage these devices to generate fraudulent advertising revenue through fake clicks and impressions, often without user consent.
Bitdefender discovered the campaign after their security software flagged an unusual system file named “com.android.system.lite.” Further investigation revealed 32 distinct applications linked to this infrastructure, which masquerade as weather services, file managers, note-taking programs, or app lockers. Additionally, 13 apps found on the Google Play Store were discovered to communicate with the same infrastructure, suggesting the reach of the threat extends beyond pre-infected hardware.

Uncertainty Regarding Supply Chain Origins
While researchers have identified firmware signed with certificates associated with Shenzhen Zediel, a hardware manufacturer based in China, the exact point of entry remains unconfirmed. Bitdefender has clarified that this technical link does not constitute definitive proof that Shenzhen Zediel knowingly authored or distributed the malware.
Bitdefender
Limitations on User Remediation
Removing the malware is a complex process for the average user, as the software is deeply embedded in the device’s operating system. According to Bitdefender, a successful cleanup requires either a complete re-flashing of the device firmware or the manual deactivation of the malicious components using the Android Debug Bridge (ADB). Because these methods require technical expertise, many users find the malware nearly impossible to eliminate.
In one instance, an owner of a Doogee Fire 3 Max reported that an official firmware update introduced the malware, which disappeared after rolling back to an older version but returned upon reinstalling the update. In cases where remediation fails, experts suggest that replacing the device entirely may be the only reliable solution.
