Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Malware found in firmware of thousands of Android phones

Published 9 October 2026

Midnight Mimosa, malware embedded in the firmware of some low-cost MediaTek Android phones, has been found on thousands of devices across more than 150 countries, according to cybersecurity researchers at Bitdefender. The software can secretly install apps that generate fraudulent advertising activity and has capabilities for registering phones as residential proxies. Bitdefender said it observed the malware over approximately two years. Because its core component is built into the device firmware and runs with system-level privileges, it can install or remove applications, grant permissions and download additional code without the owner’s knowledge. It cannot be removed through Android’s standard app-uninstall process. Researchers identified at least 32 disguised apps deployed by the malware, including programs presented as weather utilities, app lockers and other tools. These apps can load legitimate advertisements in hidden windows and generate fraudulent impressions or clicks. The malware may temporarily disable the Google Play Store while installing some payloads, then turn it back on. The campaign also includes a residential-proxy capability.

Now playing
0:00 / 0:00