Search results for

All search results
Best daily deals

Affiliate links on Android Authority may earn us a commission. Learn more.

Some cheap Android phones are shipping with malware baked in

Midnight Mimosa malware arrives pre-served.
By
•

Oct 8, 2026 — 9:00 AM ET

•
•
android malware hero
Karandeep Singh Oberoi / Android Authority
Add Android Authority on Google:
TL;DR
  • Researchers have uncovered a malware campaign affecting some low-cost Android phones, including devices from Doogee and Cubot.
  • Dubbed Midnight Mimosa, the malware is embedded in device firmware and can install apps, grant permissions, evade Play Protect, and turn phones into botnet nodes.
  • The campaign has been seen on thousands of devices across more than 150 countries, and removing the malware isn’t easy because it lives in the system partition.

Over the years, we’ve been warned about the dangers of downloading unknown apps on our smartphones. The instructions have been clear: stick to the Google Play Store, and if you must sideload APKs, use trusted sources. Those instructions make sense when your phone is malware-free in the first place, but what if your phone was already compromised before you even took it out of its box?

That’s exactly the situation researchers at Bitdefender have uncovered, as shared on their blog. There’s a new malware campaign dubbed Midnight Mimosa, and as pleasant as that name sounds, you definitely don’t want it served to you.

Midnight Mimosa is malware that’s reportedly embedded directly into the firmware of some low-cost Android devices. Thankfully, it doesn’t affect some of the best low-cost Android phones you and I can buy right now. Instead, Bitdefender says the malware campaign mainly affects fringe, lesser-known Android phones from brands you might have never heard of before. These include phones like Doogee’s S200 X, Cubot’s KINGKONG X, and others.

Those are most likely white-label devices that those companies simply brand as their own. I’ve never heard of those brands before, but they’re not completely obscure in the Android space either. We reviewed a phone from Cubot, though that was back in 2014. More recently, in 2021, we also reviewed a rugged phone from DOOGEE. Although we haven’t written about the exact malware-infested phones in question, other reliable publications, including Gizmodo and NotebookCheck, have.

According to the report, Midnight Mimosa has also been found on counterfeit devices that mimic flagships, using model names such as S24 Ultra, S25 Ultra, S26 Ultra, i17 Pro Max, i16_Pro_Max, 17_Pro_Max, and more, as seen in the image below.

counterfeit phone listing
BitDefender

So yes, even though these are fringe devices, they do seem to have a market. And that’s why the new findings are concerning. Given that Midnight Mimosa has been found embedded directly in the firmware of those phones, it is present before those phones can even be turned on. It’s not entirely clear when exactly the phones get infected during their early life cycle. What is clear, however, is that buyers of these phones are not at fault in such a scenario. Well, other than buying one of those phones in the first place.

Midnight Mimosa reportedly runs with system-level privileges, which allows it to silently install new apps, remove existing ones, grant permissions, and even load code remotely.

Considering that, staying under the radar has been relatively easy for the malware. Midnight Mimosa has reportedly been found to disable the Google Play Store just before installing a payload, likely an attempt to avoid Play Protect detection. Once you’re in that deep, the sky is the limit.

The malware campaign appears to be focused on making money, using infected devices for hidden ads and click fraud, and repurposing them as proxy nodes in a larger botnet for DDoS attacks.

According to the report, over a two-year period, the malware campaign was observed on thousands of devices across more than 150 countries. The largest concentrations were found in Mexico, France, and Italy, followed by the US, Germany, Brazil, and Spain.

What can you do if you own one of these phones?

Unfortunately, there isn’t a simple uninstall button here. Midnight Mimosa lives in an infected phone’s system partition, and removing it requires either a firmware-level remedy or disabling it over ADB.

Neither of those is a viable option for the average user. Plus, we don’t expect someone with knowledge of ADB, firmware flashing, and manually disabling system packages to be a buyer of such phones in the first place.

This leaves actual users of infected devices in a bad position, with replacing the device, unfortunately, being the most viable option.

Thank you for being part of our community. Read our Comment Policy before posting.