Some budget Android smartphones are sold with preinstalled malware that gains system privileges and can install apps without the owner's knowledge. According to cybersecurity specialists at Bitdefender, the Midnight Mimosa malware has been found on devices from several lesser-known brands, as well as on counterfeit smartphones masquerading as flagship models.

The virus gets onto the smartphone before it is even turned on for the first time

Midnight Mimosa is embedded directly into the device's firmware. That means it is present in the system from the very beginning — the user does not need to accidentally download an infected app or click a malicious link.

Among the affected devices, researchers name the Doogee S200 X and Cubot KINGKONG X. Devices sold under names imitating popular models may also be at risk: S24 Ultra, S25 Ultra, S26 Ultra, and i17 Pro Max.

According to Bitdefender, some of these devices are produced under a rebranding model, in which the manufacturer sells the same hardware under different brand names. However, this does not in itself mean that all smartphones of the listed brands are infected: the report refers to specific devices affected by the detected campaign.

Midnight Mimosa can control system functions

The malware operates with system privileges, giving it far more capabilities than a regular app. It can silently install and remove programs, grant them permissions, and download code from a remote server.

To make detection more difficult, Midnight Mimosa, according to the research, disables the Google Play Store immediately before installing unwanted apps. This helps the malware bypass protective mechanisms, including Google Play Protect.

Smartphones are being used for fraud and DDoS attacks

Researchers estimate that the main goal of the campaign is profit. Infected devices can be used to display hidden ads, inflate ad clicks, and act as proxy nodes in a botnet.

Such proxies allow internet traffic to be routed through the devices of unsuspecting users. As part of a botnet, smartphones can also take part in DDoS attacks, in which many devices simultaneously send requests to a server in an attempt to disrupt its operation.

Over two years, researchers recorded infections on thousands of devices in more than 150 countries. The highest number of cases was in Mexico, France, and Italy. Other countries where infected smartphones were found include the United States, Germany, Brazil, and Spain.

Why a regular factory reset may not be enough

According to Bitdefender, removing Midnight Mimosa using standard methods is difficult: the malware resides in the firmware's system partition, not just in user storage. Therefore, a normal factory reset may not solve the problem.

Removing the infection may require reflashing the device or disabling the malicious components using special tools. Such actions require technical knowledge and are not always accessible to the average smartphone owner.

If the infection is confirmed, the most reliable practical solution may be to replace the device. When buying a new smartphone, it is worth giving preference to trusted sellers and models with a clear origin, and also avoiding suspiciously cheap devices that merely imitate the names of well-known flagships.