BITDEFENDER researchers say a malware campaign they call Midnight Mimosa is preinstalled in the firmware of some low-cost, multi-brand Android devices built on MediaTek platforms. The malicious system app is present before a phone is first switched on, is signed to run with system-level privileges and cannot be removed through normal means. Bitdefender observed the campaign on thousands of devices across more than 150 countries over roughly two years.
It identified a family of enablers under changing package names, including `com.android.system.lite`, `com.android.sys.prot` and `com.android.sys.gmsprot`.
The enabler can silently install and remove apps, grant them permissions and load code supplied remotely. Bitdefender says it deploys a rotating collection of at least 32 disguised apps, including fake weather, AppLock, file-manager and OCR tools. These can generate hidden ad impressions and clicks; some can also make infected phones residential-proxy relay nodes. The researchers found code that disables Google Play Store immediately before installing payloads, then re-enables it afterwards.
They also found 13 Google Play apps communicating with the same control servers and carrying related ad-fraud code, although these store apps lack the system privileges of the preinstalled malware. Accessibility, Notification Access and SMS permissions were available to the enabler, but Bitdefender did not observe the first two being used during its analysis.
Bitdefender says certificates bearing Shenzhen Zediel’s name signed firmware on some affected devices, but it cannot establish who introduced the malware into the supply chain or whether Zediel was involved or aware. Because the root component is in the system partition, ordinary uninstallation is not a solution; the report says removal requires firmware-level cleanup or disabling the component over ADB, and that a lasting fix rests with vendors and marketplaces.