MIDNIGHT Mimosa is a supply-chain style Android malware campaign that preinstalls itself in the firmware of low-cost devices built on MediaTek platforms. Discovered and analysed by Bitdefender, the malware sits as a persistent system app that cannot be removed through normal uninstallation. On device power‑up, it is present but hidden, allowing operators to remotely control it via its command-and-control server.
The campaign is focused on ad fraud and botnet-enabled activity, with operators able to install or remove apps, grant permissions, and load payloads supplied remotely. The operators’ aim appears to be automating click fraud and turning infected devices into rentable botnet components, enabling large-scale monetisation while remaining under the radar.
Bitdefender’s findings show thousands of unique affected devices across more than 150 countries, with no single region dominating—though Mexico and France are among the top, followed by Italy, the US, Germany, Brazil and Spain. Researchers also identified 13 Google Play apps carrying the same Midnight Mimosa code under different signing certificates and developer accounts, suggesting an additional distribution channel.
When active, the malware can disable the Play Store to install further payloads and then re‑enable it, effectively blinding Google Play Protect during the installation window. Overall, Midnight Mimosa is best described as a high‑impact, hard‑to-remove preinstalled threat that enables remote payload management, ad‑fraud, and proxy network abuse from device birth. Bitdefender provides IoCs to help mitigations, emphasising this as a notable supply‑chain risk for budget Android devices.