Skip to content
See the World Through ScienceA project of ALLATRA

Cheap Android Phones Are Shipping With Malware Owners Cannot Delete, Bitdefender Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Macro photograph of a MediaTek system-on-chip, its part number legible, soldered to the circuit board of a low-cost Android phone.
The processor of a budget Android handset, photographed under magnification (illustrative). Bitdefender says the phones it examined were built on MediaTek platforms, and makes no finding against the chipmaker."File:Wiko Rainbow 4G - main printed circuit board - Mediatek MT6582V-8620.jpg" by Raimond Spekking, via wikimedia, CC-BY-SA-4.0

Bitdefender Labs said Oct. 8, 2026, that it had found a hidden app shipping inside the factory software of low-cost Android phones from several brands, all built on MediaTek chips. The company says the app is on the phone before the owner first switches it on, and that the owner cannot uninstall it.

By Bitdefender Labs' account, the campaign, which it calls Midnight Mimosa, is likely designed mainly to make money. Its report says the app quietly installs and removes a changing set of ordinary-looking apps that run invisible advertising fraud, and that it also turns the handset into a relay for other people's internet traffic.

Bitdefender counts at least 32 unique disguised apps, among them fake app locks, weather apps and file managers. Because the app is signed as part of the operating system, the company says it can install software and grant it permissions without prompting the owner. Bitdefender also says it switches off the Google Play Store, which carries Google's on-device scanner, around each installation.

Bitdefender says the same advertising-fraud code turned up in 13 apps distributed by Google Play itself, each with its own signing certificate, across at least two developer accounts. The company describes those as genuine Play builds that passed Google's review.

On that basis the company says it observed the campaign over roughly two years on thousands of devices in more than 150 countries, led by Mexico, France and Italy.

Bitdefender says it can confirm only that certificates bearing the name of a Shenzhen device maker signed firmware on affected phones. The report says it is unclear how those certificates reached the handsets, whether their owner was involved or aware, and where in the supply chain the code is added.

Bitdefender says the app sits in the phone's system partition, so an ordinary uninstall cannot reach it. The report puts the fix with the vendors and marketplaces that ship and sell these phones.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Cheap Android Phones Are Shipping With Malware Owners Cannot Delete, Bitdefender Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.