Cheap Android phones are shipping with malware you can’t remove

Your budget Android phone might have come with a bonus you didn’t ask for. Security researchers at Bitdefender have identified a pre-installed malware campaign called “Midnight Mimosa” running on low-cost, multi-brand Android devices built on MediaTek chipsets. It’s baked into the firmware. It activates the moment you first power on the device. And no, you cannot uninstall it.

According to Android Headlines, Bitdefender’s researchers found multiple malicious system packages embedded across different device models, with the exact combination varying by unit. The malware runs with full system-level privileges, which means it can silently install and remove apps, grant itself permissions, and pull in arbitrary code from remote servers whenever the operators want to update its capabilities. That’s not a bug — that’s a design.

The primary goal is money. Bitdefender says operators use infected devices to commit ad and click fraud, harvest device and app data, and conscript phones into residential proxy networks and botnets. Botnet size translates directly to profit, so every infected phone adds value for whoever is running this. It also opens the door to DDoS attacks using your device and your internet connection, without you ever knowing.

The revenue mechanism is worth understanding. The malware’s core system app, identified as com.android.system.lite, loads an invisible window on top of other apps to silently register ad impressions and clicks. But the system app itself doesn’t collect the money directly. That job falls to a set of dropper “cover” apps designed to look legitimate, including weather apps, note-taking tools, app lockers, and OCR utilities. These are the actual revenue engine.

Bitdefender also found the same malware core shipping under a rotating list of system-sounding package names:

  • com.android.sys.prot
  • com.android.sys.gmsprot
  • com.android.sys.bcprot

Each build carries different signing certificates, which helps it avoid detection. And here’s the part that should concern anyone who thinks the Play Store is a safe boundary: 13 apps currently available on Google Play were found communicating with the same command-and-control servers tied to this malware. Google has not publicly commented on whether those apps will be removed.

This fits a pattern that security researchers have been flagging for years. Budget Android devices, particularly those built on common MediaTek reference designs and sold under rotating brand names, have repeatedly shown up with supply chain compromises. The economics make it predictable. Thin margins create pressure to monetize in other ways, and firmware is an attractive place to hide revenue-generating code because most users never look there and can’t touch it if they did.

For consumers, the practical takeaway is uncomfortable. Buying a cheap Android phone from an unfamiliar brand is not just a quality risk. It may be a privacy and security risk from the moment you turn it on.