Firmware on budget Android devices found carrying stealth proxy malware

Bitdefender researchers uncovered a campaign called Midnight Mimosa that preinstalls malware in the firmware of low-cost Android phones using MediaTek chips. The malicious code runs with system-level privileges, allowing it to install apps silently, commit ad fraud, and turn devices into residential proxies. The campaign affected thousands of devices in more than 150 countries over about two years, including some Doogee and Cubot models, but manufacturers have not explained how the firmware was compromised.
Bitdefender's App Anomaly Detection first spotted a system app, com.android.system.lite, quietly adding and deleting software. Investigators linked it to a broader framework that fetches modules from command-and-control servers. Roughly 32 payloads were identified, disguised as weather, file-management, app-lock, OCR, and audio-editing tools.
The campaign, called Midnight Mimosa, targeted budget MediaTek Android handsets. It reached thousands of devices in over 150 countries across about two years. Reported models included Doogee S200 X and Cubot KINGKONG X, plus phones posing as Samsung and Apple products. Some owners saw suspicious apps return after deletion; one said an official update reintroduced the infection.
Consumers who buy inexpensive Android phones may face hidden risks long before installing anything: their devices could silently join ad-fraud schemes or proxy networks, consuming data and battery while masking attackers' traffic. Because the code sits in firmware with system privileges, ordinary removal may fail, and affected users may not know they are involved. This could erode trust in budget device brands and supply chains, while complicating efforts by carriers, platforms, and security teams to identify and remediate compromised handsets.