Midnight Mimosa Malware Was Built Into Android Phones Before Their Owners Ever Switched Them On

Ethical Hacking Complete Course Zero to Expert
Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.
→ Take the full courseThousands of Android phones in more than 150 countries came out of the box already infected. The owners did nothing wrong. The malware sat in the phone’s own system software, installing apps for two years.
You unpack the phone, switch it on, pick a language and sign in with your Google account. By that moment the malware is already running. It came onto the phone together with Android itself, somewhere between the factory and the shop, and because it is part of the system, the phone treats it as one of its own. It has no uninstall button.
Researchers Adrian Mihai Gozob and Alex Baciu at Bitdefender published the campaign on October 8 and named it Midnight Mimosa. Their own security app, which watches how apps behave on a phone, had flagged an app called com.android.system.lite. The name and the look were those of a core Android component, and it was installing and removing other apps without ever asking the owner.
They found it on thousands of devices in more than 150 countries over roughly two years. Mexico, France and Italy had the most, followed by the United States, Germany, Brazil and Spain. The report gives no total, and I am not going to make one up.
The two models that showed up most are the S200 X, sold under the Doogee brand, and the KINGKONG X from Cubot, both rugged Android phones built on MediaTek chips. Behind those two comes a long list of phones pretending to be something they are not. They call themselves S25 Ultra, S26 Ultra, Note 18 Ultra and i17 Pro Max, and some even report a genuine Samsung model number, on phones that brand never made.
The malware runs with the same rights as Android itself. That means it can put apps on the phone and take them off again, hand out permissions, and run code it downloads from the operators’ servers. The researchers counted at least 32 different apps that it swaps onto phones, dressed up as an app lock, weather apps, a file manager, an icon maker, a tool that pulls text out of photos and audio editors. The app locks have no icon, so the owner never sees them on the home screen. The other apps look like ordinary, working apps.
Right before each install, the malware switches the Play Store off. The researchers believe the point is to keep Google Play Protect, the malware scanner built into Android phones, from looking at what goes in. The new app lands, and the Play Store gets switched back on, after a failed install as well as a successful one. The malware has a backup for that too: as soon as the owner is using the phone, the Play Store comes back on, so nothing looks off. Some versions of the malware go one step further and record Google Play as the place they came from. Open the app details and it looks like you installed it yourself from the store.
All of this is about money. These apps show ads, full screen or laid over whatever is on the display, without the owner touching anything, and the malware clicks on them by itself. A minute after an ad appears, it records that the ad made someone act, what the ad business calls a conversion, while no person touched the ad. Those ad screens block screenshots and screen recordings, with a setting Android calls FLAG_SECURE.
The second income is the phone’s internet connection. One of the hidden apps, an app lock without an icon that calls itself Locket, is built to sign the phone up as a relay, so that other people’s internet traffic passes through it. From then on, a website on the other end sees the owner’s connection instead of the person who sent the traffic. Access like that gets sold, and the researchers write that a bigger botnet earns more. To stay exact: their test phone did sign up, but a correction added later says the server it reached was a sinkhole, taken over to catch this kind of traffic. No traffic went through the phone.
That is what the researchers saw happen. What the malware is able to do goes much further. It gives itself the right to read what is on the screen and tap for the user, a feature Android calls Accessibility. It gives itself access to notifications, which is where your messages and login codes land, and it gets permission to read and write text messages. According to the report, all of it sits ready for the operators the moment they want it, because the malware runs whatever code its servers send down. None of those rights were seen in use. And they do not sit still: Accessibility and notification access get switched on, then off again, over and over.
The malware also sends home the numbers that identify the phone: its IMEI, its Android ID and its MAC address. With them go the SIM country code, the time zone, the model, the Android version and the list of apps the owner installed.
Owners were finding it long before it had a name. On July 2, 2026, the owner of a Cubot KingKong X running Android 16 asked on the XDA forum what com.android.sys.extplv was. His antivirus kept flagging it as malicious. The app called itself System, it asked for access to his text messages, his contacts and his accounts, and Android said it had been installed from Google Play. Within a week others turned up in the same thread with the same app, on phones from both brands.
The owner of a Doogee Fire 3 Ultra found out that it hides. When he plugged the phone into a computer with USB debugging switched on, the way you connect a phone to look inside it, the app removed itself almost straight away. When he unplugged the cable, it was back a few hours later. Deleting it did not hold. Switching it off through ADB held for two days, and then it was switched on again. After a factory reset it came back very quickly.
On August 4 a Cubot owner posted that his Telegram account had been taken over that day. Someone had turned on two-factor authentication on his account and changed the email address, and codes were being requested to move his WhatsApp to another phone. On his phone bill he found that since July 25 his phone had sent around 30 text messages to local numbers, at random times of day, without him typing one. That is one person’s account, and it has not been checked independently. The takeover does fit the access this malware gives itself.
Some phones got it from the maker’s own update. An owner of a Doogee Fire 3 Max traced the infected version back to a software update that arrived through the phone’s own update system. It was DOOGEE-Fire 3 Max-EEA-Android15.0-20260616, 373 MB, released on June 15, 2026, from the update server fota5p.adups.com. On August 5 he wrote that this update was still online. In that version the malware ran as com.android.non.szcz, under the name Android System, the same name as the genuine one.
Cubot gave one of its customers an explanation by email in July. According to the company, a development interface meant only for engineering testing had ended up in the firmware for mass production by mistake, and the cleaned firmware had since passed Google’s security certification. What the researchers took apart is a lot more than a leftover testing interface: 32 rotating apps, ad fraud, a proxy, and the Play Store switched off before each install.
Who put it there is unknown. Firmware on affected phones was signed with certificates that the researchers trace to Shenzhen Zediel Co., Ltd. They are careful about that. The certificate does not prove the company wrote the malware or knew about it, and the malware also turned up on phones without that firmware. It could have gone in at the factory that builds phones for a brand, at the company that puts the software together, at a logistics partner, or further down the chain.
The servers do have a history. Two of them show up in Dr.Web’s records of a click-fraud trojan from late 2025, hidden in copies of popular mobile games, among them a Minecraft-style and a GTA-style game, on Xiaomi’s app store. Those games were clean when they came out and got the malware in later updates. That operation also used a domain that had turned up in Joker malware back in 2021.
The researchers found the same ad-fraud code in 13 apps on Google Play, talking to the same servers. They lack the system rights of the version built into the phones, and the report calls them dangerous all the same. I checked on October 10, and all 13 are still there. Together they have more than 1.4 million downloads, and since Google only shows a minimum, the true number is higher. The biggest is Daily Weather, with more than a million.
This has happened before. In November 2016 the security firm Kryptowire found that the BLU R1 HD, an Android phone sold through Amazon, came with update software from Shanghai Adups Technology. That software sent the full text of the owner’s messages, the contacts, the call history, the IMSI and the IMEI to a server in Shanghai. Text messages and call logs went out at 72-hour intervals. The same software could also install apps remotely.
Antivirus apps let it through, because they trust the software a phone ships with. At the time, the company said it was present in more than 150 countries and regions. Ten years later, the infected Fire 3 Max update came from an adups.com server. The company supplies update servers to phone makers, and nothing in the research shows it put this malware there.
In April 2025 Kaspersky found the Triada trojan built into the firmware of counterfeit phones imitating popular brands, on more than 4,500 devices, with more than $264,000 in cryptocurrency stolen. In June 2025 the FBI warned about BADBOX 2.0: millions of TV boxes, projectors, car screens and digital photo frames, infected before they were sold or during setup, and then rented out as proxies. In February 2026 the same security company found a backdoor called Keenadu in the firmware of Android tablets, and in several cases that firmware arrived through an update carrying a valid signature.
Cubot pushed an update in July for the KingKong 9 and the KingKong X that its customers say removed the app. Doogee told owners the problem was solved with a software update, and its build from July 31, 2026 came out clean on the Fire 3 Max owner’s phone and stayed clean at least until August 24. So if you own one of these phones, install the latest update from the maker first.
Then check what is on it. Switch on USB debugging, connect the phone to your computer and run this straight away:
| |
Anything that comes back, you can switch off with:
| |
using the package name you found. Keep the hiding trick in mind: on some phones the app removes itself as soon as the cable goes in, so an empty result does not prove the phone is clean. And it may not stay off. On the Fire 3 Ultra it switched itself back on after two days.
Another owner found that with the Play Store switched off, the app stopped reinstalling itself, since it comes back through the Play Store. That also stops your other apps from updating, so it is a stopgap.
The researchers say plainly that clearing these phones takes either work on the firmware itself or switching the component off over ADB, and that neither is realistic for most owners. If it keeps coming back after the latest update, the firmware is the problem, and the fix is a clean official firmware or another phone.
If you run Pi-hole, or your router lets you block domains, block api.weatherlive.world and oss.showtimetool.com. The first is where the malware gets its orders and reports its fake clicks, the second is where its modules come from.
And if one of those 13 apps is on your phone, uninstall it:
- โ Daily Weather
- โ CoolWeather
- โ WeatherGo
- โ Lock & Hide
- โ All Deleted Messages Recovery
- โ App Icon DIY
- โ Audify
- โ Wavrge
- โ QuickText Extractor
- โ NoteMaster
- โ QR Pocket
- โ Tap to Translate
- โ Tasky
A phone that calls itself an S25 Ultra or an i17 Pro Max at a fraction of the price is neither a Samsung nor an iPhone, and there is no way to know what software it runs.
You can watch this kind of behavior yourself: put a virtual Android device on your own computer and see with Wireshark which servers it talks to. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.
โ Join my complete ethical hacking course
Hacking is not a hobby but a way of life.
Sources:
Bitdefender Labs | XDA Forums | Kryptowire | Kaspersky Securelist
Stay updated
Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.