4 min read

Your Android phone could be infected before you turn it on

Silviu STAHIE

October 09, 2026

Your Android phone could be infected before you turn it on

Bitdefender researchers have uncovered an Android malware campaign, which they dubbed Midnight Mimosa, that can be embedded in the software of some low-cost devices before they are sold.

That means the phone may be compromised before its new owner installs a single app, signs in to an account, or even completes the first setup screen.

The malware can quietly install and remove other apps, generate fraudulent ad activity, and turn affected phones into residential-proxy relay nodes for use in a botnet. The campaign has been seen on some MediaTek-based, white-label devices, including phones marketed with misleading flagship-style names.

This doesn't mean every inexpensive Android phone is infected. But it’s a useful reminder that a device's source matters as much as the apps you install on it.

Key takeaways

  • Midnight Mimosa can be present in a phone's system software before the device is first used
  • It can silently add unwanted apps and run hidden ad and click fraud
  • Researchers also found evidence that some affected devices can be used as residential proxies, effectively making them part of a botnet
  • Normal app removal may not fix a firmware-level infection; consumers should avoid suspiciously cheap or counterfeit-looking devices and buy from trusted sellers

What makes Midnight Mimosa different

Most people know not to install apps from untrusted websites. Midnight Mimosa changes that because the dangerous components can already be part of the phone's operating system.

Bitdefender's analysis found that the malware posed as a routine system component and ran with powerful system-level rights. In plain terms, it could fetch instructions from remote servers and install or remove extra apps without showing the owner a prompt.

Those added apps were made to look ordinary. Some presented themselves as weather tools, app locks, note-taking utilities, file managers or image and text tools. Behind the scenes, they could load ads in ways the owner might never see, then register false views or clicks to make money for the people behind the operation.

The research also discovered that some payloads could turn a device into a residential-proxy relay. A proxy routes someone else's internet traffic through your connection. When this happens without your knowledge, your phone and network may become part of a larger botnet used to support other activity online.

Why bargain phones can carry extra risk

The affected devices in the investigation were linked to low-cost, multi-brand Android hardware. Some used model names that resemble premium flagship phones, even though the hardware and software did not come from the premium brand.

That doesn't make a low-cost phone automatically unsafe. Many affordable Android devices are legitimate and receive reliable support. The danger rises when a deal seems too good to be true: a supposed current-generation flagship at a ridiculously low price, an unknown seller, vague specifications, poor reviews or a listing that obscures the actual manufacturer.

Signs your Android phone may need attention

Preinstalled malware is designed to stay out of sight, so no single warning sign proves a device is infected. Still, unexpected behavior is worth taking seriously, especially on a newly bought phone.

Watch for unexplained ads appearing over other apps, apps you don't remember installing, sudden battery drain, unusual mobile data usage, frequent overheating or Play Store behavior that seems to switch off and on. You should also be wary if the phone identifies itself with a model name that does not match what you bought, although some of the clones available on the market are pretty convincing.

None of those signs confirm Midnight Mimosa on its own. Ordinary adware, a buggy app, or a battery problem can cause them. But they are a good reason to check the device, run a reputable mobile-security scan and avoid using the phone for sensitive activities until you understand what is happening.

What to do if you are worried

Start with the basics. Update Android and all installed apps, then review the app list and remove anything you don’t recognize. Check whether the device is Play Protect certified and look for a current security-update date in Settings.

If your phone behaves suspiciously, avoid using it for banking, two-factor authentication or storing sensitive documents until it has been checked. Back up personal photos and files, but don’t copy unfamiliar apps or device settings to a replacement phone.

Because Midnight Mimosa is built into the software on affected devices, a regular uninstall or factory reset won’t be enough. The most reliable consumer option is to contact the seller or manufacturer, request a refund or replacement, and choose a device from a recognized brand and retailer. Don't download unofficial firmware or follow random online instructions that promise a quick fix; they can introduce further risks or make the phone unusable.

Stay in control of your Android security

No security tool can prevent every problem caused by a compromised supply chain, but mobile protection can warn you when an app acts suspiciously. Bitdefender Mobile Security for Android helps identify dangerous apps and risky behavior while keeping you informed about threats that may otherwise remain hidden.

Bitdefender Mobile Security for Android identified this new malware using App Anomaly Detection. This feature lets the security solution monitor all app behavior, including apps that seem to belong to the operating system.

Frequently asked questions

What is Midnight Mimosa?

Midnight Mimosa is a malware campaign found on some Android devices. It can be embedded in the device's system software and then install unwanted apps, commit ad fraud or enrol the device in a botnet.

Can a new Android phone already have malware?

Yes. Most malware arrives after purchase, but firmware-level threats can be included before a phone is sold. This is why buying from trusted retailers and brands matters.

Will a factory reset remove preinstalled malware?

Not necessarily. If the malicious component is part of the system software, a factory reset may not remove it.

Are all cheap Android phones infected?

No. The research concerns a specific campaign and affected device ecosystem. Affordable phones from reputable manufacturers can still be safe choices.

What should I do if I think my phone is compromised?

Stop using it for sensitive accounts, update it, scan it with mobile-security software and contact the seller or manufacturer. If the issue persists, consider replacing the device from a trusted source.

tags


Author


Silviu STAHIE

Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.

View all posts

You might also like

Bookmarks


loader