Trusence Every claim has a source
Last updated 9 October 2026 Search Türkçe
← All stories
Security

Bitdefender finds firmware malware on low-cost Android phones used as proxies

The campaign reaches beyond infected handsets, with malware-linked apps in Google Play and live proxy infrastructure still taking registrations.

Bitdefender says a firmware-borne Android malware campaign called Midnight Mimosa has been found on low-cost phones, where it can silently install apps, push ad fraud, and even enlist devices as residential proxies. The infections were tied to MediaTek-based devices and appeared on models linked to Doogee and Cubot, as well as phones that pretended to be Samsung and Apple products. According to the researchers, the campaign reached thousands of devices in more than 150 countries over about two years, with the heaviest concentration in Mexico, France, Italy, the United States, Germany, Brazil and Spain. Bitdefender also found 13 Google Play apps connected to the same infrastructure, showing the operation extended beyond preloaded system malware into the public app store. The report says the proxy infrastructure was live and taking registrations, but the team could not confirm that traffic was actually being relayed in their tests.

Why it matters

For owners of affected low-cost Android phones, the risk is not just hidden ads or unwanted installs. The report shows the malware can also recruit devices into a proxy network, while the same operation has already reached into public app distribution, widening the number of places where the abuse can surface and be used.

Sources

  • BleepingComputer