Security researchers at Bitdefender have found that some low-cost Android smartphones come with malware already installed before they are sold. According to the researchers, a malware strain named “Midnight Mimosa” is pre-loaded in the firmware of certain Android phones.

Firmware is the special software required to run a phone’s hardware, which means the malware is present on the device before it is even switched on. Unlike a regular app, it cannot be uninstalled or removed. Because of this, buyers may face security risks from the moment they begin using the phone.

According to Bitdefender’s researchers, Midnight Mimosa operates through a persistent system app embedded in the phone’s firmware, which gives the malware access at the system level. Using this advantage, it can install and delete apps on the device, download additional code from remote servers and grant permissions to various applications.

The researchers also uncovered 32 disguised apps linked to this fraudulent activity. These apps are used to generate fake ad views and commit click fraud. By carrying out fake ad activity without the user’s knowledge, the ring behind it can earn financial benefits. The malware also uses special techniques to avoid detection. While running its harmful operations, it can secretly and temporarily shut down Google Play Store operations, an attempt to slip past Google’s Play Protect security while installing malicious apps.

Midnight Mimosa has mainly been found on low-cost Android phones from various brands built on MediaTek platforms. Most of the affected devices are from lesser-known brands, although they are available in more than 150 countries. However, the researchers did not disclose which specific phone models come with the malware pre-installed.

Source: Android Police