WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Bitdefender finds preinstalled Android malware you can’t uninstall, seen in 150 countries

A view of Melbourne's skyline as seen from Hawthorn, showcasing prominent skyscrapers and urban landscape.
Illustrative photo.Photo by Peter Withiel on PexelsGoogle logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

Bitdefender researchers discovered a campaign called Midnight Mimosa involving preinstalled Android malware (software written to damage a system or steal from it) on low-cost phones from different brands that use MediaTek platforms. Bitdefender finds Midnight Mimosa, preinstalled Android malware on cheap MediaTek phones that fakes ad clicks, drops apps and builds a proxy botnet (a network of hijacked machines controlled by one operator). Google is a software and Internet company based in Mountain View, and its products and services include Software tools.

The malware is built into the device firmware and may be hidden in different system packages depending on the model. It is already on the phone before the owner turns it on for the first time and cannot be removed.

The malware has system-level privileges, allowing it to install and remove apps, grant permissions and download code from a remote server without the user’s knowledge. This gives its operators control over the infected devices and allows them to use them for different purposes, including building a large botnet.

Sources & evidence