Insights Security & Privacy

Some cheap Android phones arrive with malware you can't remove

8 Oct 2026, 06:00 1 min read

The short version

Bitdefender found malware installed in the factory software of some budget Android phones. Owners cannot remove it in the usual way, and it can quietly add apps and use the phone for fraud.

What happened

The campaign is called Midnight Mimosa. It sits in the phone's built-in software, so it is already there when the owner first switches on. It affects low-cost phones using MediaTek chips, including models named Doogee S200 X and Cubot KINGKONG X, and phones posing as Samsung and Apple models.

The malware can install and delete apps and approve permissions without asking. It uses hidden apps posing as weather, file manager or app lock tools to create fake ad views and clicks. It can also turn the phone into a relay for other people's internet traffic.

Researchers say thousands of devices in over 150 countries were affected over about two years. It is unclear who added the malware or at which stage of the supply chain. Some owners say manufacturer updates fixed it.

Why it matters to you

Because the malware is part of the phone itself, deleting apps will not clear it. Other people's traffic could be routed through your internet connection, though researchers could not confirm this was happening in their test.

The malware also holds access that could read notifications and text messages. Researchers did not see this used, but it could be switched on remotely.

What to do

Buy phones from established brands and reputable sellers. Be wary of prices that look too good, especially for famous models.

Watch for apps you did not install or apps that return after deletion. If you see this, check for a manufacturer update or ask the seller or a technician about reinstalling clean official software.

Sources

Researched and written by our automated news system.