# Researchers find firmware malware on low-cost Android phones across more than 150 countries

_Published Thursday, October 8, 2026 at 4:06 PM EDT · Security · Latest · Tier 2 — Notable_

![Researchers find firmware malware on low-cost Android phones across more than 150 countries — Primary](https://www.bleepstatic.com/content/hl-images/2023/05/25/Android_malware.jpg)

Bitdefender researchers discovered malware embedded in low-cost Android phone firmware that can silently install applications, generate advertising fraud and register devices as residential proxies, BleepingComputer reports. The campaign, called Midnight Mimosa, affected thousands of devices across more than 150 countries over approximately two years.

The malware runs with system privileges and downloads additional modules. It temporarily disables the Google Play Store before installing malicious applications to evade detection, then re-enables it. Ordinary application removal cannot uninstall the firmware components; cleanup requires changes to firmware or disabling components through Android Debug Bridge.

Researchers confirmed that the proxy infrastructure accepted device registrations, but their test device received no relay targets, leaving active traffic forwarding unconfirmed.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/)

---
Canonical: https://techandbusiness.org/newswire/PAqwLFkPoZerTGR5e7MFCg
Published: 2026-10-08T20:06:49.443Z
Story chronology: 2026-10-08T19:20:33.000Z
Retrieved: 2026-10-08T23:18:48.716Z
Publisher: Tech & Business (techandbusiness.org)
