(Photo by Jaque Silva/NurPhoto
Be careful buying cheap Android phones. Antivirus provider Bitdefender has discovered a malware strain called Midnight Mimosa that’s coming preinstalled on counterfeit devices and products from little-known Chinese brands.
Bitdefender found the malware on “thousands of unique devices across more than 150 countries” over a two-year period, with Mexico, France, Italy, the US, and Germany in the top five.
For buyers in the UAE, Saudi Arabia, and elsewhere in the Middle East, the regional research available for this story does not confirm whether these exact affected models are sold locally or provide regional prices. Treat a phone borrowing a flagship name as a warning sign, not a bargain.
“Many of the affected models are counterfeit devices that borrow flagship names they have nothing to do with,” the company added. The names include “i17 Pro Max”, “i16_Pro_Max,” or “17_Pro_Max” or “S25 Ultra”, “S24 Ultra”, and “Note 18 Ultra.”

(Credit: Bitdefender)

(Credit: Bitdefender)
Bitdefender also discovered malware circulating on devices from Chinese brands Cubot and Doogee, including the Kingkong X, S200 X, and Kingkong 9. At least some of the affected phones contained chips from MediaTek.

(Credit: Bitdefender)
The antivirus provider investigated the problem using its Bitdefender Mobile Security app. Scans flagged a mysterious “android.system.lite” component on the affected phones that appeared dormant. Further investigation found that the component was preinstalled and could not be removed. When active, the component quietly installed and removed “a rotating set of payloads on the same devices,” the report says. The payloads covered “at least 32 unique disguised apps, including fake AppLock, weather, file-manager, icon-tool, OCR, and audio-editors.”
Midnight Mimosa leverages its deep system-level privileges to install or remove other apps and run rogue computer code. “This essentially means its operators could install and delete apps at will, tuning each device to their needs, including making them part of large botnets,” Bitdefender says.
The company suspects the preinstalled malware is targeting downloads of apps that can load genuine ads. If the ads are continually loaded, the app’s developer gets paid, resulting in “click fraud” since the ad views are generated artificially. In other cases, the malware downloaded apps that could secretly turn the Android phone into a residential proxy service for a botnet. Shady developers can sell access to such botnets, giving a way for cybercriminals to hide their true origins and route their internet traffic through a consumer’s device.
Android apps require the developer to sign them with a certificate. In this case, the malware was signed by a Chinese developer called “Shenzhen Zediel,” which appears to be Zedi Technology at Zediel.com. The company develops motherboards around processors for Chinese semiconductor provider Rockchip.
Zedi didn’t immediately respond to a request for comment. In the meantime, Bitdefender says: “How these certificates ended up on those phones — and whether the certificate owner was involved in or aware of the malware deployment — remains unclear.”
It’s possible another company, such as the device’s actual manufacturer, firmware integrator, logistics partner, or other party further down the supply chain, installed the malware using Zedi’s certificate. “The malware arrives in the ROM before the phone is sold, but identifying the specific party responsible for its inclusion requires information beyond the scope of this technical analysis,” Bitdefender added.
The company also discovered click fraud associated with malware circulating across 13 apps on the Google Play Store. “While they do provide functionality, they also load and display ads outside the app, sometimes even when the user isn’t even using the phone,” the report says.
At least some of the apps remain available. Google didn’t immediately respond to a request for comment.
For affected phone owners, Bitdefender says the malware cannot be easily removed. “Clearing the device requires firmware-level cleanup or disabling the component over ADB, and neither is realistic for most people who own these phones. The durable fix sits with the vendors and the marketplaces that ship and sell the affected firmware,” the report says.
Android phone availability and safety in the UAE and Saudi Arabia
The regional information available for this story does not verify whether the named affected phones are offered by retailers in the UAE or Saudi Arabia, and it provides no reliable local pricing. If you’re considering an unfamiliar low-cost Android phone, check the exact model and seller carefully; a familiar flagship name alone does not establish that the device is genuine or safe.
Bitdefender published the report after another antivirus provider, Kaspersky, also discovered malware being preinstalled on cheap Android phones and tablets.
