Midnight Mimosa Malware Ships Preinstalled on Cheap Android Phones, Led by Doogee S200 X and Cubot KingKong X
Midnight Mimosa, a malware family that ships inside the firmware of low-cost Android phones, has reached thousands of devices in more than 150 countries over about two years, Bitdefender researchers reported on Thursday, October 8, 2026. The United States ranks fourth by detections, behind Mexico, France and Italy. The two highest-volume models are the Doogee S200 X and the Cubot KingKong X.
- What it is: a system app preinstalled in phone firmware, named com.android.system.lite with the label "System"
- Phones affected: budget handsets on low-cost MediaTek chips, led by the Doogee S200 X and Cubot KingKong X, plus fake "Galaxy S26 Ultra" and "iPhone 17 Pro Max" clones
- Where: 150+ countries; most detections in Mexico, France, Italy, the US, Germany, Brazil and Spain
- What it does: ad and click fraud, silent app installs, remote code loading, and turning the phone into a proxy node
- Removal: not possible through a normal uninstall

Which Android phones carry Midnight Mimosa?
Midnight Mimosa shows up on cheap phones built on MediaTek platforms, with one board name in the research tied to the MT6762 chip. Bitdefender has not published a full device list. Besides the Doogee S200 X and Cubot KingKong X, the researchers found firmware that spoofs flagship names, including "S24 Ultra", "S25 Ultra", "S26 Ultra", "i17 Pro Max" and even the Samsung model code SM-S938B, all on non-Samsung hardware.
That matters for US shoppers buying from third-party marketplace sellers. A phone sold as a bargain Galaxy S26 Ultra that does not match the real Samsung Galaxy S26 Ultra specs is the exact kind of device this campaign lives on.
What the malware does once the phone is on
The core app is platform-signed, so Android treats it as part of the operating system. From there it can install and remove apps without a prompt, grant permissions, and load new code from its servers. Bitdefender counted at least 32 disguised apps pushed this way, posing as weather tools, app lockers, file managers, OCR tools and audio editors.
The payloads generate fake ad impressions and clicks, collect identifiers such as the IMEI, Android ID and MAC address along with the list of installed apps, and register the phone as a residential proxy node. Before each silent install, Midnight Mimosa briefly disables the Google Play Store app and switches it back on afterwards, which keeps Play Protect out of the way.
What the research confirms, and what it doesn't
Details vary across the published accounts, so here is where each point stands as of October 9.
| Question | What is established |
|---|---|
| Is the proxy network active? | The control server accepted Bitdefender's test device, but that device never received traffic to relay, so live forwarding is unconfirmed |
| Have phone makers patched it? | Bitdefender reports no vendor fixes. Some owners say a firmware update removed it, while one Doogee Fire 3 Max owner said an official update put it back |
| Who planted it? | Unknown. The tampering happened somewhere in the supply chain, and no maker has explained how |
| Is Google Play involved? | 13 Play Store apps carry the same ad-fraud code, signed by at least two developer accounts. It is not clear whether they have been removed |
| Has Google commented? | No Google statement has been published |
How to check a budget Android phone
Start with Google's own certification check, which tells you whether Google has compatibility test results for your device. In the Play Store app, tap your profile icon, then Settings, then About, and read the Play Protect certification line. Google warns that an uncertified device may be less secure and may not get updates. A certified result does not prove the phone is free of Midnight Mimosa, but an uncertified clone is a red flag.
Next, look for the package names Bitdefender published: com.android.system.lite, com.android.sys.prot, com.android.sys.gmsprot and com.android.non.szcz, plus dropped apps such as com.mobile.applock.en and com.dmstudio.weather. Bitdefender also lists the MAC address prefix A0:53:94 as a device-level warning sign.
If you find a match, there is no simple fix. The researchers say cleanup needs firmware-level work or disabling the component over ADB, which is unrealistic for most owners. Replacing the phone, or returning it to the seller, is the practical route. Genuine Samsung Galaxy phones get regular security patches, such as the Samsung October 2026 security update, and if a phone runs hot for no clear reason, our Android overheating fixes guide covers the usual causes.
Frequently Asked Questions
What is Midnight Mimosa malware?
Midnight Mimosa is Android malware that Bitdefender researchers reported on October 8, 2026. It ships inside the firmware of low-cost Android phones as a system app called com.android.system.lite, and it is used for ad fraud, click fraud, silent app installs and turning phones into proxy nodes.
Which phones have Midnight Mimosa preinstalled?
Bitdefender says the two highest-volume models are the Doogee S200 X and the Cubot KingKong X, both budget phones on MediaTek chips. It also found the malware on clone phones that pretend to be a Galaxy S24, S25 or S26 Ultra or an iPhone 17 Pro Max. No complete device list has been published.
Is Midnight Mimosa in the US?
Yes. Bitdefender's detections span more than 150 countries, and the United States ranks fourth, behind Mexico, France and Italy and ahead of Germany, Brazil and Spain. The research gives no per-country device counts.
Can I uninstall Midnight Mimosa from my phone?
Not through a normal uninstall, because the malware is a platform-signed system app built into the firmware. Bitdefender says removing it takes firmware-level cleanup or disabling the component over ADB, which most owners cannot realistically do. Replacing the phone, or returning it to the seller, is the practical option.
Are Google Play apps linked to Midnight Mimosa?
Bitdefender found 13 apps on the Google Play Store with the same ad-fraud code as Midnight Mimosa, signed by at least two developer accounts. Examples include com.dmstudio.weather and picturetranslate.extractor.text.lite. Google has not said publicly whether the apps were removed.


