LiMP VPN

Preinstalled Malware on New Android Phones: How to Check

Preinstalled Malware on New Android Phones: How to Check

Quick summary: In October 2026, Bitdefender described a campaign called Midnight Mimosa — malware built directly into the factory firmware of budget Android phones on MediaTek chipsets, and into devices disguised as Samsung and Apple models; such phones are sold on Amazon, AliExpress, Temu, and other third-party marketplace listings, and reports note the same models have also turned up on Russian marketplaces. The malware silently installs and removes apps, clicks on ads in the background, and rents out the owner's internet connection as a residential proxy — and a factory reset does not remove it, since the malware lives in the firmware itself. You need to check the phone in the first few days after buying it, before you add your bank, messaging apps, and passwords: Play Protect certification, the real chipset, system apps, and background traffic. If the check confirms infection, that is grounds to return the phone to the seller, not to "clean" it with an antivirus app. And to be upfront: a VPN will not fix a compromised firmware.

What happened: Midnight Mimosa and marketplace smartphones

On October 8, 2026, Bitdefender Labs published a report on a campaign it named Midnight Mimosa. The malware is not a standalone app — it is embedded in the factory firmware of budget Android phones built on MediaTek chipsets. The campaign has been active for roughly two years, from 2024 through 2025, and has reached thousands of devices across more than 150 countries, with the highest concentrations reported in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. The report names specific models — Doogee S200 X and Cubot KINGKONG X — plus devices that visually and by name pass themselves off as Samsung and Apple hardware. The malicious code hides inside system packages named com.android.system.lite, com.android.sys.prot, and com.android.sys.gmsprot — names deliberately chosen to resemble legitimate Android components so they blend in. Through these packages, the device quietly loads roughly three dozen disguised payload apps, and the module itself runs with system-level privileges: it can install and remove apps, grant permissions, and execute code on command from a remote control server, all without the owner noticing.

The report describes two monetization paths. The first is straightforward ad fraud: hidden windows and background ad clicks that drain battery and data without the owner's knowledge. The second is more concerning — the infected phone becomes a residential proxy node, meaning someone else's internet traffic gets routed through the owner's home or mobile IP address. Independent write-ups covering the same Bitdefender report, including Hackread and other outlets published on October 9, confirm three use cases for the infected devices: ad fraud, data collection, and conversion into residential proxy nodes, and note that roughly 13 related apps were also found circulating on Google Play. One notable detail: the campaign specifically targets MediaTek chipsets — devices on Qualcomm Snapdragon do not appear in the report — though that does not mean fakes on other chipsets don't exist. Some manufacturers have already released firmware updates that fix the infection since the report went public, meaning not every unit of an affected model is necessarily compromised.

This is not the first time phones have shipped infected from the factory. In April 2025, Kaspersky described a similar scheme: a new version of the Triada trojan was embedded in the firmware of counterfeit smartphones sold through online stores. More than 2,600 people were affected; the trojan stole access to Telegram and WhatsApp accounts and swapped cryptocurrency wallet addresses copied to the clipboard — Kaspersky estimated the attackers moved roughly $270,000 in cryptocurrency this way. Telling the infected firmware apart from the genuine one was nearly impossible by eye: its build name differed from the official one by a single letter (TGPMIXM instead of the legitimate TGPMIXN). What both cases have in common is that the infection happens in the supply chain, before the phone reaches the buyer — it has nothing to do with anything the owner did afterward. A similar "infected straight out of the box" pattern also shows up on other device types: we covered Android TV boxes shipping with factory malware separately — see infected Android TV boxes — though that piece is about home-network and smart-home isolation, not a personal phone holding your bank and messaging apps.

Why factory malware is worse than the usual kind

  • System-level privileges. The malware is baked into the firmware rather than installed as a regular app, so a normal factory reset does not remove it — the reset simply restores the same infected firmware image.
  • Silent app install and removal. With system privileges, the module can add or remove apps on command from the control server, with no permission prompt and no notification.
  • Residential proxy use. Your IP address starts carrying someone else's traffic, which can trigger CAPTCHAs, temporary blocks, or flags on your own accounts at services that watch for unusual activity from your address.
  • Ad fraud. Hidden background ad clicks and impressions drain battery and mobile data for no visible reason.
  • Data collection. A system-level module can technically access far more than a regular app with limited permissions.
  • Phone-specific stakes. Unlike a TV box, a phone holds your SMS verification codes, banking apps, messaging apps, and possibly a crypto wallet — which is exactly why Triada targeted Telegram and WhatsApp accounts and swapped wallet addresses instead of just serving ads.

Which phones are at risk

There is no useful "dangerous brands" ranking here — instead, watch for warning signs visible before you even buy.

  • A "flagship" price tag on a budget-level listing is the clearest red flag.
  • A model name the manufacturer doesn't actually make — Samsung, for example, has no "Note 18 Ultra" in its lineup.
  • A device marketed as Samsung or Honor but with a MediaTek chip listed, when the genuine model with that name ships with a Snapdragon or Exynos chip.
  • A no-name, no-history seller with reviews mentioning "strange apps," unexpected ads, or fast battery drain.
  • Listings describing a "global version" with no mention of certification and no link to the actual manufacturer.
  • A phone that ships with a third-party app store preinstalled instead of Google Play.

There is a separate, more honest category: legitimate budget brands that are not involved in any counterfeiting campaign but have their own weak spot — infrequent or missing security updates. If the manufacturer of your model has not shipped a patch in a long time, the risk grows over time even without factory malware — we covered this in smartphones without security updates.

How to check a new smartphone: 7 steps on day one

  1. Don't sign into accounts before checkingDon't enter your Google account password, open a banking app, or link a card until you've run at least the basic checks below — that way you risk nothing if the phone turns out to be infected.
  2. Check Play Protect certificationOpen Google Play → profile icon → Settings → "About" or "Play Protect certification" — the device should show "Device is certified." Missing certification is a clear sign the firmware never passed Google's review.
  3. Verify the real hardwareInstall a third-party device-info app (such as CPU-Z or a similar app from Google Play) and compare the actual chipset, memory, and display against what the listing claims. If a device is sold as a Samsung Galaxy S-series phone but the chip info shows MediaTek instead of the official Snapdragon or Exynos, it's a fake.
  4. Check the IMEIDial *#06# to display the IMEI on screen and compare it against the number on the box and in the documentation. For Samsung and Apple devices, also verify the IMEI through the manufacturer's own official check.
  5. Compare the firmware build numberUnder Settings → "About phone," find the build number and compare it against the manufacturer's official page for that model. As the Triada case showed, the difference can be a single letter — and that's not a typo, it's a sign of tampering.
  6. Inspect the system appsUnder Settings → "Apps," enable "show system apps" and scroll through the full list looking for unfamiliar packages named like com.android.system.lite, com.android.sys.prot, or com.android.sys.gmsprot. Also check whether any system utility has permission to install unknown apps — genuine system components should not have that permission; see dangerous app permissions for more on what to look for.
  7. Check idle trafficUnder Settings → "Network & internet" → "Data usage," check how much data the phone uses in the background, especially overnight with the screen off. If possible, also check your router's per-device statistics — noticeable background traffic on a sleeping phone is worth a closer look.

What a check can't tell you

A regular mobile antivirus app detects known threats by signature, but without root access it simply cannot remove a system-level package — it doesn't have the permissions to. A "clean" scan result is therefore not a guarantee: an antivirus can report nothing wrong on a phone where the malware is baked into the firmware and disguised as a system component. If your phone isn't brand new and you suspect something is off right now rather than straight out of the box, see our separate breakdown of ongoing-compromise signs: signs your phone is hacked.

What to do if the phone is infected

If the checks above turned up red flags — an uncertified device, a mismatched chipset, suspicious system packages — here's the order of operations.

First, disconnect the phone from the network: switch on airplane mode or remove the SIM card to cut off communication with the malware's control server. Don't enter any new passwords on this device and don't link new cards — anything typed on an infected phone should be treated as potentially compromised. Don't count on a factory reset to fix it: if the malware is baked into the firmware itself, a reset just restores the same infected image.

Next, check whether the manufacturer has released an official firmware update — as noted above, some vendors shipped fixes after the Bitdefender report went public. Install any such update only from the manufacturer's own site, not from a third-party source. If no fix exists, or you've confirmed the device is a counterfeit of another brand, the sensible move is to file a return through the marketplace's buyer-protection process, citing the item as not matching its description, with screenshots of your checks (Play Protect status, chipset mismatch, suspicious system packages) as evidence.

If you already signed into accounts before noticing the problem, change your passwords from a different, known-clean device, end active sessions in Google, Telegram, WhatsApp, and your banking app, and contact your bank to reissue your card if you suspect card data may have been exposed. There is also a more advanced option — disabling specific system packages via ADB from a computer — but it doesn't guarantee full removal and can break other system functions, so for most people returning the device is the more practical route rather than trying to "clean" the firmware yourself.

Table: what each measure actually protects against

MeasureWhat it protects againstLimitation
Play Protect certificationConfirms the firmware passed Google's baseline reviewDoesn't always catch custom system packages added by the manufacturer
IMEI and real chipset checkCatches a device counterfeiting another brand's flagshipRequires installing a third-party device-info app
Official firmware updateRemoves known infection if the manufacturer shipped a patchNot available for every model or every vendor
Marketplace returnGets rid of the specific infected unitDoesn't undo the risk if you already signed into accounts
VPN on the phoneEncrypts traffic on public networks, hides your IP from sitesDoesn't remove system-level malware or block its link to the control server
2FA / passkeys on accountsLimits the damage if a password has already leakedDoesn't protect against the firmware infection itself

Will a VPN help if the firmware is infected?

To be upfront: a VPN does not remove malware and does not stop it from talking to its control server. On an infected device, a system-level module can, in principle, handle data before it ever reaches the VPN tunnel — so promising protection against this specific malware would be dishonest. A VPN solves a different problem and is genuinely useful in other situations: on a clean, verified phone, it encrypts your traffic on public networks — a café, an airport, a hotel — and hides your real IP address from the sites and services you connect to. That's also useful on other devices, like a laptop or tablet you take while travelling. In the LiMP VPN app, you can always see at a glance whether the tunnel is active right now — nothing runs hidden in the background. LiMP VPN uses the WireGuard protocol, which encrypts traffic with ChaCha20-Poly1305. To set up a VPN on Android, see LiMP VPN for Android; and for a clear breakdown of what a VPN protects against and what it doesn't, see what a VPN protects against.

Checklist: what to do with a new phone

  • Buy from an authorized retailer or the brand's own store, not an anonymous no-history marketplace seller.
  • Check Play Protect certification before signing into Google or a banking app.
  • Compare the advertised model against the real chipset using a device-info app.
  • Keep the box and receipt until your marketplace return window closes — your insurance if you discover a fake later.
  • Turn on automatic system updates and, where available, Android's advanced protection mode — see Android advanced protection mode.
  • Only install banking apps from the bank's official site or Google Play, never from unverified APK files.
  • Turn on two-factor authentication or passkeys on your key accounts.
  • Use a VPN on public Wi-Fi networks, on this phone and your other devices.

Frequently asked questions

Is there a similar virus for iPhone?

Every known campaign of this type targets Android firmware specifically. But there's a related scenario worth knowing: a device sold as an "iPhone" that actually runs Android is a common form of marketplace counterfeit. A genuine iPhone is best verified by its serial number through Apple's own official check.

Are official Xiaomi, Samsung, or Honor phones from authorized stores infected?

The published reports describe counterfeits of these brands and specific named budget models on MediaTek — genuine devices from major manufacturers, bought through their own stores, do not appear in these reports.

Can I return an infected phone to the marketplace?

Yes, this is standard practice for an item that doesn't match its description or advertised specs — file it through the marketplace's return or buyer-protection process, with screenshots of your checks as supporting evidence.

Is it risky to buy Snapdragon phones from the same sellers?

Per Bitdefender, this specific Midnight Mimosa campaign targets MediaTek chipsets, but brand counterfeits in general show up on various chipsets — so the same checks are worth running regardless of which processor a listing claims.

How do I know if my home IP is being used as a proxy?

There's no direct indicator on the phone itself, but warning signs include more frequent CAPTCHAs during normal browsing, unexpected account blocks for "suspicious activity," and noticeable background data use when you check your data usage stats.

Will rooting and installing custom firmware help?

Technically yes, but it's a complex operation that voids the warranty and can break banking apps that require system integrity checks — not a practical fix for most buyers, whereas returning a counterfeit to the seller remains simpler and safer.

Do I need a separate antivirus app on a new phone?

An antivirus app doesn't replace the checks in this article: it catches known threats by signature but, without root, can't remove a system-level package — the core checks are worth doing regardless of whether you also run an antivirus.

Read also

Setup & Devices

How to Block an App's Internet Access on Android and Windows

14 min read
Setup & Devices

Infected Android TV Box: How to Check and Protect Your Network

12 min read
Setup & Devices

How to Install a VPN on a TCL Smart TV in 2026

9 min read

Secure your connection in a minute

Download LiMP VPN for free and feel the difference within a minute.

Download for AndroidPricing