Some cheap Android phones have malware directly in the system, researchers warn. It cannot be uninstalled

  • Researchers have uncovered malware embedded directly in the system of some cheap Android phones
  • It appeared, among others, on Doogee S200 X and Cubot KingKong X models
  • It cannot be removed by conventional uninstallation

Sdílejte:
Adam Kurfürst
Adam Kurfürst
10. 10. 2026 04:30
Advertisement

Anyone who orders a phone for a few thousand from an online marketplace usually expects a worse camera or a slower chip. However, the security firm Bitdefender is now warning of a much more unpleasant price for the low cost. The campaign named Midnight Mimosa works by having malware on the phone before the owner even turns it on for the first time.

Mainly cheap Chinese phones are affected

According to Bitdefender’s report, malicious code is hidden in the firmware of cheap devices with MediaTek chips from multiple manufacturers. In approximately two years, researchers have detected it on thousands of phones in over 150 countries. Most frequently in Mexico, France, and Italy, followed by the USA, Germany, Brazil, and Spain.

Most infected units reported themselves as Doogee S200 X and Cubot KingKong X, which are rugged phones from lesser-known Chinese brands. However, they can also be found in the Czech Republic. The rest are mainly unbranded devices and counterfeits posing as flagships. Models like „S25 Ultra“, „S26 Ultra“ or „i17 Pro Max“ appear in the data, which have nothing in common with Samsung or Apple.

Who smuggled the malware into the system is not yet clear. Part of the affected firmware was signed with certificates from the Chinese company Shenzhen Zediel, but Bitdefender emphasizes that this does not prove its involvement. According to them, the malicious code could have entered the system at the manufacturer, the firmware supplier, or anywhere else in the supply chain.

Similar experiences are shared by owners on the XDA forum. Users of Cubot and Doogee phones describe suspicious applications that reappear after being removed. One Doogee Fire 3 Max owner even claims that an official system update brought him malware. After reverting to an older version, it allegedly disappeared and returned with a new update. According to BleepingComputer, manufacturers have not yet publicly explained how the malicious code got into their firmware.

What does the malware cause?

The core of the campaign consists of applications that masquerade as part of Android. In the app list, they are simply named „System“ and have no icon. However, thanks to system permissions, they install and delete other applications, grant them permissions, and download new code from a server without the owner’s knowledge. Bitdefender has thus counted at least 32 masked applications that rotate on phones – from weather apps to app lockers and sound editors.

The whole purpose is mainly to make money. The injected applications display ads in invisible windows and click on them themselves, so advertisers pay for impressions that no one saw. Another module turns the phone into a so-called residential proxy. Foreign traffic can then flow through your connection, appearing as if it originated from you, and is useful, for example, for masking attacks. Researchers verified that the command and control server indeed registers new devices. However, it did not assign any traffic to their test phone for forwarding.

Furthermore, the malware tries to bypass Google’s protection. Just before installing another application, it disables the Play Store, and with it, Google Play Protect’s checks, and then re-enables it after installation. Some variants also pretend that the injected applications originate from Google Play.

The access that the malware enables itself is also concerning. This includes accessibility features, notification reading, and SMS reading. Although Bitdefender did not observe operators actively abusing these, with such permissions, it is possible to read screen content and verification codes from SMS, which are precisely the capabilities on which banking Trojans rely. Whether operators will ever exploit them is entirely up to them.

Researchers also found the same advertising code in 13 applications on Google Play, published by developers operating as fivedev and CPS Developer. These include weather apps, QR code readers, note-taking apps, and sound editors. Although they cannot install additional software without system permissions, Bitdefender states that they display ads even outside the application itself, even when the phone is not currently in use.

A regular user cannot get rid of the malware

Not through conventional means. The malware resides in the system partition, so it cannot be uninstalled from the settings. According to Bitdefender, the only solution is to modify the firmware, or disable the malicious component via ADB from a computer, which most owners of cheap phones would not dare to do.

If you have a Doogee, Cubot, or another cheap model from an unknown brand, it’s worth checking for system updates first. Some XDA users report that manufacturers have since released firmware that removed the infection. More experienced users can look for packages named by Bitdefender in the list of system applications, such as com.android.system.lite, com.android.sys.prot, or com.android.sys.gmsprot. If the phone installs applications you didn’t download on its own, or shows ads outside of applications, it’s time to consider replacing it.

Would you buy a cheap phone from an unknown brand from an online marketplace after this news?

Sources: Bitdefender, BleepingComputer, Android Authority, XDA

About the author

Adam Kurfürst

Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author

Adam Kurfürst
Sdílejte: