Bitdefender published its investigation of Midnight Mimosa on October 8, 2026, describing a campaign it observed during 2024–2025 on some low-cost Android devices. The reported chain began with a persistent system app installed in device firmware before the phone’s first use, which could silently deploy payloads linked to ad fraud and residential-proxy activity.
How the firmware app deployed other software
In the analyzed build, the central component was com.android.system.lite, a platform-signed system app that Bitdefender described as persistent. Unlike an ordinary downloaded app, it had system-level privileges: it could install and remove packages silently, grant permissions and load code from a remote source. Related versions appeared under other system-like names, including com.android.sys.prot, com.android.sys.gmsprot and com.android.sys.bcprot.
Bitdefender reported that plugins temporarily disabled the Google Play Store package before installing partner apps, then enabled it again. The investigation interpreted that sequence as an attempt to evade Google Play Protect. It also identified at least 32 disguised payload apps, presented as tools such as AppLock, weather, file management, icon customization, OCR and audio editing.
Ad fraud and residential-proxy capability
The reported payloads supported ad and click fraud, collected information about devices and installed apps, and included residential-proxy functionality. A residential proxy routes network traffic through an internet connection associated with a regular household device; the reported capability could therefore turn an affected device into a relay point.
The proxy capability and the observed test result were separate findings. In its account of a tested sample, Bitdefender later identified the observed IP address as a sinkhole rather than a command-and-control server. The test node received no relay targets, and no traffic was relayed during that observation.
A separate route through Google Play
Bitdefender also reported 13 Google Play apps carrying related ad-fraud code. Those apps used 13 signing certificates across at least two developer accounts. They were a separate distribution channel from the persistent component installed in firmware.
What the telemetry and certificate findings say
Bitdefender reported that its telemetry recorded thousands of unique devices across more than 150 countries. That is the investigation’s observed-device count and geographic reach; its report also associated some device-model strings with brands, while warning that strings could be spoofed or counterfeit.
Bitdefender reported finding firmware-signing certificates bearing Shenzhen Zediel Co., Ltd.’s name. The investigation did not identify who integrated the malware into the firmware or establish whether the certificate holder knew about it.