Bitdefender’s malware researchers flagged a system app called com.android.system.lite on low-cost Android phones because it kept silently installing and removing other apps. The app turned out to be baked into the firmware of phones including the Doogee S200 X and the Cubot KINGKONG X, and the campaign it belongs to, which Bitdefender named Midnight Mimosa, has been seen on thousands of devices in more than 150 countries over roughly two years.
Because the code sits in the system partition and carries a platform signature, an owner cannot uninstall it the way any normal app is removed.
The preinstalled app that Bitdefender caught installing other apps
The Bitdefender Labs report, titled “The phone was compromised before the user turned it on,” was published on Oct. 8, 2026 and written by Adrian Mihai Gozob and Alex Baciu. It describes com.android.system.lite as a preinstalled, platform-signed system app found on MediaTek-based devices. Companion packages with system-sounding names, including com.android.sys.prot and com.android.sys.gmsprot, round out the framework, which downloads further modules from command servers.
The two highest-volume models are genuine budget brands: Doogee’s S200 X and Cubot’s KINGKONG X. Many other model names in the data are counterfeit flagships such as the “S25 Ultra” and fake iPhone labels, which the authors treat as a spoofing signal rather than a real device inventory. The “thousands” figure is deliberately approximate, with detections led by Mexico, France and Italy, followed by the United States, Germany, Brazil and Spain.
BleepingComputer’s coverage adds a field report: a Doogee Fire 3 Max owner said an official firmware update reinstalled the malware, which vanished after a rollback to an older firmware version and came back when the update was applied again.
Residential proxy and ad fraud: what the infected phones do
The payload Bitdefender dwells on is com.mobile.applock.en, a disguised app locker containing a TCP back-connect proxy. It enrolls each phone as a relay node with a remote server, which can then tell the phone to connect to chosen hosts and pass traffic along, hiding the true origin of that traffic behind an ordinary household connection. That is the residential-proxy business model. The researchers confirmed a control server was live and accepting enrollments, though their test phone was handed no relay targets, so they did not observe traffic being forwarded.
The second revenue stream is advertising. The system app does not itself fake clicks; roughly 32 cover apps disguised as weather tools, file managers, app lockers, OCR utilities and audio editors load real ads through a legitimate ad SDK, often in invisible windows over other apps. Hackread’s summary notes that Bitdefender saw Accessibility and Notification Access permissions switched on automatically but did not see them used for data theft; monetization, not spying, was the focus.
To keep Google Play Protect quiet, the malware temporarily disables the Play Store package, installs its payloads, then switches the store back on. Some variants also edit installer records so that sideloaded apps look as if they came from Google Play. Separately, 13 apps on the Play Store itself carry the same ad-fraud code and talk to Midnight Mimosa infrastructure, using 13 signing certificates and at least two developer accounts, “fivedev” and “CPS Developer.” Those builds lack the privileges to install software silently, but they can still show ads outside their own windows.
Zediel certificate, system partition and the removal problem
Bitdefender found the firmware signed with a certificate attributed to Shenzhen Zediel Co., Ltd. The authors are explicit that this is not proof the company wrote the malware or knew of it, and they say they cannot tell at what stage of the supply chain it was added. None of the outlets that covered the report, including Android Authority, quotes a statement from Doogee, Cubot or Google.
Cleanup is the harder half. A factory reset wipes user data and apps but leaves the system partition alone, so the preinstalled app comes back. Bitdefender says clearing an infected phone needs firmware-level cleanup, or disabling the component over the Android Debug Bridge, which requires USB debugging to be switched on and a computer to drive the commands. The report calls that unrealistic for most owners and puts the durable fix with phone makers and app marketplaces. Android Authority concludes that replacing the device is the most workable option for affected buyers.
Bitdefender Mobile Security’s App Anomaly Detection feature is what first surfaced the pattern. The open item in the record is attribution: the report establishes what the app does and where it sits on these handsets, but it leaves unanswered who placed it there and at which factory or firmware stage, and no vendor has publicly explained how the code reached the firmware images that Doogee and Cubot owners received.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Common allergy, bladder and sleep pills tied to sharply higher dementia odds
- NOAA now gives this winter a 75% chance of the strongest El Nino since 1950
- Doctors warn a silent liver disease now affects one in three American adults
- The FBI told the rest of ShinyHunters to surrender after a 24-year-old was arrested