Bitdefender researchers have identified a malware campaign called Midnight Mimosa that can be embedded in the software of low-cost Android devices before sale. This malware operates stealthily, allowing it to install and remove applications without user knowledge, generate fraudulent advertising activity, and convert devices into residential-proxy relay nodes for a botnet. It has been found on MediaTek-based, white-label devices marketed under misleading names. Users should be cautious of suspiciously cheap devices and look for signs of infection, such as unexplained ads, unfamiliar apps, sudden battery drain, and discrepancies in model names. Standard uninstallation or factory resets may not remove this malware, and users are advised to update their devices, review app lists, and contact sellers for refunds or replacements if they suspect infection. Mobile protection solutions can help monitor app behavior and alert users to potential threats.