Bitdefender researchers discovered Midnight Mimosa, a malware campaign preinstalled in firmware on low-cost MediaTek Android devices that runs with system privileges to commit ad fraud, collect device data, and operate botnets. The malware cannot be uninstalled and ships under rotating system package names, with 13 related apps also found on Google Play communicating with the same control servers.