Cheap counterfeit Android phones are showing up with malware already installed.
Security firm Bitdefender says it found thousands of unique devices across more than 150 countries carrying a strain of malware it calls Midnight Mimosa. The malware doesn't need a shady app download or a phishing link to get on the phone. It ships preinstalled, baked in before the buyer even opens the box. Bitdefender ties it to click fraud and botnet operations, meaning the phone's processing power and internet connection get quietly rented out to inflate ad clicks or support larger attacks.
Counterfeit phones already cut corners on components and quality control. Now they're cutting corners on buyer privacy and bandwidth too. Someone chasing a bargain device ends up supplying free infrastructure to a criminal operation, and no antivirus app fixes a compromise baked in at the hardware or firmware level.
The fix here isn't a software update. It's the same advice that's applied to counterfeit electronics for years: a price that looks too good to be true usually is.