decrypted · 9 october 2026 · vulnerabilities and patching · supply chain · uk policy and law

Malware in the box: cheap Android phones that arrive already compromised

Bitdefender published research this week on Midnight Mimosa, malware that ships inside the firmware of cheap Android phones, installed before the owner ever switches the device on. It is a different problem from this morning's story about state hacking kit, and it asks an awkward question of anyone who buys phones for staff: who checked what was already on the box?

What Bitdefender found

Bitdefender reports thousands of affected devices in more than 150 countries, observed over roughly two years. Mexico, France and Italy lead, followed by the United States, Germany, Brazil and Spain. The reporting does not name the UK, so this is a pattern, not a UK incident count.

The handsets use MediaTek chips and are low-cost, white-label or counterfeit models, some labelled to imitate flagship Samsung and Apple names. Bitdefender found a system app, signed with the platform key, sitting in the system partition. Because it is part of the firmware, it cannot be uninstalled in the normal way.

How the trick works

Think of a hotel room where a previous guest has cut a copy of the master key and left it with the cleaner. The lock works, the room looks tidy, and nobody asks who else can walk in. Here the platform signature is the master key: the app can silently install and remove other apps, grant permissions and pull extra code from a remote server.

The observed behaviour is mostly commercial: ad and click fraud, and proxy software that turns the phone into a relay for other people's traffic. Bitdefender also says the malware can switch on Accessibility, notification and SMS permissions on demand, though it did not see that used. Before installing a payload, it turns off the Google Play Store, which hosts the Play Protect scanner, then turns it back on afterwards. A scanner that has been switched off cannot object.

Who is accountable

Some firmware carries a signing certificate naming Shenzhen Zediel, but Bitdefender says that shows only the firmware supply chain, not that the company wrote the malware or knew about it. The insertion point could be the original manufacturer, a firmware integrator, a logistics partner or another intermediary.

This is where Secure by Design earns its keep. The UK product security regime, in force since 29 April 2024 and enforced by the Office for Product Safety and Standards, covers manufacturers, importers and distributors. Its three requirements are banning universal default passwords, publishing how to report security issues and publishing minimum security update periods. Notice what is absent: none of them tests whether the firmware is clean. A phone can tick every box and still carry a pre-installed passenger.

What it costs to apply

Buy from suppliers who will name the manufacturer, and write that into the contract. Be wary of extremely cheap handsets and anything imitating a flagship name, as Bitdefender advises. Because removal needs firmware-level cleanup that most owners cannot do, a compromised phone is realistically a replaced phone, so the cheapest control is not buying it. Opinion, not advice: a director's test is whether anyone can say who built the firmware on the phones in your pocket, and what they would do if it were wrong.

Also this week

Vulnerability: Citrix NetScaler and SonicWall. Citrix has patched CVE-2026-107406, a memory overflow rated 9.5 on the CVSS v4.0 scale that can lead to remote code execution or denial of service. It matters only if the appliance is configured as a SAML service provider or identity provider, and Citrix publishes commands to check for that. Fixed builds include 14.1-73.46 and 13.1-64.29. Citrix-managed cloud services are updated by Citrix itself. The bulletin does not say whether it is being exploited. Separately, SonicWall fixed a pre-authentication flaw, CVE-2026-102255, rated CVSS 10 in its SMA1000 appliances, and says it has no evidence of exploitation. Both product families sit on the edge of the network by design, which is exactly why the design question is whether they need to be reachable from the whole internet at all. Check the configuration today, then check the exposure.

Ransomware: a recovery firm accused of paying the gang itself. US prosecutors have charged Zohar Pinhasi, owner of the Florida firm MonsterCloud, with wire fraud and conspiracy to commit wire fraud. The indictment alleges the firm advertised proprietary decryption tools but secretly paid ransoms of about $8 million, then billed clients about $19 million. In one 2023 case, an alleged $8,200 ransom became a $150,000 fee. Two ransomware negotiators received four-year sentences in May for related conduct. These are allegations: he is presumed innocent, and MonsterCloud did not respond to The Record's request for comment. The lesson for UK boards is procedural. Ask any recovery supplier, in writing, whether they negotiate or pay, who authorises it, and what you will be invoiced.

Sources

If you want help working out who built the devices and appliances your organisation depends on, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.