Bitdefender: malware ships in cheap Android firmware. The UK is 3.49% of its chart; no device count above 199
Bitdefender says malware ships in the firmware of cheap MediaTek Android phones and cannot be uninstalled. Its text never mentions the UK, but its chart gives the UK 3.49% of observed infected devices; the only device counts it prints stop at 199.
By Parminder Kumar Sharma · · 28 min read

The report's largest device count is 199, and the UK appears only in a chart
Bitdefender Labs published its Midnight Mimosa report on 8 October 2026. It says malware ships preinstalled in the firmware of low-cost Android phones built on MediaTek platforms, and that the campaign was observed on "thousands" of devices in more than 150 countries over roughly two years. We read the whole post, its tables and its images, and The Record's coverage as a pointer.
The largest device count the report prints is 199. It is in a table that the report says counts "a single studied enabler's installed portfolio": nine rows, of 199, 199, 182, 139, 120, 97, 2, 1 and 1 devices. The rows sum to 940 (derived). A device can appear in more than one row, so that one component was on at least 199 and at most 940 devices (derived). The text puts no number behind "thousands".
The UK is not named anywhere in the text. It is in one chart, titled "Country distribution by infected devices (two year window)": United Kingdom, 3.49%. That is the eighth of the twelve named countries by share (derived), after the seven the text names: Mexico 13.02%, France 12.48%, Italy 9.97%, the United States 8.36%, Germany 7.30%, Brazil 7.02% and Spain 6.72%. The 13 bars sum to 100.00% (derived), with "rest of the world" at 24.20%.
What that does not establish.
- How many phones are infected. "Thousands" is Bitdefender's word for what it observed, not a population, and no exact figure is printed.
- How many are in the UK. 3.49% is a share of a total the report does not give. Applying it to 199 or to "thousands" would be arithmetic on a denominator that is not the chart's.
- That 3.49% is an infection rate. The data come from what the report calls Bitdefender's "insights" and telemetry, and it does not say how its users divide by country. A chart of detections is shaped by where the detecting product is installed as well as by where infected phones are (inference).
- That any UK organisation holds one of these phones, or that any UK seller sold one. The report names no UK seller or buyer.
- Anything about phones on sale today. The report gives no start or end date for its "roughly two years".
What each figure in the report counts, and what it leaves out
Figures printed in the Bitdefender report and what each counts. Source: Bitdefender Labs, 8 October 2026; derived items are this site's arithmetic.
- Figure in the report
- "Thousands" of unique devices, more than 150 countries, roughly two years
- What it counts
- Bitdefender's observation across the whole family of enabler builds
- What it does not give
- An exact count. The start and end of the window: a lineage table in the report dates the campaign 2024 to 2025
- Figure in the report
- 199, 199, 182, 139, 120, 97, 2, 1, 1
- What it counts
- Devices on which one studied enabler installed each of nine packages
- What it does not give
- Unique devices. Derived: between 199 and 940
- Figure in the report
- At least 32 disguised apps
- What it counts
- Distinct cover apps the enablers install
- What it does not give
- How many one phone receives. The enabler in the table installed nine
- Figure in the report
- 13 apps on Google Play
- What it counts
- Play listings that share the ad-fraud code and servers
- What it does not give
- A download count, or whether they were removed
- Figure in the report
- 120 samples
- What it counts
- A list headed "Full sample set (120 MD5 hashes)": system components, droppers, cover apps and Play builds
- What it does not give
- Phones. A sample is a file, not a device
- Figure in the report
- 3.49% (United Kingdom)
- What it counts
- One bar in one chart of observed infected devices
- What it does not give
- A UK count, or the denominator of the chart
- Figure in the report
- 11.33% (most common model string)
- What it counts
- One bar in a second chart of unique devices by reported model string
- What it does not give
- That every phone of that name is affected: the report says the model column can be spoofed
| Figure in the report | What it counts | What it does not give |
|---|---|---|
| "Thousands" of unique devices, more than 150 countries, roughly two years | Bitdefender's observation across the whole family of enabler builds | An exact count. The start and end of the window: a lineage table in the report dates the campaign 2024 to 2025 |
| 199, 199, 182, 139, 120, 97, 2, 1, 1 | Devices on which one studied enabler installed each of nine packages | Unique devices. Derived: between 199 and 940 |
| At least 32 disguised apps | Distinct cover apps the enablers install | How many one phone receives. The enabler in the table installed nine |
| 13 apps on Google Play | Play listings that share the ad-fraud code and servers | A download count, or whether they were removed |
| 120 samples | A list headed "Full sample set (120 MD5 hashes)": system components, droppers, cover apps and Play builds | Phones. A sample is a file, not a device |
| 3.49% (United Kingdom) | One bar in one chart of observed infected devices | A UK count, or the denominator of the chart |
| 11.33% (most common model string) | One bar in a second chart of unique devices by reported model string | That every phone of that name is affected: the report says the model column can be spoofed |
What Bitdefender analysed, and whose telemetry this is
The investigation began, the report says, when App Anomaly Detection, a technology in Bitdefender Mobile Security, flagged a component that looked like part of Android but behaved like nothing of the sort. The field data it then cites are "insights" and "telemetry" from devices running Bitdefender's product, plus the 120 samples. It does not say how many devices or firmware images were examined, whether Bitdefender bought or tested any phone, or how any device was obtained.
Its reasons for calling the component firmware are listed: it is signed with the platform key, the model strings include region-coded build names and raw board names where a model name should be, and the owner cannot remove it. None is described as inspecting a firmware image. That is reasonable inference from telemetry, and this briefing treats the firmware conclusion as Bitdefender's finding, not as something we tested.
The Record says one device the researchers examined cost about $180. That figure is not in Bitdefender's post. The only listing the post reproduces is a screenshot of a phone sold under a flagship's name on a mainstream online marketplace, marked new and priced at £138.95 in pounds sterling, which suggests (inference) a UK-facing page. The caption does not name the marketplace and does not say the pictured phone carried the malware. This briefing does not name the marketplace either.
Method, not accusation. Bitdefender sells the product whose detection began the work, and its legal note says it "does not claim that any named entity has engaged in illegal conduct". That is a reason to know whose telemetry this is, not to doubt the behaviour described, which is specific and internally consistent. We did not analyse a sample or a device. Where this briefing says a component does something, the source is Bitdefender's description.
The country chart, read from the image
The report's text names seven countries and gives no percentages. The values are printed on the bars of one chart image, which we read directly and checked: the 13 bars sum to 100.00%. Rows below are in the chart's order, with a running total that is this site's arithmetic.
Bitdefender's chart "Country distribution by infected devices (two year window)", read from the image on 8 October 2026. The running total is derived.
- Country as charted
- Mexico
- Share of observed infected devices
- 13.02%
- Running total (derived)
- 13.02%
- Country as charted
- France
- Share of observed infected devices
- 12.48%
- Running total (derived)
- 25.50%
- Country as charted
- Italy
- Share of observed infected devices
- 9.97%
- Running total (derived)
- 35.47%
- Country as charted
- United States
- Share of observed infected devices
- 8.36%
- Running total (derived)
- 43.83%
- Country as charted
- Germany
- Share of observed infected devices
- 7.30%
- Running total (derived)
- 51.13%
- Country as charted
- Brazil
- Share of observed infected devices
- 7.02%
- Running total (derived)
- 58.15%
- Country as charted
- Spain
- Share of observed infected devices
- 6.72%
- Running total (derived)
- 64.87%
- Country as charted
- United Kingdom
- Share of observed infected devices
- 3.49%
- Running total (derived)
- 68.36%
- Country as charted
- Canada
- Share of observed infected devices
- 2.74%
- Running total (derived)
- 71.10%
- Country as charted
- Romania
- Share of observed infected devices
- 1.76%
- Running total (derived)
- 72.86%
- Country as charted
- Poland
- Share of observed infected devices
- 1.54%
- Running total (derived)
- 74.40%
- Country as charted
- Thailand
- Share of observed infected devices
- 1.40%
- Running total (derived)
- 75.80%
- Country as charted
- Rest of the world
- Share of observed infected devices
- 24.20%
- Running total (derived)
- 100.00%
| Country as charted | Share of observed infected devices | Running total (derived) |
|---|---|---|
| Mexico | 13.02% | 13.02% |
| France | 12.48% | 25.50% |
| Italy | 9.97% | 35.47% |
| United States | 8.36% | 43.83% |
| Germany | 7.30% | 51.13% |
| Brazil | 7.02% | 58.15% |
| Spain | 6.72% | 64.87% |
| United Kingdom | 3.49% | 68.36% |
| Canada | 2.74% | 71.10% |
| Romania | 1.76% | 72.86% |
| Poland | 1.54% | 74.40% |
| Thailand | 1.40% | 75.80% |
| Rest of the world | 24.20% | 100.00% |
The top three countries, Mexico, France and Italy, hold 35.47% (derived: 13.02 + 12.48 + 9.97). The seven the text names hold 64.87% (derived). The UK's 3.49% is about 48% of Germany's 7.30% and 52% of Spain's 6.72% (derived), and above Canada's 2.74%.
Bitdefender's reading is that no single country dominates and that the weight sits in two regional centres, Western Europe and the Americas, which it says is what hardware moving through international online marketplaces looks like, rather than a regional channel. That is Bitdefender's inference from the shape. The report shows no sales or shipment data.
A comparison shows how far to trust the shape of any one vendor's chart. Kaspersky's February 2026 analysis of a different firmware-resident family, Keenadu, which Bitdefender cites as an earlier case of this way of shipping malware, counted 13,715 users in its telemetry and named Russia, Japan, Germany, Brazil and the Netherlands as its top five. Two vendors, two rankings: each chart is a view of one vendor's customers (inference), not a map of where phones are infected.
A second chart ranks model strings, and its long tail is the point
A second chart, headed "Unique devices", has no caption in the text. It ranks the model strings that devices report. We read it from the image, and its 16 bars sum to 100.00% (derived). The first five bars are below, with the report's own gloss where the text gives one.
Bitdefender's chart "Unique devices" by reported model string, first five bars read from the image on 8 October 2026. Model strings are what the firmware reports, not verified product names.
- Model string as reported
- Most common string, a budget brand's model name
- Share of unique devices
- 11.33%
- What the report says
- The report associates it with a budget handset brand, which this briefing does not name
- Model string as reported
- Second string, another budget brand's model name
- Share of unique devices
- 4.08%
- What the report says
- The report associates it with a second budget brand, also not named here
- Model string as reported
- Third string, a budget brand's model name
- Share of unique devices
- 3.35%
- What the report says
- Not discussed in the text
- Model string as reported
- S25 ULTRA
- Share of unique devices
- 2.91%
- What the report says
- An imitation flagship name, in the report's account
- Model string as reported
- SM-S938B
- Share of unique devices
- 2.54%
- What the report says
- A Samsung-looking model code that the report says appears on devices that are not Samsung
- Model string as reported
- Ten more strings, each 0.97% to 1.42%
- Share of unique devices
- 11.57%
- What the report says
- Region-coded builds such as J10_EEA and Q6_EEA, which the report calls typical of no-name ODM devices, and others not discussed
- Model string as reported
- "Others"
- Share of unique devices
- 64.22%
- What the report says
- A long tail
| Model string as reported | Share of unique devices | What the report says |
|---|---|---|
| Most common string, a budget brand's model name | 11.33% | The report associates it with a budget handset brand, which this briefing does not name |
| Second string, another budget brand's model name | 4.08% | The report associates it with a second budget brand, also not named here |
| Third string, a budget brand's model name | 3.35% | Not discussed in the text |
| S25 ULTRA | 2.91% | An imitation flagship name, in the report's account |
| SM-S938B | 2.54% | A Samsung-looking model code that the report says appears on devices that are not Samsung |
| Ten more strings, each 0.97% to 1.42% | 11.57% | Region-coded builds such as J10_EEA and Q6_EEA, which the report calls typical of no-name ODM devices, and others not discussed |
| "Others" | 64.22% | A long tail |
The 15 named strings together hold 35.78% (derived) and "others" hold 64.22%. Three strings that imitate a Samsung flagship's name or code, S25 ULTRA, SM-S938B and S24 ULTRA, hold 6.74% together (derived: 2.91 + 2.54 + 1.29). So a list of models to avoid would cover at most 35.78% of the devices in this chart, and the report says the model column is "a spoofing indicator, not a real device inventory". The report does not say that either brand shipped the component or knew of it, and its legal note says the naming of companies and brands is a technical observation, not an allegation. We found no statement from either brand. A buyer cannot use a model name as a safe list or a block list; certification and a supplier you can name are better tests.
What the report states, and what it does not
Stated and not stated in the Bitdefender report, with the briefing's own searches where a statement from another party would be expected. Read 8 October 2026.
- Question
- Where it sits
- Stated
- Preinstalled in firmware: a platform-signed system component, "on the phone before the owner switches it on for the first time"
- Not stated
- How many devices or firmware images were examined, or how they were obtained
- Question
- Who, and where in the chain
- Stated
- It "could be introduced by an ODM, a firmware integrator, a logistics partner" or another party. Some firmware was signed with certificates bearing the name of a Shenzhen company; Bitdefender says that does not show the company wrote it, shipped it or knew
- Not stated
- The actor. The point of insertion. Any company's knowledge. The payload operator is called a separate actor, and the report links its code to earlier families catalogued by another vendor, which we did not check
- Question
- MediaTek
- Stated
- Devices "built on MediaTek platforms"; one board name is shown as a MediaTek part
- Not stated
- That MediaTek's chips or software are the cause. We found no MediaTek statement. Its October bulletin, published 5 October, lists chipset vulnerabilities and does not mention the campaign
- Question
- Handset brands
- Stated
- The two most common model strings, put at 11.33% and 4.08% of unique devices in a second chart, are associated with two budget handset brands that this briefing does not name. Other devices report imitation Samsung and Apple names, and in some cases a genuine-looking Samsung model code
- Not stated
- That either brand shipped or knew of the component. The report calls the model column "a spoofing indicator, not a real device inventory". We found no statement from either brand
- Question
- What it does
- Stated
- Ad and click fraud through hidden cover apps; device and installed-app information collected; a device enrolled as a relay node; the Play Store switched off around some installs
- Not stated
- The cost to the owner in battery, data or money. Any data theft
- Question
- What it could do
- Stated
- System privileges to install and remove apps, grant permissions and run code supplied remotely. Accessibility, Notification Access and SMS permissions are available
- Not stated
- Use of them. Bitdefender says it did not see Accessibility or Notification Access used, and that what is done with them is the operator's decision
- Question
- Google Play
- Stated
- 13 apps "currently present on Google Play" when it published: genuine Play builds with Play's own signature that share the code and servers but have no system privileges
- Not stated
- Whether Google removed them. We found no Google statement. Google's October Android bulletin, published 5 October, does not mention the campaign
- Question
- Reset and removal
- Stated
- The owner cannot uninstall it ("it can't be uninstalled"). Clearing needs "firmware-level cleanup or disabling the component over ADB", which the report calls unrealistic for most owners
- Not stated
- Whether a factory reset removes it: the words "factory reset" do not appear. Any test of reflashing, or of a maker's clean firmware
- Question
- When
- Stated
- Roughly two years, more than 150 countries, thousands of devices
- Not stated
- Start and end dates. Whether phones on sale now carry it
| Question | Stated | Not stated |
|---|---|---|
| Where it sits | Preinstalled in firmware: a platform-signed system component, "on the phone before the owner switches it on for the first time" | How many devices or firmware images were examined, or how they were obtained |
| Who, and where in the chain | It "could be introduced by an ODM, a firmware integrator, a logistics partner" or another party. Some firmware was signed with certificates bearing the name of a Shenzhen company; Bitdefender says that does not show the company wrote it, shipped it or knew | The actor. The point of insertion. Any company's knowledge. The payload operator is called a separate actor, and the report links its code to earlier families catalogued by another vendor, which we did not check |
| MediaTek | Devices "built on MediaTek platforms"; one board name is shown as a MediaTek part | That MediaTek's chips or software are the cause. We found no MediaTek statement. Its October bulletin, published 5 October, lists chipset vulnerabilities and does not mention the campaign |
| Handset brands | The two most common model strings, put at 11.33% and 4.08% of unique devices in a second chart, are associated with two budget handset brands that this briefing does not name. Other devices report imitation Samsung and Apple names, and in some cases a genuine-looking Samsung model code | That either brand shipped or knew of the component. The report calls the model column "a spoofing indicator, not a real device inventory". We found no statement from either brand |
| What it does | Ad and click fraud through hidden cover apps; device and installed-app information collected; a device enrolled as a relay node; the Play Store switched off around some installs | The cost to the owner in battery, data or money. Any data theft |
| What it could do | System privileges to install and remove apps, grant permissions and run code supplied remotely. Accessibility, Notification Access and SMS permissions are available | Use of them. Bitdefender says it did not see Accessibility or Notification Access used, and that what is done with them is the operator's decision |
| Google Play | 13 apps "currently present on Google Play" when it published: genuine Play builds with Play's own signature that share the code and servers but have no system privileges | Whether Google removed them. We found no Google statement. Google's October Android bulletin, published 5 October, does not mention the campaign |
| Reset and removal | The owner cannot uninstall it ("it can't be uninstalled"). Clearing needs "firmware-level cleanup or disabling the component over ADB", which the report calls unrealistic for most owners | Whether a factory reset removes it: the words "factory reset" do not appear. Any test of reflashing, or of a maker's clean firmware |
| When | Roughly two years, more than 150 countries, thousands of devices | Start and end dates. Whether phones on sale now carry it |
Where the report does not know
Bitdefender is plain about the gap in the middle. Its words are that the malware "arrives in the ROM before the phone is sold" but that naming the party responsible "requires information beyond the scope of this technical analysis". It lists an original design manufacturer, a firmware integrator and a logistics partner as possible points, and says the same firmware is not the only route: devices without the certificate it names carry the same malware. The diagram draws that gap as a gap. The report establishes where the component ends up, not who put it there.
One inconsistency inside the report is worth stating. Its architecture figure labels the first stage "ODM firmware", tagged "MTK, multi-brand", while its text says the point of insertion is not known. We follow the text. The figure names a stage of the chain; it does not establish that a design manufacturer inserted anything.
What it costs the owner, and what the access could do
What was observed is fraud against advertisers, run on the owner's phone. The cover apps show real ads from a legitimate ad network in hidden windows and over other apps, sometimes when the phone is not in use. The report says the fake clicks are issued with no touch and that the ad surface is marked so it does not appear in screenshots or screen recordings. It gives no figure for battery, mobile data or money lost by the owner. Loading and showing ads uses data and power, which is our inference, not a measurement in the report.
Two further behaviours matter more to an organisation. The report says the operators collect device and installed-app information, and that a payload enrols the phone as a relay node, a residential-proxy exit, which it describes as able to reach "arbitrary hosts including the local network". In Bitdefender's own test a freshly enrolled node received no relay targets and no traffic was relayed. A phone on an office network is therefore a possible relay by design, with use not observed.
What the access could do is a different list, and the report keeps it separate. The component runs with system privileges and can install and remove apps, grant them permissions and run code supplied by a remote server. It holds Accessibility, Notification Access and SMS permissions, and the report says it switches the first two on itself, then grants and withdraws them repeatedly. Bitdefender explains what those permissions allow on any Android phone: an accessibility service can read the content of every screen and observe what is typed, notification access can read any notification including chat apps, and SMS access can read one-time codes. It also says it saw neither Accessibility nor Notification Access used, and that what is done with them is a decision the operator makes remotely, not a property of the samples it analysed. Its architecture figure lists "enables accessibility and notification capture" under the operator's remote control; the text says neither was seen used, and this briefing follows the text, because the figure shows the design, not an observation. Android 17's restriction of accessibility services to verified tools applies only with Advanced Protection on, as our earlier briefing set out; neither the Bitdefender report nor that briefing says whether it reaches a platform-signed system component.
Cannot be uninstalled: what the report says about reset, and what others say
The report's claim is precise and narrow. The malware "can't be uninstalled"; because the root component ships in the system partition, an affected owner cannot remove it by the normal route; and clearing the device "requires firmware-level cleanup or disabling the component over ADB", Android's debug bridge, "and neither is realistic for most people who own these phones". The words "factory reset" do not appear in the report. It does not say a reset fails, and it reports no test of one. It also says nothing about a clean firmware image from the maker, or whether any maker has published one.
Two other sources frame the question. Kaspersky's write-up of Keenadu gives the closest comparison. For a malicious system app it says the app cannot be removed because it sits in the system partition, and suggests replacing its function or disabling it over ADB. For a modified system library it says standard Android tools cannot remove it, that the first thing to check is whether the manufacturer has released clean firmware, that flashing firmware yourself can brick the device, and that until the firmware is replaced the device should not be used. The NCSC's guidance on erasing devices, last reviewed on 13 May 2025, says that in nearly all cases a factory reset is all you need to do, and offers reinstalling Android from stock images "available from some OEMs" as an advanced option. That page does not mention firmware, pre-installed software or the supply chain (keyword check). For a white-label handset with no published image there may be nothing to reinstall, which is our inference and not something the report says.
The practical reading, which is ours: replace rather than clean.
Friendly names are not controls, and this campaign uses several
Each label below can be true of an affected phone, on the report's account or, where marked, on our reading.
- "System". The component's label is the generic "System" and its icon is hidden. Its package names sound like parts of Android and change between builds. The report's own line: "The package name is not the threat."
- A valid platform signature. It shows who signed the component, not what the component does. Certificates bearing a company's name on firmware do not show that company's involvement, the report says.
- "Installed from Google Play". On part of its sample set the recorded installer was set to Google Play although the Play signature block was absent. Bitdefender says the installer field cannot be used on its own to clear a sample.
- Play Protect. The report says the Play Store is switched off around some installs, which it reads as probably an attempt to avoid Play Protect detection.
- A Play listing. The 13 Play apps are, in the report's words, builds that "passed Play review".
- The model name. Cheap devices report flagship names, and on some a genuine-looking Samsung model code. The model column, the report says, is a spoofing indicator.
- A Play Store icon. Google's help page says only Play Protect certified devices are eligible to include Google apps such as the Play Store, and that those apps on uncertified devices are not licensed and are not real Google apps. The malware switches the Play Store off and on, so the affected phones had one. Whether they were certified, or ran an unlicensed copy, the report does not say. A Play Store icon is therefore not evidence of certification (inference).
A label records where something came from. A control stops something that should not happen. Briefing 265 found the same shape in a different supply chain: a package release with valid provenance, a trusted publisher and Verified commits, all of which recorded where a build came from and none of which examined what it contained.
What the UK product security regime requires, and what it does not
The regime is Part 1 of the Product Security and Telecommunications Infrastructure Act 2022 and the 2023 Regulations, both in force from 29 April 2024. We read the legislation.gov.uk text, the OPSS guidance and DSIT's policy page.
Smartphones are inside it. Schedule 1 of the Regulations refers to "a smartphone or a tablet computer capable of connecting to cellular networks", while Schedule 3 excepts desktops, laptops and tablets without a cellular connection. A product is a UK consumer connectable product if it is made available to consumers in the UK, or to business customers where identical products are available to consumers (section 54 of the Act), so a small organisation buying a consumer phone is not outside it. The OPSS guidance lists the three security requirements: banning universal default and easily guessable passwords, publishing information on how to report security issues, and publishing information on minimum security update periods.
What the Act and Regulations require of each party, and what the text does not say. Source: legislation.gov.uk text read 8 October 2026; sections and regulations as cited.
- Party
- Manufacturer
- What the text requires
- Meet Schedule 1: no universal or easily guessed default passwords; a published contact for security reports with when the reporter gets an acknowledgement and updates; a published minimum security update period with an end date. Supply a statement of compliance with the product and keep it for the longer of 10 years or the support period (regulation 8)
- What it does not say
- Nothing about malware, firmware integrity or the supply chain. The words are not in the Regulations or in Part 1 of the Act
- Party
- Importer
- What the text requires
- Not make the product available without a statement of compliance, keep a copy (regulation 9), and not make it available if it knows or believes the manufacturer has a compliance failure (sections 15 and 16)
- What it does not say
- Any duty to inspect firmware. A compliance failure means failing a security requirement
- Party
- Distributor
- What the text requires
- Not make the product available without a statement of compliance, or if it knows or believes there is a compliance failure by the manufacturer (sections 22 and 23)
- What it does not say
- Whether an online marketplace operator is a distributor
- Party
- Enforcer
- What the text requires
- OPSS, per its guidance, using compliance, stop and recall notices and monetary penalties. The Act sets penalties at up to the greater of £10 million or 4% of qualifying worldwide revenue (section 38). OPSS says it can publish details of compliance failures
- What it does not say
- That a firmware compromise counts as a compliance failure. OPSS invites contact about suspected non-compliance but does not say what it would do with this
| Party | What the text requires | What it does not say |
|---|---|---|
| Manufacturer | Meet Schedule 1: no universal or easily guessed default passwords; a published contact for security reports with when the reporter gets an acknowledgement and updates; a published minimum security update period with an end date. Supply a statement of compliance with the product and keep it for the longer of 10 years or the support period (regulation 8) | Nothing about malware, firmware integrity or the supply chain. The words are not in the Regulations or in Part 1 of the Act |
| Importer | Not make the product available without a statement of compliance, keep a copy (regulation 9), and not make it available if it knows or believes the manufacturer has a compliance failure (sections 15 and 16) | Any duty to inspect firmware. A compliance failure means failing a security requirement |
| Distributor | Not make the product available without a statement of compliance, or if it knows or believes there is a compliance failure by the manufacturer (sections 22 and 23) | Whether an online marketplace operator is a distributor |
| Enforcer | OPSS, per its guidance, using compliance, stop and recall notices and monetary penalties. The Act sets penalties at up to the greater of £10 million or 4% of qualifying worldwide revenue (section 38). OPSS says it can publish details of compliance failures | That a firmware compromise counts as a compliance failure. OPSS invites contact about suspected non-compliance but does not say what it would do with this |
In the Act's wording a compliance failure is a failure to comply with a security requirement, so the duties to investigate, notify and stop supplying attach to those three requirements. It follows, on our reading and not on any regulator's statement, that a handset could meet all three requirements and still carry a component like this one. A compliant listing proves a contact address and an end date for updates, not clean firmware.
Two parts of the regime are still useful to a buyer. The support period must be published in English, free, without a prior request and in a way a reader without technical knowledge can understand, and the NCSC's Android guide says manufacturers must publish it to comply, so a listing with no end date is a question to put to the seller. And the statement of compliance must accompany the product, so its absence is a second question.
Online marketplaces. The Act, the Regulations, the OPSS guidance and the DSIT page do not contain the words "online marketplace", and none says whether a marketplace operator is a distributor. Bitdefender writes that "the durable fix sits with the vendors and the marketplaces" that ship and sell the firmware; that is its view, not a legal finding. Separately, OPSS and the Department for Business and Trade consulted from 31 March to 23 June 2026 on a new general product safety framework that would modernise duties for online marketplaces, and the page says responses are being analysed. It is a closed consultation, not law. This briefing makes no claim about what any marketplace must do today about connected-product security.
What the NCSC guidance and Cyber Essentials v3.3 say about phones
The NCSC device security pages were published on 29 June 2021, reviewed on 13 May 2025, and are tagged for cyber security professionals, large organisations and the public sector. Cyber Essentials v3.3, dated April 2026, covers every size of organisation that certifies. Neither was written with this campaign in mind, and the table is a reading of what each does and does not reach.
What UK guidance says that bears on preinstalled Android firmware, and what it does not say. Sources: NCSC device security guidance pages and Cyber Essentials v3.3, read 8 October 2026.
- Source
- NCSC, choosing devices
- What it says
- Play Protect certified devices "have been tested to ensure they do not contain any pre-installed malware", and the NCSC recommends choosing them. Check the maker's security reputation, what it pre-installs and how long it supports the device
- What it does not say
- Whether the phones in this report were certified. Nothing on white-label devices
- Source
- NCSC, purchasing devices
- What it says
- Buying directly from a reputable vendor is likely to give a better outcome than second hand devices from online marketplaces. A device compromised before configuration can be very difficult to detect. Devices bought outside a trusted supplier should be securely erased and enrolled manually
- What it does not say
- That the sentence about marketplaces concerns second hand devices, while the listing in Bitdefender's screenshot is marked new. Nothing on firmware-level components surviving an erase
- Source
- NCSC, managing device firmware
- What it says
- Firmware is the foundation of trust, and "firmware attacks would have to be highly targeted"
- What it does not say
- A revenue-driven campaign found in more than 150 countries, which is how Bitdefender describes this one. That framing does not fit it (our reading)
- Source
- NCSC, mobile device management
- What it says
- MDM can report device compliance, and some also offer device attestation, which "can provide stronger assertions of device compliance and device health", usable to gate access to organisational data
- What it does not say
- Whether either would flag these phones. Bitdefender says "behavior was the only thing left to catch it by"
- Source
- Cyber Essentials v3.3, scope
- What it says
- User-owned devices that access organisational data or services are in scope, except those used only for native voice, native text or MFA apps. Devices include smartphones
- What it does not say
- Anything about a device's own supply chain or preinstalled firmware
- Source
- Cyber Essentials v3.3, secure configuration
- What it says
- For mobile phones: "remove or disable unnecessary software (including applications, system utilities and network services)"
- What it does not say
- A component the owner cannot remove
- Source
- Cyber Essentials v3.3, security update management
- What it says
- Software must be licensed and supported: "The vendor must provide the future date when they will stop providing these." Fixes for critical or high risk flaws within 14 days
- What it does not say
- Preinstalled components. A phone whose maker publishes no end date cannot be shown to run supported software (our reading)
- Source
- Cyber Essentials v3.3, malware protection
- What it says
- For phones the listed mechanism is application allow listing: "Only approved applications, restricted by code signing, are allowed to execute on devices."
- What it does not say
- How a validly signed system component is treated. The clause concerns approved applications (our reading)
| Source | What it says | What it does not say |
|---|---|---|
| NCSC, choosing devices | Play Protect certified devices "have been tested to ensure they do not contain any pre-installed malware", and the NCSC recommends choosing them. Check the maker's security reputation, what it pre-installs and how long it supports the device | Whether the phones in this report were certified. Nothing on white-label devices |
| NCSC, purchasing devices | Buying directly from a reputable vendor is likely to give a better outcome than second hand devices from online marketplaces. A device compromised before configuration can be very difficult to detect. Devices bought outside a trusted supplier should be securely erased and enrolled manually | That the sentence about marketplaces concerns second hand devices, while the listing in Bitdefender's screenshot is marked new. Nothing on firmware-level components surviving an erase |
| NCSC, managing device firmware | Firmware is the foundation of trust, and "firmware attacks would have to be highly targeted" | A revenue-driven campaign found in more than 150 countries, which is how Bitdefender describes this one. That framing does not fit it (our reading) |
| NCSC, mobile device management | MDM can report device compliance, and some also offer device attestation, which "can provide stronger assertions of device compliance and device health", usable to gate access to organisational data | Whether either would flag these phones. Bitdefender says "behavior was the only thing left to catch it by" |
| Cyber Essentials v3.3, scope | User-owned devices that access organisational data or services are in scope, except those used only for native voice, native text or MFA apps. Devices include smartphones | Anything about a device's own supply chain or preinstalled firmware |
| Cyber Essentials v3.3, secure configuration | For mobile phones: "remove or disable unnecessary software (including applications, system utilities and network services)" | A component the owner cannot remove |
| Cyber Essentials v3.3, security update management | Software must be licensed and supported: "The vendor must provide the future date when they will stop providing these." Fixes for critical or high risk flaws within 14 days | Preinstalled components. A phone whose maker publishes no end date cannot be shown to run supported software (our reading) |
| Cyber Essentials v3.3, malware protection | For phones the listed mechanism is application allow listing: "Only approved applications, restricted by code signing, are allowed to execute on devices." | How a validly signed system component is treated. The clause concerns approved applications (our reading) |
Cyber Essentials therefore says nothing about whether a phone left the factory clean. The words "Play Protect" and "certified" do not appear in the v3.3 requirements. It asks whether software is supported and whether applications are approved. It does not ask where a device's firmware came from.
What a small UK organisation should do, in the order worth doing it
Take this with you
Defender checklist for a small UK organisation
- List every phone and tablet that reaches work email, files or messaging, including personal ones. Cyber Essentials v3.3 puts a user-owned device in scope when it reaches organisational data or services, unless it is used only for calls, texts and MFA apps.
- For each Android device, record the make, the model, the security patch level and the Play Protect certification state. Google's help page says to open the Play Store, then the profile, Settings and About. A Play Store icon is not proof, because the report says the malware switches the Play Store off and on, so the app was present.
- Do not buy uncertified, white-label or counterfeit-branded phones for work. Buy from a supplier you can name, and ask for the end date of security updates and the statement of compliance before you order. A phone with no published end date cannot be shown to meet the Cyber Essentials supported-software test on our reading.
- Enrol work phones in mobile device management and use its compliance reporting, with device attestation where it is offered, to decide which devices may reach organisational data. Treat the result as one signal, not a clearance.
- For personal phones you cannot vouch for, use the lowest-risk access you have. The NCSC's BYOD guidance lists browser-based access with strong authentication and virtual desktops among its controls. Where you can, keep such a phone off the office network, because the report describes the relay function as able to reach the local network.
- Compare the apps on managed phones with the 13 Google Play package names in Bitdefender's report, which this briefing does not reprint, and remove any match. A match is a prompt to look closer, not a verdict: the report says the same package names appear both as Play builds and as apps installed by the system component, and that the system component changes its own names between builds.
- Treat a phone that behaves oddly as untrusted: full-screen or overlay ads when the screen wakes, apps nobody installed, accessibility or notification access nobody granted, a Play Store that is disabled or that reappears. Take it off work accounts until it has been checked or replaced.
- Replace rather than clean. The report says uninstalling is not an option and that clearing needs firmware-level work, and Kaspersky's advice on a comparable family is to stop using the device until the firmware is replaced. As a precaution, and from a clean device, revoke sessions and reset the credentials of accounts used on the phone: the report shows no theft, but the access to read screens, notifications and texts was present.
- Report it. Tell the seller and ask for a refund or replacement; this briefing makes no claim about the legal entitlement. Report the phone to Report Fraud, which replaced Action Fraud on 4 December 2025. If the listing lacked an end date for security updates or a statement of compliance, tell OPSS, whose guidance invites contact about suspected non-compliance. Whether OPSS will treat a firmware compromise as within its remit is not stated.
What is not established, and what we could not read
- A count of affected phones, in total or in the UK, and the denominator of the chart.
- Who inserted the malware and where in the chain, and whether any company knew.
- Whether a factory reset or a maker's clean firmware removes it. No test is reported.
- Whether phones on sale today carry it, and what the "roughly two years" window covers.
- Whether the affected phones were Play Protect certified.
- Whether Google will remove the 13 Play apps, and whether Google or MediaTek will comment. We found no statement from Google, MediaTek or either of the two handset brands the report associates with its top model strings, as of the times above.
- Any theft of data, credentials or money. None is described.
- The forum thread Bitdefender cites about a model from one of the two named brands: its site put up a bot check and we did not bypass it. Android Authority's coverage and the Action Fraud and Report Fraud sites answered us with a block page, also not bypassed. We relied on GOV.UK's announcement for the Report Fraud change.
- The Dr.Web records Bitdefender links to its operator lineage. We did not check them, so that lineage is Bitdefender's inference.
- The $180 figure, which rests on The Record alone.
The question
The labels on these phones are friendly: a component called System, a Play Store icon, a flagship's name in the model field, a valid platform signature. Each was true in its way and none was a control. What would have helped sits on the buyer's side: a supplier you can name, a certification you can check, and a published end date for security updates, which the law now requires the maker to publish and which you can ask for before you order.
So if a phone in your organisation was compromised before its owner first switched it on, which of your controls would notice, and who could say where its firmware came from?
Key facts
Sources
- PrimaryThe Midnight Mimosa report of 8 October 2026, read in full including tables and images: the figures, the country chart (UK 3.49%), the stated and unstated points, and the legal note. The primary source.Bitdefender Labsaccessed 2026-10-08
- PrimaryKaspersky analysis of the Keenadu firmware backdoor dated 17 February 2026, which Bitdefender cites as an earlier case: 13,715 users in its telemetry, its top five countries, and its advice for firmware-resident malware.Kaspersky (Securelist)accessed 2026-10-08
- PrimaryThe October 2026 product security bulletin, published 5 October: chipset vulnerabilities only, no mention of the campaign. Read with the security announcements page to look for a MediaTek statement; none found.MediaTekaccessed 2026-10-08
- PrimaryThe Android Security Bulletin for October 2026, published 5 October: vulnerabilities only, no mention of the campaign. Read to look for a Google statement; none found.Google (Android Open Source Project)accessed 2026-10-08
- PrimaryCheck and fix Play Protect certification status: how to check the state in the Play Store, and what Google says about uncertified devices and Google apps.Google Play Helpaccessed 2026-10-08
- PrimaryPart 1 of the Product Security and Telecommunications Infrastructure Act 2022: relevant persons, duties of manufacturers, importers and distributors, enforcement, penalties, and the meaning of a UK consumer connectable product.legislation.gov.ukaccessed 2026-10-08
- PrimaryThe 2023 Security Requirements for Relevant Connectable Products Regulations, current revised text: the three Schedule 1 requirements, excepted products, and the statement of compliance rules.legislation.gov.ukaccessed 2026-10-08
- PrimaryOPSS guidance on the regulations: who is covered, the three security requirements, and where to raise suspected non-compliance.Office for Product Safety and Standards, DBT and DSITaccessed 2026-10-08
- PrimaryDSIT policy page on the product security regime: commencement on 29 April 2024 and a summary of the security requirements.Department for Science, Innovation and Technologyaccessed 2026-10-08
- PrimaryOPSS enforcement guidance for the regime: compliance, stop and recall notices, penalties, and publication of compliance failures.Office for Product Safety and Standardsaccessed 2026-10-08
- PrimaryClosed consultation of 31 March to 23 June 2026 on a new product safety framework, read for its proposals on online marketplaces. A proposal, not law.OPSS and Department for Business and Tradeaccessed 2026-10-08
- PrimaryChoosing devices: Play Protect certification, reputable vendor and support duration for Android devices.NCSCaccessed 2026-10-08
- PrimaryPurchasing devices: supply chain advice, the sentence on second hand devices from online marketplaces, and erasing devices bought outside a trusted supplier.NCSCaccessed 2026-10-08
- PrimaryErasing devices: factory reset as the usual route and stock images from some OEMs as an advanced option.NCSCaccessed 2026-10-08
- PrimaryManaging device firmware: the statement that firmware attacks would have to be highly targeted.NCSCaccessed 2026-10-08
- PrimaryMobile device management: compliance monitoring and device attestation.NCSCaccessed 2026-10-08
- PrimaryAndroid platform guide: the statement that manufacturers must publish support years to comply with the product security law.NCSCaccessed 2026-10-08
- PrimaryBring your own device guidance and its technical controls (action 5): browser access with strong authentication and virtual desktops.NCSCaccessed 2026-10-08
- PrimaryCyber Essentials requirements for IT infrastructure v3.3, April 2026: BYOD scope, secure configuration, security update management and malware protection clauses.NCSCaccessed 2026-10-08
- PrimaryAnnouncement of 4 December 2025 that Report Fraud replaces Action Fraud as the national platform for reporting cyber crime and fraud.GOV.UK (Serious Fraud Office)accessed 2026-10-08
- Reported byNews coverage of the report, read as a pointer. The only source for the $180 device price and the statement that the researchers said the phones are sold through mainstream marketplaces.The Record from Recorded Future Newsaccessed 2026-10-08


