P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Bitdefender: malware ships in cheap Android firmware. The UK is 3.49% of its chart; no device count above 199

Bitdefender says malware ships in the firmware of cheap MediaTek Android phones and cannot be uninstalled. Its text never mentions the UK, but its chart gives the UK 3.49% of observed infected devices; the only device counts it prints stop at 199.

By Parminder Kumar Sharma · · 28 min read

A graphite budget smartphone stands against an open plain cardboard box on a dark walnut desk, its screen film peeling at one corner and its screen showing a list of blank rows with one outlined in amber, a white charging cable beside it. Text on the left reads: UK is 3.49% of Bitdefender's infected-phone chart. 3.49%. UK share of observed infected devices. No device count given.

The report's largest device count is 199, and the UK appears only in a chart

Bitdefender Labs published its Midnight Mimosa report on 8 October 2026. It says malware ships preinstalled in the firmware of low-cost Android phones built on MediaTek platforms, and that the campaign was observed on "thousands" of devices in more than 150 countries over roughly two years. We read the whole post, its tables and its images, and The Record's coverage as a pointer.

The largest device count the report prints is 199. It is in a table that the report says counts "a single studied enabler's installed portfolio": nine rows, of 199, 199, 182, 139, 120, 97, 2, 1 and 1 devices. The rows sum to 940 (derived). A device can appear in more than one row, so that one component was on at least 199 and at most 940 devices (derived). The text puts no number behind "thousands".

The UK is not named anywhere in the text. It is in one chart, titled "Country distribution by infected devices (two year window)": United Kingdom, 3.49%. That is the eighth of the twelve named countries by share (derived), after the seven the text names: Mexico 13.02%, France 12.48%, Italy 9.97%, the United States 8.36%, Germany 7.30%, Brazil 7.02% and Spain 6.72%. The 13 bars sum to 100.00% (derived), with "rest of the world" at 24.20%.

What that does not establish.

  • How many phones are infected. "Thousands" is Bitdefender's word for what it observed, not a population, and no exact figure is printed.
  • How many are in the UK. 3.49% is a share of a total the report does not give. Applying it to 199 or to "thousands" would be arithmetic on a denominator that is not the chart's.
  • That 3.49% is an infection rate. The data come from what the report calls Bitdefender's "insights" and telemetry, and it does not say how its users divide by country. A chart of detections is shaped by where the detecting product is installed as well as by where infected phones are (inference).
  • That any UK organisation holds one of these phones, or that any UK seller sold one. The report names no UK seller or buyer.
  • Anything about phones on sale today. The report gives no start or end date for its "roughly two years".

What each figure in the report counts, and what it leaves out

Figures printed in the Bitdefender report and what each counts. Source: Bitdefender Labs, 8 October 2026; derived items are this site's arithmetic.

  1. Figure in the report
    "Thousands" of unique devices, more than 150 countries, roughly two years
    What it counts
    Bitdefender's observation across the whole family of enabler builds
    What it does not give
    An exact count. The start and end of the window: a lineage table in the report dates the campaign 2024 to 2025
  2. Figure in the report
    199, 199, 182, 139, 120, 97, 2, 1, 1
    What it counts
    Devices on which one studied enabler installed each of nine packages
    What it does not give
    Unique devices. Derived: between 199 and 940
  3. Figure in the report
    At least 32 disguised apps
    What it counts
    Distinct cover apps the enablers install
    What it does not give
    How many one phone receives. The enabler in the table installed nine
  4. Figure in the report
    13 apps on Google Play
    What it counts
    Play listings that share the ad-fraud code and servers
    What it does not give
    A download count, or whether they were removed
  5. Figure in the report
    120 samples
    What it counts
    A list headed "Full sample set (120 MD5 hashes)": system components, droppers, cover apps and Play builds
    What it does not give
    Phones. A sample is a file, not a device
  6. Figure in the report
    3.49% (United Kingdom)
    What it counts
    One bar in one chart of observed infected devices
    What it does not give
    A UK count, or the denominator of the chart
  7. Figure in the report
    11.33% (most common model string)
    What it counts
    One bar in a second chart of unique devices by reported model string
    What it does not give
    That every phone of that name is affected: the report says the model column can be spoofed

What Bitdefender analysed, and whose telemetry this is

The investigation began, the report says, when App Anomaly Detection, a technology in Bitdefender Mobile Security, flagged a component that looked like part of Android but behaved like nothing of the sort. The field data it then cites are "insights" and "telemetry" from devices running Bitdefender's product, plus the 120 samples. It does not say how many devices or firmware images were examined, whether Bitdefender bought or tested any phone, or how any device was obtained.

Its reasons for calling the component firmware are listed: it is signed with the platform key, the model strings include region-coded build names and raw board names where a model name should be, and the owner cannot remove it. None is described as inspecting a firmware image. That is reasonable inference from telemetry, and this briefing treats the firmware conclusion as Bitdefender's finding, not as something we tested.

The Record says one device the researchers examined cost about $180. That figure is not in Bitdefender's post. The only listing the post reproduces is a screenshot of a phone sold under a flagship's name on a mainstream online marketplace, marked new and priced at £138.95 in pounds sterling, which suggests (inference) a UK-facing page. The caption does not name the marketplace and does not say the pictured phone carried the malware. This briefing does not name the marketplace either.

Method, not accusation. Bitdefender sells the product whose detection began the work, and its legal note says it "does not claim that any named entity has engaged in illegal conduct". That is a reason to know whose telemetry this is, not to doubt the behaviour described, which is specific and internally consistent. We did not analyse a sample or a device. Where this briefing says a component does something, the source is Bitdefender's description.

The country chart, read from the image

The report's text names seven countries and gives no percentages. The values are printed on the bars of one chart image, which we read directly and checked: the 13 bars sum to 100.00%. Rows below are in the chart's order, with a running total that is this site's arithmetic.

Bitdefender's chart "Country distribution by infected devices (two year window)", read from the image on 8 October 2026. The running total is derived.

  1. Country as charted
    Mexico
    Share of observed infected devices
    13.02%
    Running total (derived)
    13.02%
  2. Country as charted
    France
    Share of observed infected devices
    12.48%
    Running total (derived)
    25.50%
  3. Country as charted
    Italy
    Share of observed infected devices
    9.97%
    Running total (derived)
    35.47%
  4. Country as charted
    United States
    Share of observed infected devices
    8.36%
    Running total (derived)
    43.83%
  5. Country as charted
    Germany
    Share of observed infected devices
    7.30%
    Running total (derived)
    51.13%
  6. Country as charted
    Brazil
    Share of observed infected devices
    7.02%
    Running total (derived)
    58.15%
  7. Country as charted
    Spain
    Share of observed infected devices
    6.72%
    Running total (derived)
    64.87%
  8. Country as charted
    United Kingdom
    Share of observed infected devices
    3.49%
    Running total (derived)
    68.36%
  9. Country as charted
    Canada
    Share of observed infected devices
    2.74%
    Running total (derived)
    71.10%
  10. Country as charted
    Romania
    Share of observed infected devices
    1.76%
    Running total (derived)
    72.86%
  11. Country as charted
    Poland
    Share of observed infected devices
    1.54%
    Running total (derived)
    74.40%
  12. Country as charted
    Thailand
    Share of observed infected devices
    1.40%
    Running total (derived)
    75.80%
  13. Country as charted
    Rest of the world
    Share of observed infected devices
    24.20%
    Running total (derived)
    100.00%

The top three countries, Mexico, France and Italy, hold 35.47% (derived: 13.02 + 12.48 + 9.97). The seven the text names hold 64.87% (derived). The UK's 3.49% is about 48% of Germany's 7.30% and 52% of Spain's 6.72% (derived), and above Canada's 2.74%.

Bitdefender's reading is that no single country dominates and that the weight sits in two regional centres, Western Europe and the Americas, which it says is what hardware moving through international online marketplaces looks like, rather than a regional channel. That is Bitdefender's inference from the shape. The report shows no sales or shipment data.

A comparison shows how far to trust the shape of any one vendor's chart. Kaspersky's February 2026 analysis of a different firmware-resident family, Keenadu, which Bitdefender cites as an earlier case of this way of shipping malware, counted 13,715 users in its telemetry and named Russia, Japan, Germany, Brazil and the Netherlands as its top five. Two vendors, two rankings: each chart is a view of one vendor's customers (inference), not a map of where phones are infected.

A second chart ranks model strings, and its long tail is the point

A second chart, headed "Unique devices", has no caption in the text. It ranks the model strings that devices report. We read it from the image, and its 16 bars sum to 100.00% (derived). The first five bars are below, with the report's own gloss where the text gives one.

Bitdefender's chart "Unique devices" by reported model string, first five bars read from the image on 8 October 2026. Model strings are what the firmware reports, not verified product names.

  1. Model string as reported
    Most common string, a budget brand's model name
    Share of unique devices
    11.33%
    What the report says
    The report associates it with a budget handset brand, which this briefing does not name
  2. Model string as reported
    Second string, another budget brand's model name
    Share of unique devices
    4.08%
    What the report says
    The report associates it with a second budget brand, also not named here
  3. Model string as reported
    Third string, a budget brand's model name
    Share of unique devices
    3.35%
    What the report says
    Not discussed in the text
  4. Model string as reported
    S25 ULTRA
    Share of unique devices
    2.91%
    What the report says
    An imitation flagship name, in the report's account
  5. Model string as reported
    SM-S938B
    Share of unique devices
    2.54%
    What the report says
    A Samsung-looking model code that the report says appears on devices that are not Samsung
  6. Model string as reported
    Ten more strings, each 0.97% to 1.42%
    Share of unique devices
    11.57%
    What the report says
    Region-coded builds such as J10_EEA and Q6_EEA, which the report calls typical of no-name ODM devices, and others not discussed
  7. Model string as reported
    "Others"
    Share of unique devices
    64.22%
    What the report says
    A long tail

The 15 named strings together hold 35.78% (derived) and "others" hold 64.22%. Three strings that imitate a Samsung flagship's name or code, S25 ULTRA, SM-S938B and S24 ULTRA, hold 6.74% together (derived: 2.91 + 2.54 + 1.29). So a list of models to avoid would cover at most 35.78% of the devices in this chart, and the report says the model column is "a spoofing indicator, not a real device inventory". The report does not say that either brand shipped the component or knew of it, and its legal note says the naming of companies and brands is a technical observation, not an allegation. We found no statement from either brand. A buyer cannot use a model name as a safe list or a block list; certification and a supplier you can name are better tests.

What the report states, and what it does not

Stated and not stated in the Bitdefender report, with the briefing's own searches where a statement from another party would be expected. Read 8 October 2026.

  1. Question
    Where it sits
    Stated
    Preinstalled in firmware: a platform-signed system component, "on the phone before the owner switches it on for the first time"
    Not stated
    How many devices or firmware images were examined, or how they were obtained
  2. Question
    Who, and where in the chain
    Stated
    It "could be introduced by an ODM, a firmware integrator, a logistics partner" or another party. Some firmware was signed with certificates bearing the name of a Shenzhen company; Bitdefender says that does not show the company wrote it, shipped it or knew
    Not stated
    The actor. The point of insertion. Any company's knowledge. The payload operator is called a separate actor, and the report links its code to earlier families catalogued by another vendor, which we did not check
  3. Question
    MediaTek
    Stated
    Devices "built on MediaTek platforms"; one board name is shown as a MediaTek part
    Not stated
    That MediaTek's chips or software are the cause. We found no MediaTek statement. Its October bulletin, published 5 October, lists chipset vulnerabilities and does not mention the campaign
  4. Question
    Handset brands
    Stated
    The two most common model strings, put at 11.33% and 4.08% of unique devices in a second chart, are associated with two budget handset brands that this briefing does not name. Other devices report imitation Samsung and Apple names, and in some cases a genuine-looking Samsung model code
    Not stated
    That either brand shipped or knew of the component. The report calls the model column "a spoofing indicator, not a real device inventory". We found no statement from either brand
  5. Question
    What it does
    Stated
    Ad and click fraud through hidden cover apps; device and installed-app information collected; a device enrolled as a relay node; the Play Store switched off around some installs
    Not stated
    The cost to the owner in battery, data or money. Any data theft
  6. Question
    What it could do
    Stated
    System privileges to install and remove apps, grant permissions and run code supplied remotely. Accessibility, Notification Access and SMS permissions are available
    Not stated
    Use of them. Bitdefender says it did not see Accessibility or Notification Access used, and that what is done with them is the operator's decision
  7. Question
    Google Play
    Stated
    13 apps "currently present on Google Play" when it published: genuine Play builds with Play's own signature that share the code and servers but have no system privileges
    Not stated
    Whether Google removed them. We found no Google statement. Google's October Android bulletin, published 5 October, does not mention the campaign
  8. Question
    Reset and removal
    Stated
    The owner cannot uninstall it ("it can't be uninstalled"). Clearing needs "firmware-level cleanup or disabling the component over ADB", which the report calls unrealistic for most owners
    Not stated
    Whether a factory reset removes it: the words "factory reset" do not appear. Any test of reflashing, or of a maker's clean firmware
  9. Question
    When
    Stated
    Roughly two years, more than 150 countries, thousands of devices
    Not stated
    Start and end dates. Whether phones on sale now carry it

Where the report does not know

Seven stacked cards from chip platform to buyer, then a separate lane. Red cards mark what is unknown: where the malware went in, and any use of the Accessibility, notification and SMS access. Blue and orange cards give what Bitdefender states: MediaTek platforms, a system component in firmware, cheap phones sold online, already running on first switch-on, at least 32 hidden cover apps. A separate card covers 13 Google Play apps.
Drawn from the Bitdefender report of 8 October 2026; the Play listings check is this site's own.

Bitdefender is plain about the gap in the middle. Its words are that the malware "arrives in the ROM before the phone is sold" but that naming the party responsible "requires information beyond the scope of this technical analysis". It lists an original design manufacturer, a firmware integrator and a logistics partner as possible points, and says the same firmware is not the only route: devices without the certificate it names carry the same malware. The diagram draws that gap as a gap. The report establishes where the component ends up, not who put it there.

One inconsistency inside the report is worth stating. Its architecture figure labels the first stage "ODM firmware", tagged "MTK, multi-brand", while its text says the point of insertion is not known. We follow the text. The figure names a stage of the chain; it does not establish that a design manufacturer inserted anything.

What it costs the owner, and what the access could do

What was observed is fraud against advertisers, run on the owner's phone. The cover apps show real ads from a legitimate ad network in hidden windows and over other apps, sometimes when the phone is not in use. The report says the fake clicks are issued with no touch and that the ad surface is marked so it does not appear in screenshots or screen recordings. It gives no figure for battery, mobile data or money lost by the owner. Loading and showing ads uses data and power, which is our inference, not a measurement in the report.

Two further behaviours matter more to an organisation. The report says the operators collect device and installed-app information, and that a payload enrols the phone as a relay node, a residential-proxy exit, which it describes as able to reach "arbitrary hosts including the local network". In Bitdefender's own test a freshly enrolled node received no relay targets and no traffic was relayed. A phone on an office network is therefore a possible relay by design, with use not observed.

What the access could do is a different list, and the report keeps it separate. The component runs with system privileges and can install and remove apps, grant them permissions and run code supplied by a remote server. It holds Accessibility, Notification Access and SMS permissions, and the report says it switches the first two on itself, then grants and withdraws them repeatedly. Bitdefender explains what those permissions allow on any Android phone: an accessibility service can read the content of every screen and observe what is typed, notification access can read any notification including chat apps, and SMS access can read one-time codes. It also says it saw neither Accessibility nor Notification Access used, and that what is done with them is a decision the operator makes remotely, not a property of the samples it analysed. Its architecture figure lists "enables accessibility and notification capture" under the operator's remote control; the text says neither was seen used, and this briefing follows the text, because the figure shows the design, not an observation. Android 17's restriction of accessibility services to verified tools applies only with Advanced Protection on, as our earlier briefing set out; neither the Bitdefender report nor that briefing says whether it reaches a platform-signed system component.

Cannot be uninstalled: what the report says about reset, and what others say

The report's claim is precise and narrow. The malware "can't be uninstalled"; because the root component ships in the system partition, an affected owner cannot remove it by the normal route; and clearing the device "requires firmware-level cleanup or disabling the component over ADB", Android's debug bridge, "and neither is realistic for most people who own these phones". The words "factory reset" do not appear in the report. It does not say a reset fails, and it reports no test of one. It also says nothing about a clean firmware image from the maker, or whether any maker has published one.

Two other sources frame the question. Kaspersky's write-up of Keenadu gives the closest comparison. For a malicious system app it says the app cannot be removed because it sits in the system partition, and suggests replacing its function or disabling it over ADB. For a modified system library it says standard Android tools cannot remove it, that the first thing to check is whether the manufacturer has released clean firmware, that flashing firmware yourself can brick the device, and that until the firmware is replaced the device should not be used. The NCSC's guidance on erasing devices, last reviewed on 13 May 2025, says that in nearly all cases a factory reset is all you need to do, and offers reinstalling Android from stock images "available from some OEMs" as an advanced option. That page does not mention firmware, pre-installed software or the supply chain (keyword check). For a white-label handset with no published image there may be nothing to reinstall, which is our inference and not something the report says.

The practical reading, which is ours: replace rather than clean.

Friendly names are not controls, and this campaign uses several

Each label below can be true of an affected phone, on the report's account or, where marked, on our reading.

  • "System". The component's label is the generic "System" and its icon is hidden. Its package names sound like parts of Android and change between builds. The report's own line: "The package name is not the threat."
  • A valid platform signature. It shows who signed the component, not what the component does. Certificates bearing a company's name on firmware do not show that company's involvement, the report says.
  • "Installed from Google Play". On part of its sample set the recorded installer was set to Google Play although the Play signature block was absent. Bitdefender says the installer field cannot be used on its own to clear a sample.
  • Play Protect. The report says the Play Store is switched off around some installs, which it reads as probably an attempt to avoid Play Protect detection.
  • A Play listing. The 13 Play apps are, in the report's words, builds that "passed Play review".
  • The model name. Cheap devices report flagship names, and on some a genuine-looking Samsung model code. The model column, the report says, is a spoofing indicator.
  • A Play Store icon. Google's help page says only Play Protect certified devices are eligible to include Google apps such as the Play Store, and that those apps on uncertified devices are not licensed and are not real Google apps. The malware switches the Play Store off and on, so the affected phones had one. Whether they were certified, or ran an unlicensed copy, the report does not say. A Play Store icon is therefore not evidence of certification (inference).

A label records where something came from. A control stops something that should not happen. Briefing 265 found the same shape in a different supply chain: a package release with valid provenance, a trusted publisher and Verified commits, all of which recorded where a build came from and none of which examined what it contained.

What the UK product security regime requires, and what it does not

The regime is Part 1 of the Product Security and Telecommunications Infrastructure Act 2022 and the 2023 Regulations, both in force from 29 April 2024. We read the legislation.gov.uk text, the OPSS guidance and DSIT's policy page.

Smartphones are inside it. Schedule 1 of the Regulations refers to "a smartphone or a tablet computer capable of connecting to cellular networks", while Schedule 3 excepts desktops, laptops and tablets without a cellular connection. A product is a UK consumer connectable product if it is made available to consumers in the UK, or to business customers where identical products are available to consumers (section 54 of the Act), so a small organisation buying a consumer phone is not outside it. The OPSS guidance lists the three security requirements: banning universal default and easily guessable passwords, publishing information on how to report security issues, and publishing information on minimum security update periods.

What the Act and Regulations require of each party, and what the text does not say. Source: legislation.gov.uk text read 8 October 2026; sections and regulations as cited.

  1. Party
    Manufacturer
    What the text requires
    Meet Schedule 1: no universal or easily guessed default passwords; a published contact for security reports with when the reporter gets an acknowledgement and updates; a published minimum security update period with an end date. Supply a statement of compliance with the product and keep it for the longer of 10 years or the support period (regulation 8)
    What it does not say
    Nothing about malware, firmware integrity or the supply chain. The words are not in the Regulations or in Part 1 of the Act
  2. Party
    Importer
    What the text requires
    Not make the product available without a statement of compliance, keep a copy (regulation 9), and not make it available if it knows or believes the manufacturer has a compliance failure (sections 15 and 16)
    What it does not say
    Any duty to inspect firmware. A compliance failure means failing a security requirement
  3. Party
    Distributor
    What the text requires
    Not make the product available without a statement of compliance, or if it knows or believes there is a compliance failure by the manufacturer (sections 22 and 23)
    What it does not say
    Whether an online marketplace operator is a distributor
  4. Party
    Enforcer
    What the text requires
    OPSS, per its guidance, using compliance, stop and recall notices and monetary penalties. The Act sets penalties at up to the greater of £10 million or 4% of qualifying worldwide revenue (section 38). OPSS says it can publish details of compliance failures
    What it does not say
    That a firmware compromise counts as a compliance failure. OPSS invites contact about suspected non-compliance but does not say what it would do with this

In the Act's wording a compliance failure is a failure to comply with a security requirement, so the duties to investigate, notify and stop supplying attach to those three requirements. It follows, on our reading and not on any regulator's statement, that a handset could meet all three requirements and still carry a component like this one. A compliant listing proves a contact address and an end date for updates, not clean firmware.

Two parts of the regime are still useful to a buyer. The support period must be published in English, free, without a prior request and in a way a reader without technical knowledge can understand, and the NCSC's Android guide says manufacturers must publish it to comply, so a listing with no end date is a question to put to the seller. And the statement of compliance must accompany the product, so its absence is a second question.

Online marketplaces. The Act, the Regulations, the OPSS guidance and the DSIT page do not contain the words "online marketplace", and none says whether a marketplace operator is a distributor. Bitdefender writes that "the durable fix sits with the vendors and the marketplaces" that ship and sell the firmware; that is its view, not a legal finding. Separately, OPSS and the Department for Business and Trade consulted from 31 March to 23 June 2026 on a new general product safety framework that would modernise duties for online marketplaces, and the page says responses are being analysed. It is a closed consultation, not law. This briefing makes no claim about what any marketplace must do today about connected-product security.

What the NCSC guidance and Cyber Essentials v3.3 say about phones

The NCSC device security pages were published on 29 June 2021, reviewed on 13 May 2025, and are tagged for cyber security professionals, large organisations and the public sector. Cyber Essentials v3.3, dated April 2026, covers every size of organisation that certifies. Neither was written with this campaign in mind, and the table is a reading of what each does and does not reach.

What UK guidance says that bears on preinstalled Android firmware, and what it does not say. Sources: NCSC device security guidance pages and Cyber Essentials v3.3, read 8 October 2026.

  1. Source
    NCSC, choosing devices
    What it says
    Play Protect certified devices "have been tested to ensure they do not contain any pre-installed malware", and the NCSC recommends choosing them. Check the maker's security reputation, what it pre-installs and how long it supports the device
    What it does not say
    Whether the phones in this report were certified. Nothing on white-label devices
  2. Source
    NCSC, purchasing devices
    What it says
    Buying directly from a reputable vendor is likely to give a better outcome than second hand devices from online marketplaces. A device compromised before configuration can be very difficult to detect. Devices bought outside a trusted supplier should be securely erased and enrolled manually
    What it does not say
    That the sentence about marketplaces concerns second hand devices, while the listing in Bitdefender's screenshot is marked new. Nothing on firmware-level components surviving an erase
  3. Source
    NCSC, managing device firmware
    What it says
    Firmware is the foundation of trust, and "firmware attacks would have to be highly targeted"
    What it does not say
    A revenue-driven campaign found in more than 150 countries, which is how Bitdefender describes this one. That framing does not fit it (our reading)
  4. Source
    NCSC, mobile device management
    What it says
    MDM can report device compliance, and some also offer device attestation, which "can provide stronger assertions of device compliance and device health", usable to gate access to organisational data
    What it does not say
    Whether either would flag these phones. Bitdefender says "behavior was the only thing left to catch it by"
  5. Source
    Cyber Essentials v3.3, scope
    What it says
    User-owned devices that access organisational data or services are in scope, except those used only for native voice, native text or MFA apps. Devices include smartphones
    What it does not say
    Anything about a device's own supply chain or preinstalled firmware
  6. Source
    Cyber Essentials v3.3, secure configuration
    What it says
    For mobile phones: "remove or disable unnecessary software (including applications, system utilities and network services)"
    What it does not say
    A component the owner cannot remove
  7. Source
    Cyber Essentials v3.3, security update management
    What it says
    Software must be licensed and supported: "The vendor must provide the future date when they will stop providing these." Fixes for critical or high risk flaws within 14 days
    What it does not say
    Preinstalled components. A phone whose maker publishes no end date cannot be shown to run supported software (our reading)
  8. Source
    Cyber Essentials v3.3, malware protection
    What it says
    For phones the listed mechanism is application allow listing: "Only approved applications, restricted by code signing, are allowed to execute on devices."
    What it does not say
    How a validly signed system component is treated. The clause concerns approved applications (our reading)

Cyber Essentials therefore says nothing about whether a phone left the factory clean. The words "Play Protect" and "certified" do not appear in the v3.3 requirements. It asks whether software is supported and whether applications are approved. It does not ask where a device's firmware came from.

What a small UK organisation should do, in the order worth doing it

Take this with you

Defender checklist for a small UK organisation

  • List every phone and tablet that reaches work email, files or messaging, including personal ones. Cyber Essentials v3.3 puts a user-owned device in scope when it reaches organisational data or services, unless it is used only for calls, texts and MFA apps.
  • For each Android device, record the make, the model, the security patch level and the Play Protect certification state. Google's help page says to open the Play Store, then the profile, Settings and About. A Play Store icon is not proof, because the report says the malware switches the Play Store off and on, so the app was present.
  • Do not buy uncertified, white-label or counterfeit-branded phones for work. Buy from a supplier you can name, and ask for the end date of security updates and the statement of compliance before you order. A phone with no published end date cannot be shown to meet the Cyber Essentials supported-software test on our reading.
  • Enrol work phones in mobile device management and use its compliance reporting, with device attestation where it is offered, to decide which devices may reach organisational data. Treat the result as one signal, not a clearance.
  • For personal phones you cannot vouch for, use the lowest-risk access you have. The NCSC's BYOD guidance lists browser-based access with strong authentication and virtual desktops among its controls. Where you can, keep such a phone off the office network, because the report describes the relay function as able to reach the local network.
  • Compare the apps on managed phones with the 13 Google Play package names in Bitdefender's report, which this briefing does not reprint, and remove any match. A match is a prompt to look closer, not a verdict: the report says the same package names appear both as Play builds and as apps installed by the system component, and that the system component changes its own names between builds.
  • Treat a phone that behaves oddly as untrusted: full-screen or overlay ads when the screen wakes, apps nobody installed, accessibility or notification access nobody granted, a Play Store that is disabled or that reappears. Take it off work accounts until it has been checked or replaced.
  • Replace rather than clean. The report says uninstalling is not an option and that clearing needs firmware-level work, and Kaspersky's advice on a comparable family is to stop using the device until the firmware is replaced. As a precaution, and from a clean device, revoke sessions and reset the credentials of accounts used on the phone: the report shows no theft, but the access to read screens, notifications and texts was present.
  • Report it. Tell the seller and ask for a refund or replacement; this briefing makes no claim about the legal entitlement. Report the phone to Report Fraud, which replaced Action Fraud on 4 December 2025. If the listing lacked an end date for security updates or a statement of compliance, tell OPSS, whose guidance invites contact about suspected non-compliance. Whether OPSS will treat a firmware compromise as within its remit is not stated.

What is not established, and what we could not read

  • A count of affected phones, in total or in the UK, and the denominator of the chart.
  • Who inserted the malware and where in the chain, and whether any company knew.
  • Whether a factory reset or a maker's clean firmware removes it. No test is reported.
  • Whether phones on sale today carry it, and what the "roughly two years" window covers.
  • Whether the affected phones were Play Protect certified.
  • Whether Google will remove the 13 Play apps, and whether Google or MediaTek will comment. We found no statement from Google, MediaTek or either of the two handset brands the report associates with its top model strings, as of the times above.
  • Any theft of data, credentials or money. None is described.
  • The forum thread Bitdefender cites about a model from one of the two named brands: its site put up a bot check and we did not bypass it. Android Authority's coverage and the Action Fraud and Report Fraud sites answered us with a block page, also not bypassed. We relied on GOV.UK's announcement for the Report Fraud change.
  • The Dr.Web records Bitdefender links to its operator lineage. We did not check them, so that lineage is Bitdefender's inference.
  • The $180 figure, which rests on The Record alone.

The question

The labels on these phones are friendly: a component called System, a Play Store icon, a flagship's name in the model field, a valid platform signature. Each was true in its way and none was a control. What would have helped sits on the buyer's side: a supplier you can name, a certification you can check, and a published end date for security updates, which the law now requires the maker to publish and which you can ask for before you order.

So if a phone in your organisation was compromised before its owner first switched it on, which of your controls would notice, and who could say where its firmware came from?

Key facts

Sources

  1. PrimaryThe Midnight Mimosa report of 8 October 2026, read in full including tables and images: the figures, the country chart (UK 3.49%), the stated and unstated points, and the legal note. The primary source.Bitdefender Labsaccessed 2026-10-08
  2. PrimaryKaspersky analysis of the Keenadu firmware backdoor dated 17 February 2026, which Bitdefender cites as an earlier case: 13,715 users in its telemetry, its top five countries, and its advice for firmware-resident malware.Kaspersky (Securelist)accessed 2026-10-08
  3. PrimaryThe October 2026 product security bulletin, published 5 October: chipset vulnerabilities only, no mention of the campaign. Read with the security announcements page to look for a MediaTek statement; none found.MediaTekaccessed 2026-10-08
  4. PrimaryThe Android Security Bulletin for October 2026, published 5 October: vulnerabilities only, no mention of the campaign. Read to look for a Google statement; none found.Google (Android Open Source Project)accessed 2026-10-08
  5. PrimaryCheck and fix Play Protect certification status: how to check the state in the Play Store, and what Google says about uncertified devices and Google apps.Google Play Helpaccessed 2026-10-08
  6. PrimaryPart 1 of the Product Security and Telecommunications Infrastructure Act 2022: relevant persons, duties of manufacturers, importers and distributors, enforcement, penalties, and the meaning of a UK consumer connectable product.legislation.gov.ukaccessed 2026-10-08
  7. PrimaryThe 2023 Security Requirements for Relevant Connectable Products Regulations, current revised text: the three Schedule 1 requirements, excepted products, and the statement of compliance rules.legislation.gov.ukaccessed 2026-10-08
  8. PrimaryOPSS guidance on the regulations: who is covered, the three security requirements, and where to raise suspected non-compliance.Office for Product Safety and Standards, DBT and DSITaccessed 2026-10-08
  9. PrimaryDSIT policy page on the product security regime: commencement on 29 April 2024 and a summary of the security requirements.Department for Science, Innovation and Technologyaccessed 2026-10-08
  10. PrimaryOPSS enforcement guidance for the regime: compliance, stop and recall notices, penalties, and publication of compliance failures.Office for Product Safety and Standardsaccessed 2026-10-08
  11. PrimaryClosed consultation of 31 March to 23 June 2026 on a new product safety framework, read for its proposals on online marketplaces. A proposal, not law.OPSS and Department for Business and Tradeaccessed 2026-10-08
  12. PrimaryChoosing devices: Play Protect certification, reputable vendor and support duration for Android devices.NCSCaccessed 2026-10-08
  13. PrimaryPurchasing devices: supply chain advice, the sentence on second hand devices from online marketplaces, and erasing devices bought outside a trusted supplier.NCSCaccessed 2026-10-08
  14. PrimaryErasing devices: factory reset as the usual route and stock images from some OEMs as an advanced option.NCSCaccessed 2026-10-08
  15. PrimaryManaging device firmware: the statement that firmware attacks would have to be highly targeted.NCSCaccessed 2026-10-08
  16. PrimaryMobile device management: compliance monitoring and device attestation.NCSCaccessed 2026-10-08
  17. PrimaryAndroid platform guide: the statement that manufacturers must publish support years to comply with the product security law.NCSCaccessed 2026-10-08
  18. PrimaryBring your own device guidance and its technical controls (action 5): browser access with strong authentication and virtual desktops.NCSCaccessed 2026-10-08
  19. PrimaryCyber Essentials requirements for IT infrastructure v3.3, April 2026: BYOD scope, secure configuration, security update management and malware protection clauses.NCSCaccessed 2026-10-08
  20. PrimaryAnnouncement of 4 December 2025 that Report Fraud replaces Action Fraud as the national platform for reporting cyber crime and fraud.GOV.UK (Serious Fraud Office)accessed 2026-10-08
  21. Reported byNews coverage of the report, read as a pointer. The only source for the $180 device price and the statement that the researchers said the phones are sold through mainstream marketplaces.The Record from Recorded Future Newsaccessed 2026-10-08

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.