
AI-generated summary
Bitdefender is an internationally renowned information security company that frequently publishes research reports on malware and network threats. In recent years, cheap Android phones have frequently become a breeding ground for malware due to system security vulnerabilities, especially white-brand and copycat models that rarely receive regular security updates.
Some niche Chinese brand Android phones have been found to contain malware, so be careful when buying them. (Photo/Reuters)
Be careful when buying a cheap mobile phone. You might save your wallet, but end up buying a problematic mobile phone with a built-in "virus"! The security company Bitdefender recently revealed that a piece of malware called "Midnight Mimosa" is actually hidden directly in the systems of some cheap Android phones, especially Chinese niche brands, white brands and copycat phones, which are more worthy of attention.
According to a Bitdefender research report, Midnight Mimosa is different from malware that is usually infected by downloading unknown apps. It is directly embedded into the phone's firmware, which means that even if the app is not downloaded indiscriminately, the purchased phone may have already been "infected."
Please read on...
Two Chinese mobile phone brands have been named. Beware of white brands and copycats
The affected devices discovered so far are mainly concentrated in less well-known niche Android mobile phone brands, including Doogee and Cubot from China. In addition, be careful of white-brand mobile phones and counterfeit mobile phones, especially counterfeits that deliberately imitate Apple and Samsung flagship phones.
Fortunately, there is currently no evidence that this wave of attacks has affected mainstream affordable Android phones on the market, including well-known Chinese brands. Although the risky phones named by Bitdefender are not common in Taiwan, if you travel to China and other places for business, you should be especially careful not to buy low-priced phones from unknown sources.
The scariest thing about Midnight Mimosa is that it has extremely high system permissions. It can secretly install or delete apps, open permissions on its own, and even download and execute other malicious programs remotely without the user's knowledge. What’s even more cunning is that it will temporarily disable the Google Play Store before installing malicious programs in an attempt to avoid Google Play Protect’s security detection, making it more difficult for users to detect abnormalities.
Malicious software has extremely high permissions and your phone may be controlled by hackers
Judging from the information currently available, the main purpose of Midnight Mimosa seems to be to make illegal profits through infected mobile phones. One of the methods is to secretly display ads or create false ad clicks without the user's knowledge, in order to earn advertising revenue.
What is even more worrying is that attackers can turn infected mobile phones into part of a large botnet, allowing the mobile phone to act as a proxy node, and even be used to launch distributed denial of service attacks (DDoS). You think you just bought a cheap Android phone, but you may make your phone a tool controlled by hackers without knowing it.
Thousands of mobile phones around the world are affected by viruses that are difficult to remove
During a two-year observation period, researchers have discovered thousands of devices involved in this wave of malware activity in more than 150 countries around the world. Among them, Mexico, France and Italy are concentrated, followed by the United States, Germany, Brazil and Spain.
Since Midnight Mimosa is not easy to completely remove from your phone, if you find yourself buying a problematic phone, the best way is to "discard it immediately."
"You May Also Want to See"
New virus hides in 50 Android apps! Downloaded more than 2.3 million times, these people are the most dangerous
AI outlook — possibilities, not facts
Affected users will gradually abandon infected mobile phones and turn to devices of well-known brands or with security update guarantees.
Likely · Within months
Chinese regulators may tighten safety testing and certification requirements for white-brand and copycat phones.
Possible · Within months

Google Cloud released the Gemini enterprise agent at the Gemini at Work event, which allows employees to delegate tasks through natural language on Gmail, Docs and other platforms. AI will plan its own steps, call the enterprise system and send the results back to the original working environment. It supports cross-device continuous execution and multi-model selection. It is currently in the early testing stage.

OpenAI announced the launch of Ultrafast ultra-high-speed mode for GPT-6.1 Sol. The token generation speed can be up to 8 times that of the standard mode, but the API usage cost has also increased to 6 times that of the standard version, even higher than the flagship Astra model. It is mainly aimed at professional developers and enterprise users. It has been gradually launched in API, Codex and ChatGPT Work.

A study by the Carnegie Endowment for International Peace found that only one in every 30 Chinese researchers engaged in AI research in the United States will return to China in 2025, but the overall number of Chinese researchers in the United States has increased by four percentage points. The study concluded by analyzing the author flow of NeurIPS papers that China has made progress in retaining local talent, while the United States relies on foreign researchers to maintain its lead. Chinese universities have risen significantly in the rankings of top institutions, with Peking University and Tsinghua University surpassing prestigious American schools such as MIT. At the same time, the Chinese government has intensified its restrictions on AI talents leaving the country, as shown by incidents such as the founder of Manus being blocked from leaving the country.

The U.S. government has suspended the acceptance of new and pending permanent labor certification applications submitted by eight technology companies including Microsoft and Adobe for foreign employees. Vice President Vance claimed that the visa system was abusing the visa system to prioritize hiring foreign employees. Labor Secretary Sandlin confirmed that the suspension covers all applications. Microsoft responded that its H-1B applications are mostly used to extend or change the status of existing employees rather than recruit new employees.

GlobalFoundries signed a five-year agreement worth US$2 billion with TSMC to produce silicon interposers for TSMC's CoWoS advanced packaging at its Malta, New York, factory. Production is expected to increase in the first half of 2028 to cope with the lack of advanced packaging production capacity caused by AI chip demand.

U.S. President Trump is expected to announce at the Science Summit in Washington that he has received a total of $2.4 billion in funding commitments from Silicon Valley giants such as Nvidia, AMD, OpenAI, Anthropic and Google to support the U.S. government's "Genesis" AI scientific research program. At the same time, the White House will launch a STEM education project and invest more than $100 million. However, relations between the technology industry and the White House are tense over immigration issues. Vice President Vance and the Secretary of Labor announced that they would suspend companies such as Microsoft from participating in the visa program, accusing them of abusing foreign workers to apply for permanent residency. Despite the friction, the tech community sees Trump as an ally who supports its priorities and has highlighted his stance on lax AI regulation and concerns about competition from China.