New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes
ID: b0c10f6d-8edf-50a4-b343-28c92a37de40
STIX ID: report--b0c10f6d-8edf-50a4-b343-28c92a37de40
Feed Name: cybersecurityNews.com
Mirax is a dual-purpose Android malware (MaaS) that both harvests banking credentials and turns infected devices into residential SOCKS5 proxy nodes using Yamux over WebSocket, enabling attackers to route malicious traffic through victims' real IPs. The campaign, observed by Cleafy beginning March 2026 and first advertised on underground forums in December 2025, spread via paid Meta ads and phishing sites impersonating IPTV/streaming services, reached hundreds of thousands of accounts, abuses Accessibility Services for persistence, and is marketed to a limited set of trusted affiliates to reduce detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
