logo

New Mirax Android RAT Turns Infected Phones Into Residential Proxy Nodes

ID: b0c10f6d-8edf-50a4-b343-28c92a37de40

STIX ID: report--b0c10f6d-8edf-50a4-b343-28c92a37de40

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Mirax is a dual-purpose Android malware (MaaS) that both harvests banking credentials and turns infected devices into residential SOCKS5 proxy nodes using Yamux over WebSocket, enabling attackers to route malicious traffic through victims' real IPs. The campaign, observed by Cleafy beginning March 2026 and first advertised on underground forums in December 2025, spread via paid Meta ads and phishing sites impersonating IPTV/streaming services, reached hundreds of thousands of accounts, abuses Accessibility Services for persistence, and is marketed to a limited set of trusted affiliates to reduce detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.