New Android Malware Recruits Phones as Residential Proxies in Stealth Campaign
ID: 75ec3af2-5597-51b8-8087-9cef6c0be9cb
STIX ID: report--75ec3af2-5597-51b8-8087-9cef6c0be9cb
Feed Name: Cyber Press
Threat Score
**Mirax** is an Android Remote Access Trojan and banking malware distributed via malicious Meta ads and fake IPTV apps that has been observed in March 2026 targeting Spanish-speaking users; it abuses Accessibility, uses packed droppers on GitHub, maintains persistence and C2 over WebSockets (ports 8443–8445), and provides capabilities for overlays, VNC/control, UI automation, data exfiltration, and SOCKS5 proxying for potential botnet/proxy abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
