logo

New Android Malware Recruits Phones as Residential Proxies in Stealth Campaign

ID: 75ec3af2-5597-51b8-8087-9cef6c0be9cb

STIX ID: report--75ec3af2-5597-51b8-8087-9cef6c0be9cb

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-15

Date Updated: 2026-04-15

Author: Varshini

...
...

**Mirax** is an Android Remote Access Trojan and banking malware distributed via malicious Meta ads and fake IPTV apps that has been observed in March 2026 targeting Spanish-speaking users; it abuses Accessibility, uses packed droppers on GitHub, maintains persistence and C2 over WebSockets (ports 8443–8445), and provides capabilities for overlays, VNC/control, UI automation, data exfiltration, and SOCKS5 proxying for potential botnet/proxy abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.