Mirax malware campaign hits 220K accounts, enables full remote control
ID: 0f5cbeb8-ed67-5cb8-bf8f-bbdaf6e9f43c
STIX ID: report--0f5cbeb8-ed67-5cb8-bf8f-bbdaf6e9f43c
Feed Name: Security Affairs
Mirax is a newly identified Android Remote Access Trojan actively distributed via Meta ads and GitHub Releases that has reportedly infected over 220,000 users. The campaign uses multi-stage droppers, obfuscation (RC4/XOR, packers like Golden Encryption), dynamic loading, and social engineering to get victims to sideload an app that requests Accessibility permissions; once installed it provides full RAT capabilities, data theft, and converts devices into SOCKS5 residential proxies for downstream criminal use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
