logo

Mirax Android RAT Hijacks Infected Phones as Residential Proxies

ID: 858eedcf-4010-5017-9e81-302046fdcd39

STIX ID: report--858eedcf-4010-5017-9e81-302046fdcd39

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Technical analysis of Mirax, an emerging Android banking trojan sold as a private MaaS that combines RAT, spyware (keystroke logging, accessibility abuse, overlays) and a built-in SOCKS5 residential proxy to monetize infections and bypass fraud controls; distributed via malvertising (Meta ads) and GitHub-hosted droppers, targeting Spanish-speaking users in Europe and including multiple IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.