Mirax Android Trojan Turns Devices Into Residential Proxy Nodes
ID: 7bdaf9b9-cc97-52a2-ad59-0b666c1f9c69
STIX ID: report--7bdaf9b9-cc97-52a2-ad59-0b666c1f9c69
Feed Name: Infosecurity Magazine (News)
A newly observed Android banking trojan named Mirax is being distributed via social-media ads and fake streaming/IPTV apps, primarily targeting Spanish-speaking users. Mirax provides real-time remote control, dynamic overlay attacks to harvest credentials, continuous keylogging, and collects lock-screen data; it also converts infected devices into residential proxy nodes for fraud and anonymized network abuse. The operators use a restricted Malware-as-a-Service model with payloads fetched from C2 servers and WebSocket-based control, and Cleafy reports campaigns that have reached over 200,000 accounts with likely expansion beyond Spain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
