Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
ID: 0cfa251a-1f11-5e38-8be1-16656d56001f
STIX ID: report--0cfa251a-1f11-5e38-8be1-16656d56001f
Feed Name: The Hacker News
Mirax is an active Android remote access trojan (RAT) observed targeting Spanish-speaking users via Meta advertisements and malicious dropper apps (e.g., StreamTV, Reproductor de video). The malware provides full RAT capabilities (keystroke capture, camera, SMS, overlays for credential theft) and uniquely embeds a SOCKS5 residential proxy (Yamux multiplexing) to route attacker traffic through victims' real IPs. Campaigns have reached large audiences (the report cites a single ad reach of ~190,987 and campaigns touching >220,000 accounts), use GitHub-hosted APK droppers, crypters (Virbox, Golden Crypt), multi-stage unpacking, accessibility abuse, and multiple WebSocket-based C2 channels on ports 8443–8445 for management, exfiltration, and proxying; access is marketed as MaaS with subscription pricing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
