logo

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

ID: 0cfa251a-1f11-5e38-8be1-16656d56001f

STIX ID: report--0cfa251a-1f11-5e38-8be1-16656d56001f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mirax is an active Android remote access trojan (RAT) observed targeting Spanish-speaking users via Meta advertisements and malicious dropper apps (e.g., StreamTV, Reproductor de video). The malware provides full RAT capabilities (keystroke capture, camera, SMS, overlays for credential theft) and uniquely embeds a SOCKS5 residential proxy (Yamux multiplexing) to route attacker traffic through victims' real IPs. Campaigns have reached large audiences (the report cites a single ad reach of ~190,987 and campaigns touching >220,000 accounts), use GitHub-hosted APK droppers, crypters (Virbox, Golden Crypt), multi-stage unpacking, accessibility abuse, and multiple WebSocket-based C2 channels on ports 8443–8445 for management, exfiltration, and proxying; access is marketed as MaaS with subscription pricing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.