Infosecurity-Magazine Mirax Android RAT Transforms Infected Devices into Proxy Nodes
Article Content
- •Mirax combines RAT functionalities with residential proxy capabilities, enhancing its threat level.
- •The malware is distributed through phishing websites and fake applications, reaching over 200,000 accounts.
- •It operates under a restricted MaaS model, prioritizing access for trusted affiliates.
Mirax, a newly identified Android Remote Access Trojan (RAT) and banking malware, has emerged as a significant threat, particularly in Spanish-speaking regions. It was first observed on underground forums in December 2025 and has been actively monitored since March 2026. Mirax operates under a restricted Malware-as-a-Service (MaaS) model, primarily targeting Russian-speaking affiliates. The malware's capabilities include turning infected devices into residential proxy nodes, allowing attackers to route malicious traffic through legitimate IP addresses. This functionality enhances the malware's monetization potential and expands its operational scope beyond financial theft. Distribution methods include fake IPTV applications and phishing websites, with over 200,000 accounts reportedly reached through Meta Ads. The malware can execute commands, monitor user activity, and deploy fake overlays to steal sensitive information. As Mirax continues to spread, its impact is expected to grow, prompting cybersecurity experts to issue warnings about its evolving tactics.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Albiriox in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Underground Market for Malware Crypting Services Grows An analysis by Insikt Group reveals a competitive market for malware crypting services, with 24 threat actors identified selling products designed to bypass detection by antivirus and endpoint detection tools. These services offer capabilities such as payload obfuscation, in-memory execution, and rapid re-crypting…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…