Mirax Android RAT Transforms Infected Devices into Proxy Nodes

Mirax Android RAT Transforms Infected Devices into Proxy Nodes

First seen 13 Apr 2026, 16:07 UTC English.Varthabharati.InInfosecurity-MagazineThehackernewsGbhackersCybersecuritynews+4 85% similarity 71.0

Article Content

Browse articles
ThreatCluster

Mirax, a newly identified Android Remote Access Trojan (RAT) and banking malware, has emerged as a significant threat, particularly in Spanish-speaking regions. It was first observed on underground forums in December 2025 and has been actively monitored since March 2026. Mirax operates under a restricted Malware-as-a-Service (MaaS) model, primarily targeting Russian-speaking affiliates. The malware's capabilities include turning infected devices into residential proxy nodes, allowing attackers to route malicious traffic through legitimate IP addresses. This functionality enhances the malware's monetization potential and expands its operational scope beyond financial theft. Distribution methods include fake IPTV applications and phishing websites, with over 200,000 accounts reportedly reached through Meta Ads. The malware can execute commands, monitor user activity, and deploy fake overlays to steal sensitive information. As Mirax continues to spread, its impact is expected to grow, prompting cybersecurity experts to issue warnings about its evolving tactics.

Key Points: • Mirax combines RAT functionalities with residential proxy capabilities, enhancing its threat level. • The malware is distributed through phishing websites and fake applications, reaching over 200,000 accounts. • It operates under a restricted MaaS model, prioritizing access for trusted affiliates.

ThreatCluster AI

Timeline

2025-12-19
Mirax first appears on underground forums.
2026-03-01
Cleafy begins monitoring Mirax campaigns.
2026-04-11
TraceX Labs warns about rising trojanised Android APK scams.
2026-04-13
Cleafy publishes detailed analysis of Mirax.

Community

Browse all →