Mirax Malware Turns Infected Phones into Anonymized Fraud Infrastructure

Mirax is not just stealing banking credentials; it converts compromised Android phones into controlled residential proxy nodes. This dual-use infection supports both direct fraud inside mobile banking apps and anonymized downstream abuse, making attribution and IP-based detection far more difficult than typical trojan campaigns. The malware operates as a restricted Malware-as-a-Service, limiting access to a small affiliate pool to maintain stealth and effectiveness. Campaigns have reached over 200,000 accounts via social media ads promoting fake streaming apps, primarily targeting Spanish-speaking users in Europe. Mirax uses dynamically fetched overlays, real-time device control, continuous keylogging, and lock-screen data capture to enable comprehensive surveillance and fraud. This expanded operating model means banks and fraud teams will see attacks originating from legitimate residential IPs and real user devices, complicating trust signals and fraud detection. Mirax’s modular MaaS distribution combined with residential proxy capabilities signals a shift toward infected mobile devices serving as anonymized infrastructure, broadening post-compromise monetization beyond immediate account takeover.

Part of the PlainSec briefing for 2026-04-15

Sources