Threats · 153 days ago
Mirax is not just stealing banking credentials; it converts compromised Android phones into controlled residential proxy nodes. This dual-use infection supports both direct fraud inside mobile banking apps and anonymized downstream abuse, making attribution and IP-based detection far more difficult than typical trojan campaigns.
The malware operates as a restricted Malware-as-a-Service, limiting access to a small affiliate pool to maintain stealth and effectiveness. Campaigns have reached over 200,000 accounts via social media ads promoting fake streaming apps, primarily targeting Spanish-speaking users in Europe. Mirax uses dynamically fetched overlays, real-time device control, continuous keylogging, and lock-screen data capture to enable comprehensive surveillance and fraud.
This expanded operating model means banks and fraud teams will see attacks originating from legitimate residential IPs and real user devices, complicating trust signals and fraud detection. Mirax’s modular MaaS distribution combined with residential proxy capabilities signals a shift toward infected mobile devices serving as anonymized infrastructure, broadening post-compromise monetization beyond immediate account takeover.
3 sources covering this story
Mirax RAT Targeting Android Users in Europe
Offered as a MaaS to a small number of affiliates, mainly Russian speakers, the RAT can turn devices into residential proxy nodes.
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
Mirax Android RAT spreads via Meta ads reaching 220,000 accounts, enabling proxy abuse and fraud operations.
Mirax Android Trojan Turns Devices Into Residential Proxy Nodes
Security researchers warn of Mirax, an emerging Android banking trojan using MaaS, remote access and residential proxies to target European users
Part of the PlainSec briefing for 2026-04-15