s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.mirax

📛 Threat Title

Malware family: Mirax

Category: Mirax First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.mirax`. Printable name: Mirax. Aliases: Astrinox,Mirax Bot,MiraxRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.mirax VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mirax

IOC database

Type
domain
Value
apk.mirax
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.mirax

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mirax

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Mirax Android malware steals banking creds and turns phones into proxy nodes, enabling stealthy attacks via MaaS platform.

  • web:gbhackers.com

    A new Android banking trojan called Mirax is rapidly gaining traction in the cybercrime ecosystem, combining powerful remote access features with residential proxy capabilities to turn victims' smartphones into high-value infrastructure nodes. Mirax is marketed as a premium Android RAT and banking malware , offering attackers full, real‑time control over compromised devices. Once installed ...

  • web:infrafort.tech

    Introduction A new Android remote access trojan called Mirax has reached over 220,000 accounts through paid advertising campaigns on Facebook, Instagram, Messenger, and Threads. Beyond standard RAT capabilities like keylogging and screen capture, Mirax's standout feature is turning infected devices into SOCKS5 residential proxy nodes — letting attackers route traffic through victims' home IP ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Mirax is an Android RAT / banking trojan sold as a private Malware -as-a-Service since December 2025 by an actor using the moniker " Mirax Bot", advertised only to a small pool of predominantly Russian-speaking affiliates. It combines a conventional banking-trojan stack — HTML/JavaScript overlay injection against banking and cryptocurrency apps, Accessibility-Services abuse, HVNC, keylogging ...

  • web:securityaffairs.com

    Mirax , a new Android RAT, spread via Meta ads, infected 220,000 users and turns devices into SOCKS5 proxies, giving attackers full remote control. Mirax is a new Android remote access trojan spreading through ads on Meta platforms, targeting mainly Spanish-speaking users and reaching over 220,000 accounts. The malicious code lets attackers fully control infected devices in real time and goes ...

  • web:securityarsenal.com

    Mirax RAT targets Spanish speakers via Meta Ads, hijacking devices as SOCKS5 proxies. Detection and mitigation strategies inside.

  • web:thehackernews.com

    Six Android malware families discovered targeting banking apps and crypto wallets, exploiting accessibility features to steal funds and data.

  • web:vpncentral.com

    A newly documented Android malware family called Mirax is targeting users through fake streaming and IPTV lures spread with paid ads on Meta platforms. Cleafy says the malware has appeared in campaigns since March 2026 and can steal credentials, take control of devices, and turn infected phones into residential proxy nodes that route attacker traffic […]

  • web:www.cleafy.com

    Mirax , a new Android RAT and banking malware operating as a private MaaS is actively targeting Spanish-speaking countries via Meta ad campaigns.

  • web:www.pcrisk.com

    How did Mirax RAT malware infiltrate my Android device? Mirax RAT is most commonly distributed through social media advertisements on platforms like Facebook and Instagram. These ads direct users to websites offering fake streaming or media player apps that must be installed from outside the official app store.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.