TF-MAL-apk.mirax
📛 Threat Title
Malware family: Mirax
Description
ThreatFox malware family `apk.mirax`. Printable name: Mirax. Aliases: Astrinox,Mirax Bot,MiraxRAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.mirax
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mirax
IOC database
- Type
- domain
- Value
apk.mirax- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.mirax
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.mirax
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Mirax Android malware steals banking creds and turns phones into proxy nodes, enabling stealthy attacks via MaaS platform.
-
web:gbhackers.com
A new Android banking trojan called Mirax is rapidly gaining traction in the cybercrime ecosystem, combining powerful remote access features with residential proxy capabilities to turn victims' smartphones into high-value infrastructure nodes. Mirax is marketed as a premium Android RAT and banking malware , offering attackers full, real‑time control over compromised devices. Once installed ...
-
web:infrafort.tech
Introduction A new Android remote access trojan called Mirax has reached over 220,000 accounts through paid advertising campaigns on Facebook, Instagram, Messenger, and Threads. Beyond standard RAT capabilities like keylogging and screen capture, Mirax's standout feature is turning infected devices into SOCKS5 residential proxy nodes — letting attackers route traffic through victims' home IP ...
-
web:malpedia.caad.fkie.fraunhofer.de
Mirax is an Android RAT / banking trojan sold as a private Malware -as-a-Service since December 2025 by an actor using the moniker " Mirax Bot", advertised only to a small pool of predominantly Russian-speaking affiliates. It combines a conventional banking-trojan stack — HTML/JavaScript overlay injection against banking and cryptocurrency apps, Accessibility-Services abuse, HVNC, keylogging ...
-
web:securityaffairs.com
Mirax , a new Android RAT, spread via Meta ads, infected 220,000 users and turns devices into SOCKS5 proxies, giving attackers full remote control. Mirax is a new Android remote access trojan spreading through ads on Meta platforms, targeting mainly Spanish-speaking users and reaching over 220,000 accounts. The malicious code lets attackers fully control infected devices in real time and goes ...
-
web:securityarsenal.com
Mirax RAT targets Spanish speakers via Meta Ads, hijacking devices as SOCKS5 proxies. Detection and mitigation strategies inside.
-
web:thehackernews.com
Six Android malware families discovered targeting banking apps and crypto wallets, exploiting accessibility features to steal funds and data.
-
web:vpncentral.com
A newly documented Android malware family called Mirax is targeting users through fake streaming and IPTV lures spread with paid ads on Meta platforms. Cleafy says the malware has appeared in campaigns since March 2026 and can steal credentials, take control of devices, and turn infected phones into residential proxy nodes that route attacker traffic […]
-
web:www.cleafy.com
Mirax , a new Android RAT and banking malware operating as a private MaaS is actively targeting Spanish-speaking countries via Meta ad campaigns.
-
web:www.pcrisk.com
How did Mirax RAT malware infiltrate my Android device? Mirax RAT is most commonly distributed through social media advertisements on platforms like Facebook and Instagram. These ads direct users to websites offering fake streaming or media player apps that must be installed from outside the official app store.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.