惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
H
Help Net Security
小众软件
小众软件
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
Last Week in AI
Last Week in AI
爱范儿
爱范儿
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园 - 【当耐特】
V
Visual Studio Blog
大猫的无限游戏
大猫的无限游戏
博客园_首页
Jina AI
Jina AI
D
Docker
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Security Blog
Microsoft Security Blog
阮一峰的网络日志
阮一峰的网络日志

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Mirax Android Trojan Turns Devices Into Residential Proxy...
Alessandro Mascellino · 2026-04-13 · via www.infosecurity-magazine.com

A newly identified Android banking trojan, known as Mirax, is spreading across Europe and combines remote access features with residential proxy capabilities to broaden its impact.

According to an advisory published by Cleafy, the malware has been observed targeting Spanish-speaking users, with campaigns reaching more than 200,000 accounts through advertisements on social media platforms.

Cleafy said Mirax represents a shift in how Android malware is developed and deployed. Unlike conventional threats, it operates under a restricted Malware-as-a-Service (MaaS) model, limiting access to a small group of affiliates. This controlled approach appears intended to maintain operational security while improving campaign effectiveness.

The malware enables attackers to fully control infected devices in real time. It can execute commands, monitor activity and deploy fake overlays on legitimate applications to steal sensitive data. These overlays are fetched dynamically from command-and-control (C2) servers, complicating detection efforts.

Mirax also integrates surveillance capabilities, including continuous keylogging and collection of lock screen details such as PIN structure and biometric usage. This allows attackers to gather credentials and personal information without raising suspicion.

Social Engineering Drives Distribution

The campaigns rely on social engineering to reach victims at scale. Malicious advertisements promote illegal streaming applications, encouraging users to download software from outside official app stores.

Key elements of the distribution chain include:

  • Social media advertisements used to reach large audiences

  • Fake IPTV or streaming apps acting as droppers

  • Malware hosted on GitHub with frequent updates

  • Device checks designed to evade automated analysis

Once installed, the malware executes a multi-stage process, decrypting hidden payloads and establishing communication channels via WebSockets. These channels enable attackers to remotely control devices and extract data.

Proxy Capability Expands Attack Potential

One of Mirax's defining features is its ability to convert infected devices into residential proxy nodes. This allows attackers to route malicious traffic through legitimate IP addresses, helping them bypass geographic restrictions and fraud detection systems.

Read more on proxy abuse in cybersecurity: DeadLock Ransomware Uses Polygon Smart Contracts For Proxy Rotation

This functionality extends the malware's role beyond financial theft. Compromised devices can be used as infrastructure for broader cyber-criminal activity, including account takeovers (ATO) and anonymized network attacks.

Cleafy said Mirax reflects a wider evolution in mobile threats, where tools are becoming more modular and commercially structured. Although current campaigns focus on Spain, the analysts warned that the malware's reach is likely to expand as operators refine their tactics.