惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Fox-IT International blog
Recent Announcements
Recent Announcements
D
Docker
IT之家
IT之家
B
Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
量子位
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
罗磊的独立博客
博客园 - 司徒正美
李成银的技术随笔
美团技术团队
Blog — PlanetScale
Blog — PlanetScale
雷峰网
雷峰网
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
T
Tailwind CSS Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
小众软件
小众软件
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
M
Microsoft Research Blog - Microsoft Research
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog

The Hacker News

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks The Alert Firehose Finally Meets Its Match Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories Microsoft Warns of Two Actively Exploited Defender Vulnerabilities When Identity is the Attack Path 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API Agent AI is Coming. Are You Ready? Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit Grafana GitHub Breach Exposes Source Code via TanStack npm Attack GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability The New Phishing Click: How OAuth Consent Bypasses MFA Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More How to Reduce Phishing Exposure Before It Turns into Business Disruption Developer Workstations Are Now Part of the Software Supply Chain Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure How AI Hallucinations Are Creating Real Security Risks Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation [Webinar] Why Your AppSec Tools Miss the "Lethal Path" (and How to Fix It) Most Remediation Programs Never Confirm the Fix Actually Worked Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data Android Adds Intrusion Logging for Sophisticated Spyware Forensics New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help Why Agentic AI Is Security's Next Blind Spot Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
2026-04-14 · via The Hacker News

A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta.

"Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real time," Italian online fraud prevention firm Cleafy said.

"Beyond traditional RAT behavior, Mirax enhances its operational value by turning infected devices into residential proxy nodes. Leveraging SOCKS5 protocol support and Yamux multiplexing, it establishes persistent proxy channels that allow attackers to route their traffic through the victim's real IP address."

Details of Mirax first emerged last month when Outpost24's KrakenLabs revealed that a threat actor going by the name "Mirax Bot" has been advertising a private malware-as-a-service (MaaS) offering on underground forums for $2,500 for a three-month subscription. Also available for $1,750 per month is a lightweight variant that removes certain features like the proxy and the ability to bypass Google Play Protect using a crypter.

Like other Android malware, Mirax supports the ability to capture keystrokes, steal photos, gather lock screen details, run commands, navigate the user interface, and monitor user activity on the compromised device. It can also dynamically fetch HTML overlay pages from a command-and-control (C2) server to be rendered over legitimate applications for credential theft.

The incorporation of a SOCKS proxy, on the other hand, is a relatively lesser-known feature that sets it apart from conventional RAT behavior. The proxy botnet offers several advantages in that it allows threat actors to get around geolocation-based restrictions, evade fraud detection systems, and conduct account takeovers or transaction fraud under the guise of increased anonymity and legitimacy.

Cybersecurity

"Unlike typical MaaS offerings, Mirax is distributed through a highly controlled and exclusive model, limited to a small number of affiliates," researchers Alberto Giust, Alessandro Strino, and Federico Valentini said. "Access appears to be prioritized for Russian-speaking actors with established reputations in underground communities, indicating a deliberate effort to maintain operational security and campaign effectiveness."

Attack chains distributing the malware use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them. As many as six ads have been observed actively advertising a streaming service with free access to live sports and movies. Of these, five ads are directed against users in Spain. One of the ads, which started running on April 6, 2026, has a reach of 190,987 accounts.

The dropper app URLs implement a number of checks to ensure that they are accessed from mobile devices and to prevent automated scans from revealing their true color. The names of the malicious apps are listed below -

  • StreamTV (org.lgvvfj.pluscqpuj or org.dawme.secure5ny) - Dropper app
  • Reproductor de video (org.yjeiwd.plusdc71 or org.azgaw.managergst1d) - Mirax

A notable aspect of the campaign is the use of GitHub to host the malicious dropper APK files. In addition, the builder panel offers the ability to choose between two crypters – Virbox and Golden Crypt (aka Golden Encryption) – for enhanced APK protection.

Once installed, the dropper instructs users to allow installation from unknown sources to deploy the malware. The process of extracting the final payload is a "sophisticated, multi-stage operation" that's designed to sidestep security analysis and automated sandboxing tools.

The malware, after getting installed on the device, masquerades as a video playback utility and prompts the victim to enable accessibility services, thereby allowing it to run in the background, display a fake error message stating the installation was unsuccessful, and serve bogus overlays to conceal malicious activities.

It also establishes multiple bidirectional C2 channels for tasking and data exfiltration -

  • WebSocket on port 8443, to manage remote access and execute remote commands.
  • WebSocket on port 8444, to manage remote streaming and data exfiltration.
  • WebSocket on port 8445 (or a custom port), to set up the residential proxy using SOCKS5.

Cybersecurity

"This convergence of RAT and proxy capabilities reflects a broader shift in the threat landscape," Cleafy said. "While residential proxy abuse has historically been associated with compromised IoT devices and low-cost Android hardware such as smart TVs, Mirax marks a new phase by embedding this functionality within a full-featured banking trojan."

"This approach not only increases the monetization potential of each infection but also expands the operational scope of attackers, who can now leverage compromised devices for both direct financial fraud and as infrastructure for wider cybercriminal activities."

The disclosure comes as Breakglass Intelligence detailed an Arabic-language Android RAT called ASO RAT that's distributed via apps disguised as PDF readers and Syrian government applications.

"The platform provides full device compromise capabilities – SMS interception, camera access, GPS tracking, call logging, file exfiltration, and DDoS launching from victim devices," the company said. "A multi-user panel with role-based access control suggests this operates as a RAT-as-a-Service or supports a multi-operator team."

It's currently not known what the exact end goals of the campaign are, but Syria-themed lures for the apps (e.g., SyriaDefenseMap and GovLens) suggest that it may be targeting individuals with an interest in Syrian military or governance matters as part of what's suspected to be a surveillance operation.

Update

Following the publication of the story, a Google spokesperson shared the following statement with The Hacker News -

"Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.