Mirax is an Android malware family sold as a restricted malware-as-a-service offering and commonly described as a remote access trojan with banking-trojan functionality. It has been active since late 2025 and has primarily targeted Spanish-speaking users through large-scale social-engineering campaigns, including malicious advertisements on Meta platforms that redirect victims to fake IPTV or streaming-themed lures. Infection typically relies on sideloaded Android applications delivered as multi-stage droppers, with payloads concealed through obfuscation, dynamic loading, and packer-assisted unpacking workflows designed to hinder static analysis and evade detection.
The malware uses a two-stage installation chain in which a dropper masquerades as a benign media-related application, prompts the victim to allow installation from unknown sources, and decrypts an embedded or remotely retrievable implant. Reported samples use encrypted Dalvik payloads, dynamic .dex loading, and additional decryption steps before installing the final APK. Mirax has been associated with Golden Encryption, also known as Golden Crypt, a packer used to reduce detection and complicate analysis.
Once installed, Mirax disguises itself as a video utility and abuses Android Accessibility Services to obtain broad control over the device. Documented capabilities include real-time remote control, screen monitoring, user-interface navigation, command execution, app management, keystroke capture, credential theft through overlays, collection of lock-screen and other device data, spyware-style monitoring, and data exfiltration. It can display deceptive pages and overlays to conceal malicious activity, bypass security prompts, and maintain persistence. Mirax communicates with its operators over WebSocket-based channels that support interactive control, remote streaming, and exfiltration.
A distinguishing feature of Mirax is its integrated residential proxy capability. Infected devices can be converted into SOCKS5 proxy nodes, with reported use of multiplexed proxy tunneling over WebSocket channels. This allows operators to route malicious traffic through victims’ residential IP addresses, improving anonymity and helping evade geolocation-based and IP reputation-based fraud controls. This proxy functionality expands Mirax beyond conventional mobile banking malware and enables secondary abuse such as account takeover, transaction fraud, password spraying, anonymized network operations, and potentially distributed denial-of-service activity.
Mirax has been linked to underground operators offering private access to a limited set of affiliates, reportedly favoring established Russian-speaking cybercriminal actors. It has also been discussed alongside other Android malware families targeting payment ecosystems, including campaigns focused on PIX-related fraud. Overall, Mirax represents a modular Android threat that combines financial theft, surveillance, remote administration, defense evasion, and proxyware-style monetization in a single platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.
A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is distributed through attack chains that use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them.
...including screen monitoring, credential harvesting, and remote command execution.
“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies.
By operating within legitimate apps, it can bypass common security checks and facilitate unauthorized transactions or data exfiltration.
Once executed, it extracts and decrypts the payload using RC4 with a hardcoded key, revealing the malicious code. The final payload is another encrypted APK stored inside the app, decrypted via XOR and then installed.
With these permissions, Mirax runs silently, using overlays and fake pages to steal credentials and bypass protections.
Mirax - also tracked as Mirax Bot - is capable of capturing keystrokes, stealing photos or data, including lock screen details, running commands and monitoring user activity.
With these permissions, Mirax runs silently, using overlays and fake pages to steal credentials and bypass protections.
It communicates with command-and-control servers via WebSockets, enabling real-time control and data exfiltration.
Once installed, the dropper unpacks the payload, applies strong obfuscation, and connects via WebSockets.
A key feature is its ability to turn infected devices into SOCKS5 residential proxies, masking attacker activity and enabling broader attacks like fraud, lateral movement, and DDoS.
Mirax and its advanced capabilities allow threat actors to interact with devices in real time, compromising and converting them into residential proxy nodes... relying on SOCKS5 protocol support and Yamux multiplexing to establish proxy channels.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a malware family reportedly affiliated with the GoldenCrypt crypting service provider.
Android remote access trojan distributed through malicious apps and social-engineering lures that enables full control of infected devices, including screen monitoring, credential harvesting, remote command execution, unauthorized transactions, and data exfiltration.
Android malware sold as malware-as-a-service that spreads via Meta ads and fake app lures. It provides full remote access, steals credentials and data, abuses Accessibility permissions, communicates over WebSockets, and can convert infected devices into SOCKS5 residential proxies for attacker operations.
Mirax is an Android banking trojan delivered via fake IPTV or streaming apps promoted through Facebook and Instagram ads. It acts as a dropper-hosted payload that decrypts concealed components, establishes WebSockets-based communications for remote device control and data theft, evades automated analysis, and converts infected devices into residential proxy nodes for illicit traffic routing, account takeover, and anonymized attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.