← Back to BrewedIntel
malwarehighAndroid RATMobile TrojanMirax

Apr 14, 2026 • [email protected] (The Hacker News)

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

A newly discovered Android Remote Access Trojan (RAT) dubbed 'Mirax' is actively targeting users in Spanish-speaking countries through malicious...

Source
The Hacker News
Category
malware
Severity
high

Executive Summary

A newly discovered Android Remote Access Trojan (RAT) dubbed 'Mirax' is actively targeting users in Spanish-speaking countries through malicious advertisements on Meta's platforms, including Facebook, Instagram, Messenger, and Threads. The campaign has reached over 220,000 accounts. Mirax provides threat actors with full remote control of compromised devices and converts them into SOCKS5 proxies for anonymized network traffic. Organizations should warn users about downloading apps from untrusted sources and ensure mobile devices run security solutions capable of detecting Android RATs. Monitor for unusual outbound traffic that may indicate a device has been enrolled in a proxy botnet.

Summary

A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. "Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real

Published Analysis

A newly discovered Android Remote Access Trojan (RAT) dubbed 'Mirax' is actively targeting users in Spanish-speaking countries through malicious advertisements on Meta's platforms, including Facebook, Instagram, Messenger, and Threads. The campaign has reached over 220,000 accounts. Mirax provides threat actors with full remote control of compromised devices and converts them into SOCKS5 proxies for anonymized network traffic. Organizations should warn users about downloading apps from untrusted sources and ensure mobile devices run security solutions capable of detecting Android RATs. Monitor for unusual outbound traffic that may indicate a device has been enrolled in a proxy botnet. A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. "Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. "Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real

Linked Entities

  • Mirax