Mirax Bot is the operator name associated with Mirax, a private malware-as-a-service offering centered on an Android remote access trojan that also provides residential proxy functionality. The operation has been described as a controlled affiliate model with access reportedly restricted toward established Russian-speaking underground actors. Mirax has been used in campaigns targeting Spanish-speaking users, particularly in Spain, through social-media advertising lures themed around free streaming content. Mirax supports full remote access and post-compromise control of Android devices, including command execution, user-interface navigation, user activity monitoring, keystroke capture, theft of photos and lock-screen information, and credential harvesting through dynamically delivered overlay pages impersonating legitimate applications. The malware also enables infected devices to function as residential proxy nodes using SOCKS5 and multiplexed proxy channels, allowing operators or customers to route traffic through victims’ real IP addresses for fraud enablement, geolocation bypass, and anonymity. Observed delivery chains use malicious advertisements and staged Android droppers hosted on code-sharing infrastructure. The installation flow relies on social engineering to persuade victims to allow sideloading and enable accessibility services, after which the malware can run persistently in the background while masking activity with deceptive overlays and error messages. Mirax uses a multi-stage deployment chain and anti-analysis measures intended to hinder automated scanning and sandbox inspection. Command-and-control communications have been observed over multiple WebSocket channels supporting remote administration, streaming and exfiltration, and proxy operations. Mirax Bot appears financially motivated, offering both full-featured and reduced-feature variants of the malware service. The actor is notable for combining Android RAT capabilities, credential theft, persistence mechanisms, defense evasion, and monetizable residential proxy access within a private MaaS model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.