Mirax is an Android remote-access trojan with banking-credential theft and residential-proxy capabilities. It is offered as a restricted malware-as-a-service platform and has been associated with campaigns targeting Spanish-speaking users, particularly through fraudulent streaming and IPTV-themed lures promoted in paid advertisements on Meta platforms. Infection relies on social engineering that persuades victims to sideload a dropper and grant installation-from-unknown-sources and Android Accessibility permissions. The multi-stage dropper decrypts and installs the final payload while using obfuscation, dynamic code loading, and repacking intended to hinder analysis and detection. Mirax masquerades as a video utility, can present deceptive error pages and overlays, and remains active in the background after Accessibility access is granted. The malware supports real-time device interaction, screen capture, VNC-style remote control, Accessibility-based UI navigation, keystroke capture, application management, data theft, remote command execution, and HTML or JavaScript overlays for credential harvesting. It uses WebSocket-based command-and-control communications. A distinctive feature is its integrated SOCKS5 residential-proxy function, which uses persistent multiplexed channels to route attacker traffic through an infected device's residential connection; this can support fraud, account takeover, password spraying, geolocation evasion, and other anonymized malicious activity. Reports have described access as limited to a small number of trusted affiliates, reportedly favoring established Russian-speaking cybercriminal actors, but no named operator attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“GoldenCrypt”, is reportedly affiliated ... with multiple malware families, including FvncBot, Albiriox, and Mirax.
A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is distributed through attack chains that use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them.
...including screen monitoring, credential harvesting, and remote command execution.
“Crypting” is what threat researchers generally refer to as a service or product wherein a file, almost exclusively a malicious executable of some kind, is encrypted to bypass malware detection technologies.
Meta and TikTok advertisements impersonat[ed] a free TV-streaming service... The downloaded file was a dropper... The payload used application names including “StrεαmTV Pro” and “Sistema de vídeo.”
Once executed, it extracts and decrypts the payload using RC4 with a hardcoded key, revealing the malicious code. The final payload is another encrypted APK stored inside the app, decrypted via XOR and then installed.
With these permissions, Mirax runs silently, using overlays and fake pages to steal credentials and bypass protections.
Mirax - also tracked as Mirax Bot - is capable of capturing keystrokes, stealing photos or data, including lock screen details, running commands and monitoring user activity.
With these permissions, Mirax runs silently, using overlays and fake pages to steal credentials and bypass protections.
It communicates with command-and-control servers via WebSockets, enabling real-time control and data exfiltration.
Once installed, the dropper unpacks the payload, applies strong obfuscation, and connects via WebSockets.
A key feature is its ability to turn infected devices into SOCKS5 residential proxies, masking attacker activity and enabling broader attacks like fraud, lateral movement, and DDoS.
Mirax and its advanced capabilities allow threat actors to interact with devices in real time, compromising and converting them into residential proxy nodes... relying on SOCKS5 protocol support and Yamux multiplexing to establish proxy channels.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a prior malware distribution linkage for the reused GitHub delivery infrastructure; the final payload in this campaign was StreamRAT.
An earlier campaign/malware operation materially linked to StreamRat through the GitHub account hosting the payload and a closely similar dropper. The content provides no further functional details.
Mentioned only as related reading; described here as an Android trojan that turns devices into residential proxy nodes.
Named as a malware family reportedly affiliated with the GoldenCrypt crypting service provider.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.