Malware
Mirax
aka Astrinox · Mirax Bot · MiraxRAT
Mirax is an Android RAT / banking trojan sold as a private Malware-as-a-Service since December 2025 by an actor using the moniker "Mirax Bot", advertised only to a small pool of predominantly Russian-
Mirax, also known as Astrinox, Mirax Bot, MiraxRAT, is a Android malware family.
Background
Mirax is an Android RAT and banking trojan offered as a private Malware-as-a-Service since December 2025 by an operator going by "Mirax Bot," who markets it only to a limited group of mostly Russian-speaking affiliates. Alongside a standard banking-trojan feature set — HTML/JavaScript overlay injection against banking and cryptocurrency apps, abuse of Accessibility Services, HVNC, keylogging, SMS interception, and harvesting of lock-screen (PIN / pattern / biometric) intelligence — it ships an integrated SOCKS5 residential-proxy module multiplexed via Yamux over the WebSocket C2 channel, converting compromised phones into residential-IP proxy nodes for downstream fraud. Its C2 traffic flows through a C2 Gate server across three simultaneous WebSocket channels (control on 8443, data/streaming on 8444, and the proxy tunnel on 8445). The observed campaigns lean on paid Meta ads posing as IPTV and pirated sports-streaming apps, redirecting victims to droppers on GitHub Releases whose hashes rotate daily; the analyzed campaign focused on Spanish-speaking users in Spain and hit over 220,000 accounts, even though the platform's overlay library also contains templates for German, French, Italian, Polish, Portuguese, and further European languages.
Source: Malpedia (Fraunhofer FKIE).