Mirax RAT - Remove Spyware & Malware with SpyHunter - EnigmaSoft Ltd
Summary
A new Android remote access trojan called Mirax is actively targeting Spanish-speaking users via large-scale deceptive ad campaigns on Meta platforms, reaching hundreds of thousands of accounts. Mirax grants attackers full device control and adds advanced features like keystroke logging, photo exfiltration, dynamic HTML overlays for credential harvesting, and SOCKS5 residential proxy functionality. The malware is offered as a Malware-as-a-Service (Mirax Bot) with tiered pricing and restricted affiliate distribution, and it uses a multi-stage dropper and accessibility-permission abuse to evade detection. Operators host payloads on common infrastructure, use segmented WebSocket channels for control and proxying, and leverage the infected devices to bypass geolocation and fraud detection for broader criminal use.