Mirax Android RAT
A new and sophisticated piece of Android malware named Mirax is currently targeting Spanish-speaking users through crafted ads within Meta products. The Mirax malware poses an added danger in that it allows the attacker to create residential proxy nodes from infected devices, giving them access to sensitive data, and providing them with an excellent tool for maintaining their anonymity.
In a recently published report from security research firm Cleafy, researchers explained the ways in which Mirax combines the features typically found in remote access trojans (RATs) with the added component of advanced proxy capabilities. People are being targeted by this malware campaign through ads that promise free live sports or movie streaming, and the tactics have worked well for the attackers.
How the Mirax Campaign Spreads
Malware is distributed through Snapchat and Instagram ads promoting fake apps like "StreamTV" and "Reproductor de video." When users click the ad, they are directed to a dropper webpage that checks whether the visitor is on a mobile device before delivering a malicious APK.
After installation, the dropper asks the user to enable “Install from unknown sources.” Once the real Mirax payload is installed, it masquerades as a video player app. Then it tricks the user into enabling accessibility services.
This enables it to run in the background, silently, while presenting the user with fake error messages that do not raise suspicion.
Advanced Features That Set Mirax Apart
Mirax offers a complete set of RAT functionality, including:
1. Key logging and screen capture
2. File exfiltration
3. Remotely executing commands
4. Overlaying other applications to capture credentials such as online bank account information
Mirax's most unique feature is its ability to utilize a built-in residential proxy, by routing traffic through the victim's actual IP address via the SOCKS5 protocol and Yamux multiplexing.
This allows attackers to:
1. Bypass geolocation-based (Fraud detection);
2. Attack (Takeover)/account takeovers appear legitimate.
3. Hiding the attacker’s true origin during other malicious activities
The malware maintains multiple WebSocket channels for command-and-control communication and supports two powerful crypters (Virbox and Golden Crypt) to evade security analysis and Google Play Protect.
Exclusive Distribution Model
Unlike many mass-market malware-as-a-service offerings, Mirax is sold privately on underground forums. The access is controlled and is directed at a select group of Russian-speaking affiliates who have pre-established credibility. The pricing begins with an initial charge of $2,500 for a three-month subscription period, with alternate pricing available at $1,750 monthly for the lite version.
Currently the campaign has hit over 220,000 Meta accounts through advertising, proving that threat actors are using social media sites as mechanisms for malware distribution.
Why This Malware Represents a New Threat Level
Mirax increases both the immediate monetary benefit and long-term value of every infected device because this malware has the capacity to obtain data as well as code to function as a residential proxy. Compromised phones are now useful for financial fraud while simultaneously being available for renting to facilitate other forms of crime using them as proxies.
This dual purpose usage shows that Android malware has changed over time to use multiple methods to eliminate the single source of revenue per infection.
How to Protect Yourself from Mirax and Similar Threats
Here are some simple but effective steps that anyone can take right now:
1. Be doubtful about advertisements claiming free streaming services such as live sports or movies.
2. Only enable "Unknown sources" on your device when absolutely necessary and turn it off again immediately.
3. Regularly check app permissions (especially accessibility service permissions and storage access).
4. Install a trusted mobile antivirus application that provides advanced real-time protection; installs detect threats proactively before they execute (using behavioral monitoring); and scans for malware on a continuous basis.
5. Avoid clicking on links in Social Media messages and/or advertisements that appear suspicious.
6. Keep your handheld & software applications current so that they have all available security updates.
For Organizations it is strongly encouraged to deploy MDM solutions and conduct end-user training focused on educating users on the risks associated with using Social Media.
Final Thoughts
Mirax is an example of how Android malware has evolved to become the next generation of malicious software by using advanced remote access and by delivering this via infrastructure capabilities such as residential proxies. As threats grow increasingly sophisticated, relying solely on traditional antivirus programs for protection is simply not sufficient.
To protect yourself, you should take a combination of steps to stay safe by exercising caution when interacting with advertisements and messages, maintaining good device hygiene, and using up-to-date security software.
Your best defense against Android malware is developing a heightened sense of awareness. For example, if an offer appears too good to be true on social media, there’s a high probability it’s fraudulent in nature.
FAQ Section
Q1: What is Mirax RAT?
Mirax RAT is a new mobile remote access trojan (RAT) for Android that is designed to steal sensitive information and turn exploited mobile units into residential SOCKS5 proxies for malicious actors.
Q2: What method does Mirax use to distribute itself?
Mirax RAT is distributed through deceptive advertisements on Meta Platforms (formerly known as Facebook) promoting fake streaming applications, which results in users downloading malicious APK files.
Q3: How is Mirax RAT different than other android malware currently on the Internet?
The primary distinguishing characteristic of Mirax RAT is that it can use a compromised device to function as a residential proxy enabling cybercriminals to route internet traffic through real user IP addresses, making it more difficult for law enforcement agencies to track down fraudulent activity.
Q4: What can I do to protect myself from being infected by Mirax RAT on my Android phone?
You can reduce your chances of being infected by following these three steps: Avoiding malicious ads; disabling unknown sources for application installation; reviewing the permissions required by applications before installing them; or using a reputable mobile security solution.
Q5: Is Mirax RAT readily available to all cybercriminals?
Mirax RAT is only accessible via private underground proxy boards and access to Mirax RAT appears to be limited to a select group of trusted Russian-speaking affiliates.
Source: The Hacker News