HomeSecurityMirax Bot: New Android malware advertised on hacking forum

Mirax Bot: New Android malware advertised on hacking forum

A new and particularly worrying malware for Android has begun to appear on underground cybercrime forums, causing serious concern among cybersecurity experts. The malware, known as Mirax Bot, is being promoted by threat actors as a sophisticated tool designed for banking fraud and mass theft of financial data.

Mirax Bot: New Android malware

Mirax Bot is available as Malware-as-a-Service (MaaS), meaning that one does not need to be a programmer or experienced hacker to use it. Instead, one can "rent" it for a specific period of time, just like one would with legitimate commercial software.

The tool's advertisement has been spotted on ExploitForum, one of the most well-known underground forums where hacking tools, stolen data, and cybercrime services are exchanged.

The new era of Cybercrime-as-a-Service

See also: Microsoft: New ClickFix campaign distributes Lumma Stealer

The emergence of Mirax Bot reflects a broader trend in cybercrime. In recent years, attack tools have been transformed into commercial “service packages” offered to criminals with a low technical background.

This model works similarly to SaaS software used in the business world. Malware creators provide the platform, updates, and even technical support to their customers.

In the case of Mirax Bot, pricing varies depending on the package. According to the advertisement, there is a 30-day LIGHT package that costs $1,750 and a smaller 14-day version that costs $1,000. In addition, a separate APK Loader tool is offered for $500 to distribute the malware to target devices.

Mirax Bot: Discovery by cybersecurity researchers

Mirax Bot was detected on March 5, 2026 by researchers at KrakenLabs, who systematically monitor activity on illegal forums and online marketplaces.

Android adware

According to researchers, the malware appears to be designed for bank account takeover attacks (Account Takeover – ATO), combining multiple techniques such as credential theft, remote device control, and the use of infected smartphones as proxies.

However, experts point out that many of the capabilities advertised for the malware are claims by the creator and have not yet been fully verified through independent technical analysis.

Use of infected devices as “proxies”

One of the most dangerous features attributed to Mirax Bot is its ability to turn infected Android devices into proxies.

See also: Phobos ransomware administrator pleads guilty

Simply put, attackers can route malicious activity through the victim's Internet connection, making banking transactions appear to come from the user's actual device and IP address.

This significantly hampers the fraud detection systems used by banks, which often rely on identifying suspicious IP addresses or geographic locations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

HVNC: Invisible remote control of the device

Another particularly dangerous feature of Mirax Bot is its HVNC (Hidden Virtual Network Computing) technology. This is a method that allows attackers to fully control an infected Android device without the user realizing anything.

Unlike classic remote access tools, HVNC creates a hidden session in which the hacker can interact with applications on the device without any activity appearing on the user's screen.

Thus, an attacker can open banking applications, authorize transactions, transfer money, or collect data without being noticed.

Attacks with fake banking application screens

Mirax Bot also reportedly has a huge library of more than 700 so-called “injects.” These are fake screens that appear on top of real banking or payment apps.

When the user opens a banking app, a fake form appears that looks exactly like the normal interface. The user enters the login credentials, one‑time passwords (OTP) or card details, which are sent directly to the attackers.

Support for hundreds of applications means the malware can target users of banks, crypto wallets, and payment services in multiple countries simultaneously.

See also: Authorities dismantled the infrastructure of the phishing service Tycoon2FA

Mirax Bot: New Android malware advertised on hacking forum

How Android users can protect themselves

Cybersecurity experts recommend some basic protection measures for Android users. First of all, apps should only be installed from the official Google Play.

Installing applications from unknown sources or via unofficial APK files significantly increases the risk of infection.

In addition, it is important to keep Google Play Protect active, carefully check the permissions requested by applications, and use reliable mobile security solutions with capabilities to detect suspicious behavior.

At the same time, banks and payment providers are urged to invest in more sophisticated fraud detection systems that are based on user and device behavior analysis and not solely on IP address or geographic location.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS