[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVwC99tasojbkhLAq8LmmebTIQjfabre8ta3OSZV6Qq0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"3d684a10-a1e8-42bd-984a-9a06b3fecc21","mirax-android-rat-exploits-user-trust-and-device-configuration-weaknesses","22cb48eb-5346-4533-bb62-2ceb87b58db6","Mirax Android RAT Exploits User Trust and Device Configuration Weaknesses","The Mirax Android RAT successfully compromised over 220,000 devices by exploiting user trust through legitimate-appearing Meta advertisements and fake streaming apps. Users unknowingly installed malware disguised as popular entertainment applications, demonstrating how social engineering combined with inadequate app verification can lead to massive infections. Beyond typical RAT functionality, Mirax transforms victim devices into SOCKS5 proxy nodes, enabling attackers to route malicious traffic through legitimate residential IP addresses to evade detection and conduct fraud.","**Immediate actions:**\n- Enable Google Play Protect and disable installation from unknown sources in Android settings\n- Review and uninstall any recently downloaded streaming or video player apps from unofficial sources\n- Implement mobile device management (MDM) solutions to control app installations on corporate devices\n\n**Long-term improvements:**\n- Establish user education programs focusing on identifying malicious advertisements and fake apps\n- Deploy mobile threat detection solutions that can identify proxy traffic and suspicious network behavior\n- Create policies requiring app installation approval for business-critical devices\n\n**Detection measures:**\n- Monitor network traffic for unusual SOCKS5 proxy connections from mobile devices\n- Implement behavioral analysis to detect devices exhibiting proxy server characteristics\n- Set up alerts for applications requesting excessive permissions during installation",[12,13,14,15,16],"CIS Control 7","CIS Control 12","NIST SP 800-124","NIST CM-11","OWASP Mobile Top 10","published","2026-04-14T14:10:01.796092+00:00","2026-04-14T14:10:01.643+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F04\u002Fmirax-android-rat-turns-devices-into.html","mirax-android-rat-turns-devices-into-socks5-proxies-reaching-220-000-via-meta-ad-5619cd","Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]