Mirax
Malware family · 2 sample(s) · 2 indicator record(s) · 2 signing certificate(s) · Active 2025-12-10 → 2026-04-10 (experimental)
About Mirax
Mirax is an Android RAT that turns the infected device into a SOCKS5 proxy node while also providing remote-control and stealer functionality. It is delivered both directly and as the payload of other droppers (for example the Black Hawk twin-asset dropper). Proxy/C2 coordination is at ilovepng.info. The family packs its real payload inside heavily obfuscated, sometimes deliberately malformed APK containers to resist static analysis.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| ilovepng.info:8443/control | domain | 29577570d184… | 2025-12-10 |
| ilovepng.info:8443/control | domain | 88e6e4a5478a… | 2026-04-10 |