TaxiSpy RAT

Malware family · 5 sample(s) · 5 indicator record(s) · 1 signing certificate(s) · Active 2026-02-19 → 2026-02-26 (experimental)

About TaxiSpy RAT

TaxiSpy is a Russian-nexus Android banking RAT that combines SMS theft, hidden VNC remote control and overlays to run on-device fraud. It intercepts and forwards incoming SMS (OTP and bank codes), gives the operator a live VNC view/control channel to drive the infected device directly, and beacons to its C2 at mproxs.info. Used against Russian-speaking targets.

Indicators

IndicatorTypeSampleFirst seen
mproxs.info domain 550ca70e1d0c… 2026-02-22
mproxs.info domain cbf0b7a742ad… 2026-02-19
mproxs.info domain 9457bd1ff25c… 2026-02-26
mproxs.info domain 610cc1ca02e3… 2026-02-23
mproxs.info domain dfe26af80da4… 2026-02-25