TaxiSpy RAT
Malware family · 5 sample(s) · 5 indicator record(s) · 1 signing certificate(s) · Active 2026-02-19 → 2026-02-26 (experimental)
About TaxiSpy RAT
TaxiSpy is a Russian-nexus Android banking RAT that combines SMS theft, hidden VNC remote control and overlays to run on-device fraud. It intercepts and forwards incoming SMS (OTP and bank codes), gives the operator a live VNC view/control channel to drive the infected device directly, and beacons to its C2 at mproxs.info. Used against Russian-speaking targets.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| mproxs.info | domain | 550ca70e1d0c… | 2026-02-22 |
| mproxs.info | domain | cbf0b7a742ad… | 2026-02-19 |
| mproxs.info | domain | 9457bd1ff25c… | 2026-02-26 |
| mproxs.info | domain | 610cc1ca02e3… | 2026-02-23 |
| mproxs.info | domain | dfe26af80da4… | 2026-02-25 |