Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Mirax Bot

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

15 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence2

The malware is distributed through attack chains that use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence2

The malware is distributed through attack chains that use Meta ads to promote dropper app web pages, tricking unsuspecting users into downloading them.

T1566.003Spearphishing via ServiceEvidence1

An emerging remote access Trojan targeting Android devices in Spanish-speaking nations is propagating fraudulent advertisements as an initial access point on Meta-owned applications.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence2

Mirax - also tracked as Mirax Bot - is capable of capturing keystrokes, stealing photos or data, including lock screen details, running commands and monitoring user activity.

T1204User ExecutionEvidence2

After installation, a dropper deploys malware by prompting users to allow for installation from an 'unknown source,' resulting in a 'sophisticated, multi-stage operation' designed for evasion.

Persistence

1 technique
T1546.008Accessibility FeaturesEvidence1

The malware masquerades behind video playback features, further prompting the victim to enable accessibility services that open the door to Mirax.

Privilege Escalation

2 techniques
T1546.008Accessibility FeaturesEvidence1

The malware masquerades behind video playback features, further prompting the victim to enable accessibility services that open the door to Mirax.

T1548.005Temporary Elevated Cloud AccessEvidence1

The malware masquerades behind video playback features, further prompting the victim to enable accessibility services that open the door to Mirax.

Stealth

1 technique
T1036MasqueradingEvidence2

The malware masquerades behind video playback features, further prompting the victim to enable accessibility services that open the door to Mirax.

Credential Access

3 techniques
T1056Input CaptureEvidence1

It uses overlay pages over legitimate apps to steal credentials or display notifications coming from apps.

T1056.001KeyloggingEvidence2

Mirax - also tracked as Mirax Bot - is capable of capturing keystrokes, stealing photos or data, including lock screen details, running commands and monitoring user activity.

T1649Steal or Forge Authentication CertificatesEvidence1

It uses overlay pages over legitimate apps to steal credentials or display notifications coming from apps.

Collection

2 techniques
T1056Input CaptureEvidence1

It uses overlay pages over legitimate apps to steal credentials or display notifications coming from apps.

T1056.001KeyloggingEvidence2

Mirax - also tracked as Mirax Bot - is capable of capturing keystrokes, stealing photos or data, including lock screen details, running commands and monitoring user activity.

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence1

The RAT is localized to Meta-operated platforms, 'relying on SOCKS5 protocol support and Yamux multiplexing' to establish proxy channels and uncover a victim's IP address.

T1090.002External ProxyEvidence1

Mirax and its advanced capabilities allow threat actors to interact with devices in real time, compromising and converting them into residential proxy nodes... relying on SOCKS5 protocol support and Yamux multiplexing to establish proxy channels.

T1090.003Multi-hop ProxyEvidence1

Mirax and its advanced capabilities allow threat actors to interact with devices in real time, compromising and converting them into residential proxy nodes... relying on SOCKS5 protocol support and Yamux multiplexing to establish proxy channels

T1105Ingress Tool TransferEvidence2

Mirax also utilizes GitHub as a malicious APK file dropper, offering two options of crypters - Virbox or Golden Crypt.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping15

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.