A new private Android malware-as-a-service (MaaS) platform has been identified actively advertised on underground cybercrime forums under the name Mirax Bot, operated by a threat actor going by the same moniker. First flagged by researchers at KrakenLabs, Mirax is positioned as a full-featured Android banking trojan rental targeting financial institutions at scale, combining credential theft, remote device control, SMS interception, and residential proxy routing into a single integrated toolkit. The platform is marketed as a closed rental with a limited number of slots a deliberate scarcity tactic common in the underground MaaS market to convey exclusivity and maintain operational security among subscribers. All advertised capabilities below are seller claims and have not been independently verified at time of publication.
What Is Mirax Bot?
Mirax Bot belongs to a well-established and growing class of Android banking trojans that operate via the MaaS model, where developers rent access to a fully managed malware infrastructure including the malware APK, a command-and-control (C2) panel, and subscriber support to cybercriminal affiliates who conduct their own distribution campaigns. This model, pioneered by families such as Cerberus, DroidBot, Octo, Hook, and more recently Albiriox and FvncBot, lowers the technical barrier to sophisticated mobile fraud dramatically. Affiliates need no malware development capability they purchase operational access and focus resources on distribution and monetization. Mirax Bot's feature set, as presented in the operator's underground forum advertisement, is consistent with the current state-of-the-art in Android banking trojans and reflects the accumulated capability baseline of the post-Cerberus MaaS ecosystem.
Capability Analysis: A Full Account Takeover Stack
The following capabilities are claimed by the Mirax Bot operator in their underground forum listing, organized by functional category:
Banking Overlays and HTML Injection- 700+ banking overlay templates covering a wide range of financial institutions, with dynamic template loading, add/remove/update functionality, and auto-blocking of repeated injections after a successful capture to avoid alerting the victim
- Template library with automatic sending of injects to all devices, individual on/off control per template, in-panel template preview, and filtering and search capabilities a commercially polished interface indicative of a professional MaaS operator
- Launch, delete, or block any application on the infected device via a fake "technical maintenance" overlay, allowing operators to suppress competing banking apps or security tools
- Accessibility VNC (AVNC) and Hidden VNC (HVNC) for stealth remote viewing and interaction HVNC operates a hidden secondary display invisible to the victim, enabling full on-device fraud (ODF) without triggering suspicious screen activity
- Device lock/unlock control including wake/unlock, battery saver bypass (automatic), and lock pattern/PIN capture enabling unattended fraud sessions on locked devices
- Full keylogging via Accessibility Services abuse, capturing PINs, passwords, and system prompts across all applications
- Automatic permission granting including a mode that first requests Notification permission to improve conversion rates, followed by silent escalation to full Accessibility access a staged permission harvesting approach designed to reduce user suspicion
- Full SMS operations: read, send, delete, full history retrieval, and contact list parsing enabling OTP/2FA interception and social engineering of victim contacts
- Notification capture in three modes: standard (package + title), Toast (text only), and full-screen overlay covering all common banking app authentication notification formats
- Reverse SOCKS5 proxy via victim device IP routes operator authentication attempts through the victim's own residential IP address, defeating bank-side geo-IP and device fingerprinting fraud controls. This is a particularly significant anti-fraud bypass capability, as it makes fraudulent logins appear to originate from the victim's known device and location
- Anti-removal and Google Play Protect bypass via "crypting" the APK is obfuscated through a crypter service to evade signature-based detection by Play Protect and third-party AV solutions
- Full log export in JSON and CSV formats covering keylogs, SMS intercepts, inject data, and pattern/PIN captures enabling bulk data processing across large victim pools
- Structured C2 panel with per-device management, real-time status tracking, and presumably Telegram integration for near-real-time operator alerting (consistent with the current MaaS standard)
Pricing Model: Subscription Tiers and Closed Availability
The Mirax Bot operator advertises a tiered rental model with the following pricing (seller claims):
- 30-day FULL: $2,500 includes cryptor, reverse proxy infrastructure, and full feature access
- 30-day LIGHT: $1,750 no cryptor or proxy; infrastructure responsibility falls on the buyer
- 14-day LIGHT: $1,000 shorter term, same LIGHT restrictions
- Add-on APK Loader: $500
The pricing is positioned below the $3,000/month benchmark set by DroidBot and in line with mid-tier Android MaaS offerings. The "closed rental" framing with a fixed number of FULL and LIGHT slots advertised as remaining is a standard underground marketing technique that creates artificial scarcity, encourages faster purchasing decisions, and limits the operator's exposure to a manageable number of affiliates for operational security reasons.
Why This Capability Stack Is Dangerous: ATO at Scale
As KrakenLabs researchers note, the Mirax Bot feature stack is specifically optimized for account takeover (ATO) and fraud at scale. The combination of three distinct capability layers creates a self-reinforcing fraud pipeline: credential capture (overlays, keylogging, PIN capture) feeds initial account access; remote interaction (HVNC, AVNC, app control) enables on-device fraud without credential exfiltration; and residential proxying (SOCKS5 via victim IP) defeats the geographic and device-based fraud signals that banks rely on to flag anomalous transactions. Each layer independently represents a significant fraud capability combined, they constitute a fraud stack that can defeat most consumer banking security controls deployed today, including MFA via SMS OTP (intercepted), push notification authentication (intercepted via notification capture), and location-based fraud rules (bypassed via residential proxy).
Broader Context: The Android MaaS Ecosystem in 2025–2026
Mirax Bot enters a market that has matured considerably since the Cerberus source code leak of 2020 democratized access to advanced Android banking trojan techniques. The current generation of Android MaaS offerings including Octo2, Hook, Albiriox, BlankBot, FvncBot, and now Mirax consistently feature HVNC-based remote control, overlay inject libraries targeting hundreds of institutions, SMS/OTP interception, and increasingly sophisticated anti-detection measures. The addition of residential SOCKS5 proxying via victim device IP is a particularly notable trend, reflecting an arms race between banking fraud detection systems (which increasingly rely on IP reputation and device fingerprinting) and MaaS operators who have responded by routing fraud sessions through the victim's own network. The 700+ inject template count positions Mirax competitively in terms of geographic targeting breadth, though the actual quality and currency of those templates cannot be verified from the advertisement alone.
Intelligence Assessment and Defensive Recommendations
IntelFusions assesses with low-to-moderate confidence that Mirax Bot represents a credible new entry into the Android banking MaaS market based on the technical specificity and operational detail of its underground advertisement, which is consistent with a functional product rather than an exit scam or vaporware listing. The feature set as described does not introduce novel capabilities beyond the current MaaS baseline, but the combination of HVNC, residential proxying, and a 700+ template library in a single platform at its stated price point represents meaningful value for criminal affiliates. Distribution method and initial target geographies are not yet confirmed from available open-source intelligence.
Financial institutions and mobile security teams should monitor for Mirax Bot-related activity as distribution campaigns emerge. Detection signals to watch for include accessibility service abuse by newly installed apps, unexpected SOCKS5 proxy configuration changes, and overlay injection patterns targeting banking app package names. End users should be reminded that legitimate banking applications never request Accessibility Services access, and that any app requesting such permissions after installation should be treated with extreme suspicion.
This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. All Mirax Bot capability claims are sourced from underground forum advertisements and have not been independently verified. Claims described herein should be treated as seller representations unless corroborated by technical analysis.