Mirax Bot: New Android Banking MaaS Emerges on Underground Forums with HVNC, 700+ Injects, and ATO-Optimized Feature Stack

A new private Android malware-as-a-service (MaaS) platform has been identified actively advertised on underground cybercrime forums under the name Mirax Bot, operated by a threat actor going by the same moniker. First flagged by researchers at KrakenLabs, Mirax is positioned as a full-featured Android banking trojan rental targeting financial institutions at scale, combining credential theft, remote device control, SMS interception, and residential proxy routing into a single integrated toolkit. The platform is marketed as a closed rental with a limited number of slots a deliberate scarcity tactic common in the underground MaaS market to convey exclusivity and maintain operational security among subscribers. All advertised capabilities below are seller claims and have not been independently verified at time of publication.

What Is Mirax Bot?

Mirax Bot belongs to a well-established and growing class of Android banking trojans that operate via the MaaS model, where developers rent access to a fully managed malware infrastructure including the malware APK, a command-and-control (C2) panel, and subscriber support to cybercriminal affiliates who conduct their own distribution campaigns. This model, pioneered by families such as Cerberus, DroidBot, Octo, Hook, and more recently Albiriox and FvncBot, lowers the technical barrier to sophisticated mobile fraud dramatically. Affiliates need no malware development capability they purchase operational access and focus resources on distribution and monetization. Mirax Bot's feature set, as presented in the operator's underground forum advertisement, is consistent with the current state-of-the-art in Android banking trojans and reflects the accumulated capability baseline of the post-Cerberus MaaS ecosystem.

Capability Analysis: A Full Account Takeover Stack

The following capabilities are claimed by the Mirax Bot operator in their underground forum listing, organized by functional category:

Banking Overlays and HTML Injection App Management and Device Control Keylogging and Credential Capture SMS and Communications Interception Anti-Fraud Enablement and Evasion Operator Infrastructure and Data Export

Pricing Model: Subscription Tiers and Closed Availability

The Mirax Bot operator advertises a tiered rental model with the following pricing (seller claims):

The pricing is positioned below the $3,000/month benchmark set by DroidBot and in line with mid-tier Android MaaS offerings. The "closed rental" framing with a fixed number of FULL and LIGHT slots advertised as remaining is a standard underground marketing technique that creates artificial scarcity, encourages faster purchasing decisions, and limits the operator's exposure to a manageable number of affiliates for operational security reasons.

Why This Capability Stack Is Dangerous: ATO at Scale

As KrakenLabs researchers note, the Mirax Bot feature stack is specifically optimized for account takeover (ATO) and fraud at scale. The combination of three distinct capability layers creates a self-reinforcing fraud pipeline: credential capture (overlays, keylogging, PIN capture) feeds initial account access; remote interaction (HVNC, AVNC, app control) enables on-device fraud without credential exfiltration; and residential proxying (SOCKS5 via victim IP) defeats the geographic and device-based fraud signals that banks rely on to flag anomalous transactions. Each layer independently represents a significant fraud capability combined, they constitute a fraud stack that can defeat most consumer banking security controls deployed today, including MFA via SMS OTP (intercepted), push notification authentication (intercepted via notification capture), and location-based fraud rules (bypassed via residential proxy).

Broader Context: The Android MaaS Ecosystem in 2025–2026

Mirax Bot enters a market that has matured considerably since the Cerberus source code leak of 2020 democratized access to advanced Android banking trojan techniques. The current generation of Android MaaS offerings including Octo2, Hook, Albiriox, BlankBot, FvncBot, and now Mirax consistently feature HVNC-based remote control, overlay inject libraries targeting hundreds of institutions, SMS/OTP interception, and increasingly sophisticated anti-detection measures. The addition of residential SOCKS5 proxying via victim device IP is a particularly notable trend, reflecting an arms race between banking fraud detection systems (which increasingly rely on IP reputation and device fingerprinting) and MaaS operators who have responded by routing fraud sessions through the victim's own network. The 700+ inject template count positions Mirax competitively in terms of geographic targeting breadth, though the actual quality and currency of those templates cannot be verified from the advertisement alone.

Intelligence Assessment and Defensive Recommendations

IntelFusions assesses with low-to-moderate confidence that Mirax Bot represents a credible new entry into the Android banking MaaS market based on the technical specificity and operational detail of its underground advertisement, which is consistent with a functional product rather than an exit scam or vaporware listing. The feature set as described does not introduce novel capabilities beyond the current MaaS baseline, but the combination of HVNC, residential proxying, and a 700+ template library in a single platform at its stated price point represents meaningful value for criminal affiliates. Distribution method and initial target geographies are not yet confirmed from available open-source intelligence.

Financial institutions and mobile security teams should monitor for Mirax Bot-related activity as distribution campaigns emerge. Detection signals to watch for include accessibility service abuse by newly installed apps, unexpected SOCKS5 proxy configuration changes, and overlay injection patterns targeting banking app package names. End users should be reminded that legitimate banking applications never request Accessibility Services access, and that any app requesting such permissions after installation should be treated with extreme suspicion.

This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. All Mirax Bot capability claims are sourced from underground forum advertisements and have not been independently verified. Claims described herein should be treated as seller representations unless corroborated by technical analysis.

Read the full analysis on IntelFusions