New Android Mirax Bot Advertised on Cybercriminal Forums Claiming Advanced Capabilities
A new Android banking malware known as Mirax Bot has appeared on underground cybercriminal platforms. It is promoted as an advanced tool designed for financial fraud.
A new Android banking malware known as Mirax Bot has appeared on underground cybercriminal platforms. It is promoted as an advanced tool designed for financial fraud.
The malware is available under a Malware-as-a-Service (MaaS) model. It is offered in various rental tiers, making it accessible to a wide range of individuals, regardless of technical expertise.
The introduction of Mirax Bot indicates a significant shift in mobile cybercrime, with sophisticated tools being sold similarly to commercial software, lowering the barrier for executing large-scale banking fraud against Android users globally.
Advertising for Mirax Bot is currently found on ExploitForum, a known marketplace for trading tools, services, and stolen data among cybercriminals.
The listing highlights that Mirax Bot supports over 700 application injects and features Hidden Virtual Network Computing (HVNC), enabling attackers to steal credentials and remotely control infected devices without visible signs of compromise.
The rental pricing is structured in tiers: a 30-day LIGHT package at $1,750, a 14-day LIGHT option at $1,000, and an optional APK Loader add-on for an additional $500.
A new Android banking malware known as Mirax Bot has appeared on underground cybercriminal platforms.
KrakenLabs researchers identified Mirax Bot on March 5, 2026, after tracking its advertisements on various platforms.
The malware is reportedly designed to support account takeover operations and financial fraud by combining credential capture, real-time remote device interaction, and residential proxying through compromised Android devices.
The researchers noted that the capabilities listed in the advertisement are claims from the seller and have not been independently verified.
HVNC and Inject-Based Credential Theft
Mirax Bot's most technically dangerous components are its HVNC capability and extensive library of over 700 targeted application injects.
HVNC, or Hidden Virtual Network Computing, allows attackers to remotely and silently control an infected device without the victim's awareness. Attackers can open apps, initiate transactions, and extract data without detection.
The inject library works in tandem with HVNC by overlaying fake screens on legitimate banking apps, tricking users into entering sensitive information, which is then captured by the attacker.
The inject support spans over 700 apps, including banks, crypto wallets , and payment services, making Mirax Bot a global threat.
To mitigate such threats, Android users should install applications only from the Google Play Store and avoid sideloading APKs from unknown sources. Keeping Google Play Protect active, reviewing app permissions, and using a mobile security tool with behavioral detection are essential protective measures.
Financial institutions should prioritize device-binding authentication and enhance fraud detection systems by analyzing behavioral patterns instead of relying solely on IP address-based verification.
Based on reporting by Cyber Security News.
