216.73.217.22

A new Android RAT turning infected devices into potential residential proxy nodes

· Published 13/04/2026 14:27 · Modified 13/04/2026 14:47

Export JSON

Essential information

Published
13/04/2026 14:27
Modified
13/04/2026 14:47
Tags
2026-04-13 albiriox android banking trojan html overlay meta advertisements mirax rat residential proxy socks5 spanish targets teabot
Related entities
2 observables, 3 malware, 4 others

Description

is a newly identified Remote Access Trojan operating as Malware-as-a-Service, actively targeting European users, particularly in Spanish-speaking regions. Distributed through and GitHub-hosted droppers, the malware has reached over 200,000 accounts. It employs sophisticated techniques including dynamically fetched HTML overlays, comprehensive keylogging, and remote device control capabilities. A distinctive feature is its integration of -based functionality, transforming infected devices into proxy nodes that enable attackers to route traffic through legitimate residential IP addresses. This capability allows operators to bypass geolocation restrictions and evade fraud detection systems while conducting account takeovers and transaction fraud. The malware uses commercial-grade obfuscation through Golden Encryption and establishes persistence through Accessibility Service abuse.

External references