Mirax malware campaign hits 220K accounts, enables full remote control

2026-04-15T14:51:46Za27315f9536ffcde4d3537f48d600360d29c561468266eabbd43bea3753c3339
Android RATBasic-FitBooking.comCISA KEVCVE-2025-0520CVE-2026-32201DLL sideloadingMeta adsMicrosoft Patch TuesdayMiraxOperation AtlanticPHP ComposerPerforce VCSPlugXRockstar GamesSOCKS5 proxySharePoint zero-dayShinyHuntersShowDocactive exploitationcryptocurrency theftdata breachremote access trojanremote command execution

What happened

This collection summarizes multiple high-impact security incidents and vulnerabilities: a Mirax Android RAT campaign spread via Meta ads, compromising ~220k devices and enabling full remote control and SOCKS5 proxying; two high-severity PHP Composer flaws allowing remote command execution via malicious Perforce VCS configs; Microsoft’s April 2026 Patch Tuesday fixing 165 flaws including an actively exploited SharePoint zero-day (CVE-2026-32201); and active exploitation of a critical ShowDoc RCE (CVE-2025-0520). It also covers major data breaches and leaks (Basic-Fit ~1M members, Booking.com, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a27315f9536ffcde4d3537f48d600360d29c561468266eabbd43bea3753c3339
Enrichment time
2026-04-15T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.