Mirax malware campaign hits 220K accounts, enables full remote control
2026-04-15T14:51:46Z•a27315f9536ffcde4d3537f48d600360d29c561468266eabbd43bea3753c3339
Android RATBasic-FitBooking.comCISA KEVCVE-2025-0520CVE-2026-32201DLL sideloadingMeta adsMicrosoft Patch TuesdayMiraxOperation AtlanticPHP ComposerPerforce VCSPlugXRockstar GamesSOCKS5 proxySharePoint zero-dayShinyHuntersShowDocactive exploitationcryptocurrency theftdata breachremote access trojanremote command execution
What happened
This collection summarizes multiple high-impact security incidents and vulnerabilities: a Mirax Android RAT campaign spread via Meta ads, compromising ~220k devices and enabling full remote control and SOCKS5 proxying; two high-severity PHP Composer flaws allowing remote command execution via malicious Perforce VCS configs; Microsoft’s April 2026 Patch Tuesday fixing 165 flaws including an actively exploited SharePoint zero-day (CVE-2026-32201); and active exploitation of a critical ShowDoc RCE (CVE-2025-0520). It also covers major data breaches and leaks (Basic-Fit ~1M members, Booking.com, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- a27315f9536ffcde4d3537f48d600360d29c561468266eabbd43bea3753c3339
- Enrichment time
- 2026-04-15T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.