Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads

2026-04-14T13:24:11Z8929b700078f77ad6052b9658b2066e20f9f8a5673bf63d584e0d8697486db29
AdobeAdobe-Reader-zero-dayC2CISA-KEVCPUIDCVE-2025-0520CVE-2026-21643CVE-2026-34621CVE-2026-39987EngageLab-SDKGlassWormIDE-compromise','JanelaRAT','LucidRook','RokRAT','W3LL','phish'MarimoMiraxRATSOCKS5ShowDocSmart-SliderWeblocZig-dropperandroidmalicious-chrome-extensionsmeta-adssupply-chaintracking

What happened

A broad range of high-risk activity and active exploitation was reported: multiple critical RCE and exploitation campaigns (ShowDoc CVE-2025-0520, Marimo CVE-2026-39987, Adobe Acrobat CVE-2026-34621 and an Adobe Reader zero-day) are being actively exploited; CISA added known exploited flaws including CVE-2026-21643. Simultaneously, malware and intrusions are proliferating—new and updated RAT families (Mirax Android RAT distributing SOCKS5 proxies via Meta ads, JanelaRAT, RokRAT, STX RAT, LucidRook), large-scale malicious browser-extension campaigns, supply-chain compromises (CPUID, SmartSlider

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
8929b700078f77ad6052b9658b2066e20f9f8a5673bf63d584e0d8697486db29
Enrichment time
2026-04-14T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.