Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
2026-04-14T13:24:11Z•8929b700078f77ad6052b9658b2066e20f9f8a5673bf63d584e0d8697486db29
AdobeAdobe-Reader-zero-dayC2CISA-KEVCPUIDCVE-2025-0520CVE-2026-21643CVE-2026-34621CVE-2026-39987EngageLab-SDKGlassWormIDE-compromise','JanelaRAT','LucidRook','RokRAT','W3LL','phish'MarimoMiraxRATSOCKS5ShowDocSmart-SliderWeblocZig-dropperandroidmalicious-chrome-extensionsmeta-adssupply-chaintracking
What happened
A broad range of high-risk activity and active exploitation was reported: multiple critical RCE and exploitation campaigns (ShowDoc CVE-2025-0520, Marimo CVE-2026-39987, Adobe Acrobat CVE-2026-34621 and an Adobe Reader zero-day) are being actively exploited; CISA added known exploited flaws including CVE-2026-21643. Simultaneously, malware and intrusions are proliferating—new and updated RAT families (Mirax Android RAT distributing SOCKS5 proxies via Meta ads, JanelaRAT, RokRAT, STX RAT, LucidRook), large-scale malicious browser-extension campaigns, supply-chain compromises (CPUID, SmartSlider
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8929b700078f77ad6052b9658b2066e20f9f8a5673bf63d584e0d8697486db29
- Enrichment time
- 2026-04-14T13:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.