Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
StreamRat Android trojan distributed via Meta ads to 570K EU users, grants near-complete device control.
Summary
Cybersecurity researchers disclosed StreamRat, a sophisticated Android banking trojan promoted through fake TV-streaming ads on Meta targeting Spanish-speaking users, reaching an estimated 570,950 EU accounts. The malware uses a multi-stage dropper mechanism requiring victims to grant successive permissions (Accessibility, VPN, installation from unknown sources) before achieving near-complete device control including keystroke capture and remote manipulation. The campaign also leveraged TikTok and was analyzed by ThreatFabric, which did not attribute it to a named threat actor.
Full text
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control The Hacker NewsSep 02, 2026Malvertising / Mobile Security Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported. Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming. "There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem," ThreatFabric said in its StreamRat analysis. ThreatFabric did not attribute the campaign to a named threat actor. Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely. The campaign begins when the social-media lure directs an Android user to a specially crafted website. The site checks the visitor's operating system. It displays its download button to Android devices. The visitor can then download a file named app.apk. The victim launches the APK. The dropper asks to become the device's default Home application, which returns the victim to its interface whenever the Home button is pressed. Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself. The dropper's main page downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk. The dropper next asks for permission to install applications from unknown sources. After approval, it installs the payload through Android's package installation mechanism. StreamRat launches. The payload requests Accessibility access. After the user grants that permission, the malware connects to its command-and-control (C2) server. The VPN interface forwards no routed traffic, causing other applications to lose internet connectivity during installation. The dropper shuts down the VPN after the payload executes, allowing StreamRat to communicate with its C2 server. ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks. Google Play Protect retains offline detection for known potentially harmful applications, limiting the technique's effect on the service. For a visible screen capture, StreamRat invokes Android's MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator. The malware can use Accessibility to interact with the consent dialog after the victim has granted that permission. A second mode uses the Accessibility takeScreenshot() method to capture the screen outside the MediaProjection indicator. ThreatFabric said StreamRat was also promoted through TikTok. The report's TikTok-specific public evidence consisted of landing-page code that can identify TikTok as the referring application. It supplied no TikTok ad record or reach figure. The same banners were likely displayed on Facebook and Instagram, while the primary Meta placement remained undetermined. Applicability is tied to the installation behavior and the requested permissions, as no Android version range was published. The company shared the following indicators of compromise (IoCs) - SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Package - io.base.one887 Application - StrεαmTV Pro SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Package - io.meat.hint Application - Sistema de vídeo C2 IP - 45.147.28[.]59 C2 IP - 193.32.2[.]245 The Meta campaign began on June 11, 2026. It ended on July 3, 2026. The campaign was identified in late July 2026. The findings were published on September 2, 2026. The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign. The dropper closely resembled the one used in that operation. "The droppers are hosted using GitHub releases, with different backup links and daily package updates," Cleafy said in its Mirax report. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Android, malvertising, Malware, mobile security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control
Indicators of Compromise
- hash_sha256 — e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
- malware — StreamRat
- malware — update_{timestamp}.apk