A malicious television-streaming ad campaign on social platforms has been used to distribute a new Android banking trojan dubbed StreamRat, giving threat actors near-complete control of compromised devices and potentially exposing European users to account takeover and data theft[1][2][3].
Researchers at ThreatFabric report that StreamRat was promoted to Spanish-speaking users via ads impersonating a free TV-streaming service, with one Meta campaign alone reaching about 570,000 accounts in the European Union between 11 June and 3 July 2026, primarily in Spain[1][2][4].
The attack chain starts when a victim taps the streaming-themed ad and is redirected to a phishing site that poses as a legitimate entertainment platform, where they are prompted to sideload an Android application package (APK) from outside the official Google Play Store[1][2].
Once installed, StreamRat runs a two-stage setup that aggressively requests permissions for Android Accessibility Services and MediaProjection, allowing operators to capture the device’s screen, read and interact with on-screen content, and effectively drive the phone as if they were the user sitting in front of it[2][7].
ThreatFabric’s technical analysis describes StreamRat as combining virtual network computing-like remote control, hidden-screen operation, UI-tree collection, keylogging, credential-stealing overlays, and the ability to block internet access or freeze the display, giving attackers a powerful toolkit to navigate banking and financial apps, intercept one-time passwords, and authorize fraudulent transactions[2][1][7].
Because StreamRat abuses legitimate system features rather than exploiting a specific software vulnerability, it is not associated with any published CVE entry, and there is no vendor patch that can simply be applied; instead, mitigation requires revoking the granted permissions, removing the malicious app, and, in severe cases, performing a factory reset[2][14][15].
ThreatFabric says it first spotted the campaign, internally labeled “Steamtv Esp,” while monitoring streaming-themed advertisers in late July 2026, and notes that similar lures were also observed on TikTok, broadening the reach beyond Meta’s platforms even as exact infection numbers and confirmed victim counts remain unknown[2][1][3].
Reporting from other security outlets has echoed concerns that StreamRat may be an evolution of tooling previously surfaced in Spanish-language operations, though no formal attribution has been made and researchers have not publicly tied it to a known threat group, underscoring how fast-moving criminal campaigns can weaponize mainstream ad networks against regional audiences[7][2].
For defenders, the StreamRat campaign reinforces the importance of restricting sideloading on managed Android devices, monitoring for suspicious use of Accessibility and screen-capture permissions, and educating users to treat unsolicited streaming or entertainment offers in social ads with caution, especially when they ask to install apps from unknown sources and grant broad system access[1][2].
References
- Meta Ads Push StreamRat Android Trojan That Can Gain …
- Uncovering StreamRat: From Meta Ads to Full Device …
- Post
- Security-Portal.cz | Bezpečnost • Hacking • Komunita
- CaveiraTech: Notícias de cybersecurity
- Vulnerability Metrics – NVD – NIST
- NVD
