A recent discovery has unveiled a malicious campaign targeting Android users through a fraudulent streaming app. Promoted through social media ads, this app, known as StreamRat, was designed not to provide entertainment but to gain control over users’ devices.
Targeted Attack on Spanish-Speaking Users
This deceptive campaign specifically targeted Spanish-speaking individuals in Spain. Between June 11 and July 3, 2026, advertisements reached approximately 570,000 users on Meta platforms. While this number indicates the potential reach of the ads, it does not necessarily reflect the number of infections.
The campaign bears similarities to previous malware operations involving fake streaming apps, such as those distributing the TrickMo Android banking malware. Security analysts at Zimperium highlighted the use of social media ads and a multi-step installation process in their observations.
How StreamRat Exploits Devices
StreamRat poses significant risks by capturing passwords, viewing screens, and allowing remote control of infected phones. This capability extends beyond merely stealing login credentials, as attackers can access banking apps, messages, and other sensitive accounts.
Despite the large audience of the ad campaign, researchers have not confirmed the number of infected devices or successful attacks. This distinction is crucial to avoid confusion between ad reach and actual victim count.
The Deceptive Installation Process
The campaign begins with ads promoting a free TV service, directing users to a website that checks for Android devices. If detected, it provides tailored installation instructions, encouraging users to install the app outside of the typical app store and enable Accessibility features.
Android’s permission system is manipulated similarly to how banking trojans use overlays, allowing convincing fake login pages to appear over legitimate applications. The initial malicious app attempts to become the default home screen, guiding users back to its instructions and installing the main trojan.
Once Accessibility access is granted, StreamRat can observe screen activity, record inputs, and execute taps or swipes. It also tracks installed apps, helping attackers decide when to display fake banking logins or request further information.
Mitigation and Prevention Measures
StreamRat can obscure screen activity with black screens or fake system updates while continuing operations in the background. This can lead to unauthorized account activities through phishing login pages.
Before the complete malware installation, the dropper may request VPN access, potentially interfering with cloud-based security checks. While the connection loss during installation warrants investigation, it does not disable all protections.
The campaign’s delivery method may evolve, but the critical point remains when users install untrusted apps and grant them extensive permissions. Users should be cautious of apps promoted via social media ads or unknown websites, particularly those requesting Accessibility or VPN access.
Organizations should monitor devices for unexpected permission changes or installations from unapproved sources. Recognizing these signs can prevent potential security breaches.
