Cybersecurity experts have revealed a new Android malware known as StreamRat, which has been disseminated through a deceptive television-streaming promotion on Meta platforms, primarily targeting Spanish-speaking users. This banking trojan is engineered to grant near-total control over infected devices to its operators.
Malvertising Campaign Details
The fraudulent advertisement campaign by ThreatFabric was primarily aimed at Spanish-speaking Meta users, impacting approximately 570,950 accounts across the European Union. While exact figures for affected devices remain undisclosed, the campaign has raised significant security concerns.
The attack vector requires users to sideload an Android Package (APK) and approve a series of permissions that are unusual for a streaming application. These permissions ultimately allow the malware to take control of the device, highlighting the sophistication of the threat.
Technical Insights and Threat Analysis
Although ThreatFabric has not linked the operation to a specific threat actor, the malware’s capabilities are notable. By enabling Accessibility access, it can log keystrokes, display phishing overlays, and remotely manipulate the device interface.
The attack initiates when users are redirected via social media to a tailored website that verifies the operating system before offering a download link specific to Android devices. The downloaded file, app.apk, when executed, seeks permission to become the default Home app, complicating device navigation.
Payload Execution and Mitigation Strategies
Upon installation, the dropper requests VPN connection establishment, creating a facade while the StreamRat payload is discreetly downloaded and installed. This process results in temporary internet disconnection for other applications but does not affect the malware’s communication with its command-and-control server.
StreamRat’s techniques include leveraging Android’s MediaProjection API for screen captures, and it can bypass traditional detection methods. Google Play Protect provides some defenses against known threats, but the evolving nature of such malware necessitates additional vigilance.
The campaign, running from June 11 to July 3, 2026, was later identified in July, with findings published on September 2, 2026. The malware’s infrastructure was traced to a GitHub account, with links to previous campaigns, emphasizing the ongoing threat posed by such cyber operations.
As digital threats like StreamRat continue to evolve, staying informed and cautious about app permissions and downloads remains critical for device security. Follow us for more updates on cybersecurity developments and strategies to safeguard your digital assets.
