VMTech
Discuss a project

StreamRat Android Trojan Used in Meta Streaming-Ad Campaign

StreamRat Android Trojan Used in Meta Streaming-Ad Campaign

ThreatFabric has detailed StreamRat, an Android banking trojan delivered through a fake streaming-service campaign on Meta that targeted Spanish-speaking users. The advertisements ran from June 11 to July 3, 2026, and reached an estimated 570,950 Meta accounts in the European Union at least once. The researchers did not report totals for infected devices or confirmed victims.

The campaign directed Android users to a crafted website that checked the visitor’s operating system and exposed a download button only on Android. The downloaded file, named app.apk, was a dropper rather than the final StreamRat payload. ThreatFabric said the same banners were likely shown on Facebook and Instagram, although the primary Meta placement was not determined.

A staged installation path

After launch, the dropper asks to become the device’s default Home application, causing the victim to return to its interface when pressing the Home button. It then requests permission to establish a VPN connection before downloading the final payload into the public Downloads directory as update_{timestamp}.apk.

The dropper next requests permission to install applications from unknown sources and installs the payload through Android’s package installation mechanism. StreamRat then asks for Accessibility access. Once that permission is granted, the malware connects to its command-and-control server.

The VPN interface routes no traffic other than the dropper’s, temporarily leaving other applications without internet access during installation. ThreatFabric assessed that this interruption may reduce online reputation and code-analysis checks. Google Play Protect still provides offline detection for known potentially harmful applications, limiting the technique’s effect on that service.

Accessibility enables device control

With Accessibility enabled, StreamRat operators can capture keystrokes, place credential-stealing overlays, inspect the visible interface and remotely control the device. For visible screen capture, the malware can invoke Android’s MediaProjection API, which normally displays a consent dialog and a screen-sharing indicator. Accessibility can be used to interact with that dialog after access has been granted.

A second screen-capture mode uses the Accessibility takeScreenshot() method, outside the MediaProjection indicator. ThreatFabric also found evidence that StreamRat was promoted through TikTok: landing-page code could identify TikTok as the referring application, but the report included no TikTok advertising record or reach figure.

Links to earlier tooling

ThreatFabric linked the GitHub account serving the StreamRat payload to an earlier Mirax campaign, and said the dropper closely resembled one used in that operation. Cleafy reported that Mirax droppers were hosted in GitHub releases with backup links and daily package updates. ThreatFabric did not attribute StreamRat to a named threat actor.

For businesses, the immediate lesson is to limit sideloading through device-management policy and train users to stop an installation when a streaming app asks for default Home, VPN, unknown-source installation or Accessibility permissions unrelated to its stated function.

#androidsecurity#malvertising#mobilemalware#cybersecurity
Open analytics
On the site 0 views
min read 4 02.09.2026
Instagram

StreamRat Android Trojan Used in Meta Streaming-Ad Campaign

Open the post on Instagram ↗