StreamRat is an Android banking trojan targeting Spanish-speaking users, particularly users in Spain, through fraudulent free television-streaming advertisements on Meta platforms and TikTok. The infection chain uses a sideloaded dropper that guides victims to enable installation from unknown sources, installs the final payload, and solicits Android Accessibility Services permissions. The dropper can also request default Home application status and establish a temporary nonfunctional VPN connection that disrupts other applications’ network access during installation, an apparent effort to hinder cloud-based reputation and analysis checks.
After Accessibility access is granted, StreamRat establishes command-and-control communications and provides operators with extensive device surveillance and remote-control functions. It monitors foreground applications, inventories installed applications, captures keystrokes, collects Accessibility UI-tree content, and captures screens using both MediaProjection-based streaming and Accessibility screenshot functionality. It supports credential-harvesting overlays, including automated HTML injections and operator-controlled black-screen, fake-update, custom, and interactive overlays. Operators can perform taps, swipes, global navigation actions, launch applications, lock or unlock devices, issue shell commands, display fake notifications, and use anti-uninstall controls. Technical links connect its delivery infrastructure and dropper design to earlier Mirax activity, though no named threat actor attribution has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
In parallel, the trojan captures data entered by the victim and continuously monitors which application is currently displayed on the device screen.
Injection overlay... [is] implemented using a WebView with a JavaScript interface. Data entered into the overlay is passed to the Android code and subsequently sent to the C2 server.
The bot sends a GET request to the C2 server in order to upgrade the connection to WebSocket... The RPC-like protocol is built on top of a WebSocket connection.
The dropper requests permission to create a VPN connection... routes all device traffic through it, while explicitly excluding the dropper itself... no traffic processing takes place... [then] turned off the VPN connection, so the payload could communicate with [the] control server.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan and remote-access tool delivered through fake streaming-app APKs. It abuses Accessibility permissions to capture keystrokes, conduct overlay-based credential theft, inspect and capture the screen, and remotely control infected devices. Its dropper also requests default Home-app, VPN, and unknown-source installation permissions to disrupt connectivity during installation and deploy the final payload.
Android banking trojan that uses a two-stage installation and abuses Accessibility Services and MediaProjection to give operators near-complete device control. Its capabilities include VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and internet and screen blocking.
Android banking trojan and apparent Malware-as-a-Service offering that uses Accessibility Services and MediaProjection to provide remote device control. It supports visible VNC and hidden-screen (HVNC) capture, UI-tree collection, keylogging, credential-stealing HTML overlays, application enumeration, fake notifications, device unlocking using intercepted PINs or patterns, screen blocking, and remote Accessibility-based actions. Its dropper temporarily blocks device Internet traffic with a non-functional VPN while fetching and installing the payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.