StreamRAT is an Android banking trojan and information stealer distributed through fraudulent free television-streaming advertisements aimed primarily at Spanish-speaking users, particularly in Spain. The campaign uses social-media malvertising and a device-aware fake streaming landing page that directs Android users to sideload a multi-stage application and grant high-risk permissions, including Accessibility Services. Its initial dropper attempts to become the default Home application, installs the final payload, and can temporarily disrupt other applications’ network access through a nonfunctional VPN configuration during installation.
After Accessibility access is granted, StreamRAT provides operators with extensive remote control of compromised devices. It can capture typed input, monitor foreground applications and on-screen interface content, enumerate installed applications, collect Accessibility UI-tree data, and capture screens using both visible screen-sharing functionality and hidden Accessibility-based screenshots. The trojan uses phishing overlays matching targeted applications to steal credentials and can deploy black-screen, fake-update, and other interactive overlays to conceal operator activity and block victim input. Operators can perform taps, swipes, navigation actions, application launches, screen locking, and device-unlocking actions. StreamRAT communicates through a WebSocket-based command-and-control protocol and avoids sending duplicate screen and interface data.
The malware’s administration panel, payload and dropper builders, and role-based operator management are consistent with a malware-as-a-service design. StreamRAT delivery infrastructure and its dropper share technical links with the earlier Mirax Android campaign, but it has not been publicly attributed to a named threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
“The ad led victims to a website posing as a streaming platform... Android users were shown an app download option.”
It can... capture information typed into apps [and] show convincing fake screens to steal usernames and passwords.
In parallel, the trojan captures data entered by the victim and continuously monitors which application is currently displayed on the device screen.
“[StreamRat] can... capture information typed into apps [and] show convincing fake screens to steal usernames and passwords.”
At the beginning of the communication flow, the bot sends... X-Device-Id... X-Device-Model... [and] X-Api-Level. The panel shows device manufacturer and model, region, battery level, Android version/API level.
It can... capture information typed into apps [and] show convincing fake screens to steal usernames and passwords.
In parallel, the trojan captures data entered by the victim and continuously monitors which application is currently displayed on the device screen.
“[StreamRat] can... capture information typed into apps [and] show convincing fake screens to steal usernames and passwords.”
“An operator can monitor the app a victim opens, deliver a matching fake page, collect details entered there.”
“Before downloading the final malware, the dropper can create a deliberately broken VPN connection that disrupts internet access while excluding itself.”
VPN интерфејсот не проследува никаков рутиран сообраќај, поради што другите апликации го губат пристапот до интернет за време на инсталацијата... прекинот на интернет-конекцијата може да го намали бројот на онлајн проверки поврзани со репутацијата и анализата на кодот.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison for mobile screen-viewing and device-manipulation capabilities.
Mentioned only as a comparison for screen-viewing and remote phone-manipulation capabilities.
Android banking trojan, infostealer, and remote-access malware distributed via fake streaming-service advertisements on Meta and TikTok. It monitors screens, captures typed input, overlays phishing screens to steal credentials, and permits remote device control. It can also display black-screen or fake Android-update overlays to conceal attacker activity.
Android banking trojan and infostealer distributed through malicious Meta and TikTok advertisements masquerading as a free TV-streaming service. It monitors screens, captures typed data, overlays credential-phishing screens, and enables remote control; it can also display black screens or fake Android-update screens to conceal attacker activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.