ThreatFabric identified StreamRat, a new Android banking trojan targeting Spanish-speaking users through fraudulent free television-streaming advertisements on Meta platforms and reportedly TikTok. The campaign used a sideloaded APK dropper that pressured victims to grant default Home-app, VPN, unknown-source installation, and Android Accessibility permissions before deploying the final payload. Meta advertisements active from June 11 to July 3 reportedly reached about 570,950 EU accounts, although no confirmed infections or victims were reported.
After Accessibility access is enabled, StreamRat can conduct credential theft through overlays and keylogging, collect UI-tree data, view or capture screens, and remotely operate compromised devices using VNC and hidden-screen control. It also abuses Android MediaProjection and can lock the device or block internet access, enabling operators to take extensive control while obscuring activity from victims. Researchers found infrastructure links to the earlier Mirax campaign but did not attribute StreamRat to a named threat actor.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric published findings on StreamRat, describing a sideloaded two-stage installer that seeks Home-app, VPN, unknown-source installation, and Accessibility permissions. The final payload can use overlays, keylogging, UI inspection, screen capture, and remote-control functions to take near-complete control of compromised Android devices.
The Meta advertising campaign ended after reaching an estimated 570,950 European Union Meta accounts at least once. Confirmed infections or victim counts were not reported.
ThreatFabric identified the StreamRat campaign in late July 2026. Researchers found delivery-infrastructure and dropper-code links to an earlier Mirax campaign, but did not attribute StreamRat to a named actor.
A fraudulent television-streaming advertising campaign distributing the StreamRat Android banking trojan began targeting Spanish-speaking users on Meta platforms.
Researchers observed the same fraudulent streaming-service advertising banners used to distribute StreamRat through TikTok, in addition to the Meta-platform campaign. The TikTok lures directed Android users toward the device-aware fraudulent site and sideloaded APK.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemkd-cirt.mk
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.