Malicious social-media advertisements impersonating a free TV streaming service distributed the StreamRat Android banking trojan to Spanish-speaking users in Spain. A Meta advertising campaign active from June 11 to July 3 reportedly reached about 570,000 users; this represents potential exposure rather than confirmed infections. Victims were lured through a staged sideloading process that installed a dropper, persuaded them to set it as the default launcher, and requested high-risk Accessibility permissions before downloading the primary payload.
StreamRat abuses Android Accessibility Services, screen capture, and remote-touch capabilities to monitor screens, log keystrokes, capture screenshots, inventory installed apps, and take control of infected devices. It can deploy credential-stealing overlays and hide malicious actions behind black-screen or fake-update displays. The dropper may also request VPN access to temporarily disrupt other applications' internet connectivity while preserving its own connection to retrieve the payload, potentially limiting cloud-based security checks during installation.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
A malicious-advertising campaign promoting a purported free streaming service targeted Spanish-speaking Android users in Spain and reached approximately 570,000 Meta users. The reach figure covered June 11 through July 3, 2026, and does not represent confirmed infections.
Researchers documented that StreamRat uses a sideloaded dropper, default-home-screen abuse, Accessibility permissions, screen capture, phishing overlays, and remote touch actions to control Android devices. They also identified VPN-related behavior that can temporarily disrupt other applications' connectivity while the dropper downloads the payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.