StreamRat Android Trojan Spread via Meta Ads Targets Users
A new Android banking trojan named StreamRat has been uncovered by cybersecurity researchers, who revealed that it was promoted to Spanish-speaking users through a fake streaming campaign on Meta. The advertising campaign focused on Spain and reached an estimated 570,950 Meta accounts within the European Union, according to ThreatFabric. While no data has been disclosed regarding infected devices or confirmed victims, the report highlighted the technical sophistication of the malware, attributing it to developers with prior experience in the Android malware ecosystem.
StreamRat operates through a sequence of permission requests following the installation of the APK file. The attack begins when a user is directed to a specially crafted website that checks the operating system and offers a download only to Android devices. The downloaded APK acts as a 'dropper' that requests to become the default home application, establishes a non-functional VPN connection, and ultimately installs the main payload. Once installed, StreamRat requests Accessibility access, enabling it to capture keystrokes, display fake credential-stealing overlays, and remotely control the device. It also leverages the MediaProjection API or the takeScreenshot() method to capture the screen, even outside the visibility indicator.
ThreatFabric did not attribute the campaign to a specific threat actor, but noted that the trojan's code originates from a GitHub account linked to an earlier campaign known as Mirax. The dropper used in StreamRat closely resembles the one employed in that operation, including the use of GitHub Releases to host files with backup links and daily updates. While the main campaign ran from June 11 to July 3, 2026, a presence on TikTok was also detected, though without quantitative reach data. The ad banners were likely displayed on Facebook and Instagram as well.
The threat represents a significant evolution in mobile malware, particularly due to its use of social media ads as an attack vector and its ability to manipulate OS-level permissions. The temporary traffic disruption via VPN may be designed to evade real-time detection, though Google Play Protect retains offline scanning for known potentially harmful applications. To mitigate risk, users should avoid installing APKs from unofficial sources and immediately halt any app requesting system permissions unrelated to its advertised function. This incident underscores the growing sophistication of mobile attackers and the need for greater awareness about the dangers of sideloading software outside official app stores.