Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Trending:
Galaxy S26•Pixel 10•Android 16•Nothing OS•Gemini AI•Smartwatches•Tech Deals•Latest Reviews•How-to Guides
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/New StreamRat Android banking trojan spreads via fake streaming ads
News

New StreamRat Android banking trojan spreads via fake streaming ads

Robert Haba
Sep 4, 20264 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
android-trojan
0%
Share on XFacebookBluesky
Follow on Google
Advertisement
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Key Takeaways

Automated Editorial Synthesis
AI Overview
  • SHA-256: e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
  • Application: StrεαmTV Pro
  • SHA-256: ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3

Cybersecurity researchers at ThreatFabric have disclosed a new Android banking trojan called StreamRat that was pushed to Spanish-speaking users through a fake television-streaming campaign on Meta and can hand its operators near-complete control of an infected device.

According to ThreatFabric, the campaign’s advertising focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, though the firm did not report totals for infected devices or confirmed victims. StreamRat was also promoted through TikTok, though the report’s TikTok-specific public evidence was limited to landing-page code capable of identifying TikTok as the referring application, with no TikTok ad record or reach figure supplied. ThreatFabric said the same banners were likely displayed on Facebook and Instagram as well, though the primary Meta placement itself remained undetermined.

Advertisement

The Meta campaign ran from June 11, 2026, to July 3, 2026, was identified in late July 2026, and ThreatFabric published its findings on September 2, 2026.

Source: Threatfabric.com

How the infection chain works

The campaign begins when a social-media lure directs an Android user to a specially crafted website that checks the visitor’s operating system and shows its download button only to Android devices. From there, the visitor can download a file named app.apk. Once the victim launches it, the dropper asks to become the device’s default Home application, so pressing the Home button returns the victim to its interface.

Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself, meaning other apps lose internet connectivity during installation. The dropper’s main page then downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk and asks for permission to install applications from unknown sources. After approval, it installs the payload through Android’s package installation mechanism, StreamRat launches, and the payload requests Accessibility access. Once the user grants that permission, the malware connects to its command-and-control (C2) server, and the dropper shuts down the VPN so StreamRat can communicate with it.

Advertisement

ThreatFabric assessed that the connectivity interruption may reduce online reputation and code-analysis checks during installation, though Google Play Protect retains offline detection for known potentially harmful applications, which limits the technique’s effect on the service. Users should stop the installation if a supposed streaming app requests system controls unrelated to streaming.

You May Also Like
Recommended
1

Huawei Kirin 9050 Pro chipset: full specs and what’s new

kirin 9050
2

The 5 biggest phone launches to watch in September 2026

semptember 2026 phones
3

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

What StreamRat can do once Accessibility is granted

Once Accessibility access is enabled, StreamRat’s operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely. For a visible screen capture, the malware invokes Android’s MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator; StreamRat can use Accessibility to interact with that consent dialog once the victim has granted the permission. A second capture mode uses the Accessibility takeScreenshot() method, letting the malware capture the screen without triggering the MediaProjection indicator.

Applicability is tied to StreamRat’s installation behavior and requested permissions, since ThreatFabric did not publish an affected Android version range.

Attribution and indicators of compromise

ThreatFabric did not attribute the campaign to a named threat actor, but wrote in its StreamRat analysis: “There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem.” The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation. Cleafy, in its own Mirax report, said: “The droppers are hosted using GitHub releases, with different backup links and daily package updates.”

Advertisement

ThreatFabric shared the following indicators of compromise:

  • SHA-256: e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
  • Package: io.base.one887
  • Application: StrεαmTV Pro
  • SHA-256: ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3
  • Package: io.meat.hint
  • Application: Sistema de vídeo
  • C2 IP: 45.147.28[.]59
  • C2 IP: 193.32.2[.]245
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#ads#android#android security#fake#malware#meta#streaming#trojan
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
Google Pixel Watch 4

Google Pixel Watch 4

4.8
396.00$499.99-21%
Buy on Amazon
💎Best Android Device
Samsung Galaxy S26 Ultra

Samsung Galaxy S26 Ultra

4.9
$1,212.85$1,499.99-19%
Buy on Amazon
✨DEAL!
Samsung Galaxy Watch Ultra (2025)

Samsung Galaxy Watch Ultra (2025)

5.0
$449.99$649.99-31%
Buy on Amazon
👑A good choice
Apple iPhone 17 Pro

Apple iPhone 17 Pro

4.8
$1,012.97$1,099.00-8%
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Advertisement

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Advertisement

Latest Stories

honor magicos 11
01

Honor MagicOS 11 debuts September 15 with Glazed Architecture, faster YOYO

02

OnePlus 16 reservations open in China, revealing design and colors ahead of launch

03

Honor MagicOS 11 to debut with hidden Power Saving Suggestions feature

04

Galaxy Watch 4 and Watch 4 Classic reach end of software support

Advertisement
Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Advertisement
Advertisement
Recommended stories

Continue reading

More from this category →
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
semptember 2026 phones
NewsSep 8, 2026

The 5 biggest phone launches to watch in September 2026

September is usually iPhone season, but this year several Android brands are packing their very best hardware into the same four-week stretch, aiming to steal some of the spotlight. More than 20 phones are expected to launch this month alone, and here's a rundown of five of the biggest phone launches on the calendar for […]

By Luiza Mosneagu
NewsSep 4, 2026

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

Google's Scam Detection feature could be coming to Xiaomi phones next, according to a new APK teardown by Android Authority. The AI-powered scam-call warning tool debuted first on Pixel devices, has since expanded to Samsung's Galaxy S26 series, and has shown signs of heading to vivo phones as well, and Android Authority now says it's […]

By Robert Haba
Android memory shortage
NewsSep 2, 2026

Google sets new Android RAM rules for app developers amid memory shortage

Google has introduced new Android RAM rules for app developers, tightening memory-management requirements as a global RAM shortage continues to squeeze the smartphone industry. Developers have until February 2027 to make their apps use RAM more efficiently, an effort meant to keep apps running smoothly even on phones with limited memory. Under the updated guidelines, […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.