Cybersecurity researchers at ThreatFabric have disclosed a new Android banking trojan called StreamRat that was pushed to Spanish-speaking users through a fake television-streaming campaign on Meta and can hand its operators near-complete control of an infected device.
According to ThreatFabric, the campaign’s advertising focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, though the firm did not report totals for infected devices or confirmed victims. StreamRat was also promoted through TikTok, though the report’s TikTok-specific public evidence was limited to landing-page code capable of identifying TikTok as the referring application, with no TikTok ad record or reach figure supplied. ThreatFabric said the same banners were likely displayed on Facebook and Instagram as well, though the primary Meta placement itself remained undetermined.
The Meta campaign ran from June 11, 2026, to July 3, 2026, was identified in late July 2026, and ThreatFabric published its findings on September 2, 2026.

How the infection chain works
The campaign begins when a social-media lure directs an Android user to a specially crafted website that checks the visitor’s operating system and shows its download button only to Android devices. From there, the visitor can download a file named app.apk. Once the victim launches it, the dropper asks to become the device’s default Home application, so pressing the Home button returns the victim to its interface.
Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself, meaning other apps lose internet connectivity during installation. The dropper’s main page then downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk and asks for permission to install applications from unknown sources. After approval, it installs the payload through Android’s package installation mechanism, StreamRat launches, and the payload requests Accessibility access. Once the user grants that permission, the malware connects to its command-and-control (C2) server, and the dropper shuts down the VPN so StreamRat can communicate with it.
ThreatFabric assessed that the connectivity interruption may reduce online reputation and code-analysis checks during installation, though Google Play Protect retains offline detection for known potentially harmful applications, which limits the technique’s effect on the service. Users should stop the installation if a supposed streaming app requests system controls unrelated to streaming.
What StreamRat can do once Accessibility is granted
Once Accessibility access is enabled, StreamRat’s operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely. For a visible screen capture, the malware invokes Android’s MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator; StreamRat can use Accessibility to interact with that consent dialog once the victim has granted the permission. A second capture mode uses the Accessibility takeScreenshot() method, letting the malware capture the screen without triggering the MediaProjection indicator.
Applicability is tied to StreamRat’s installation behavior and requested permissions, since ThreatFabric did not publish an affected Android version range.
Attribution and indicators of compromise
ThreatFabric did not attribute the campaign to a named threat actor, but wrote in its StreamRat analysis: “There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem.” The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation. Cleafy, in its own Mirax report, said: “The droppers are hosted using GitHub releases, with different backup links and daily package updates.”
ThreatFabric shared the following indicators of compromise:
- SHA-256: e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
- Package: io.base.one887
- Application: StrεαmTV Pro
- SHA-256: ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3
- Package: io.meat.hint
- Application: Sistema de vídeo
- C2 IP: 45.147.28[.]59
- C2 IP: 193.32.2[.]245

Google Pixel Watch 5 (45mm)

Samsung Galaxy Watch 8
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.










Comments & Discussions
Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.