BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

StreamRat Android trojan from fake TV-streaming Meta ads reaches 571K EU accounts via sideloaded APK.

  • Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake TV-streaming ads on Meta that reached nearly 571,000 EU accounts.
  • The malware requires victims to sideload an APK and grant multiple permissions, including Accessibility, enabling full device takeover and credential theft.
  • StreamRat’s dropper temporarily disables internet access via a VPN to evade analysis, then fetches the payload from GitHub, linking the campaign to the earlier Mirax operation.

Security researchers have disclosed details of a new Android banking trojan called StreamRat, promoted to Spanish-speaking users through a fake television-streaming campaign on Meta that reached an estimated 570,950 accounts in the European Union. ThreatFabric, which analyzed the malware, stated that “there is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem.”

- Advertisement -

Device takeover begins when a victim downloads a sideloaded APK from a specially crafted website after clicking a social-media ad. The dropper first requests to become the default Home application, then asks for VPN permission to route all traffic through a nonfunctional interface, cutting off internet for other apps. Once the victim grants Accessibility access, the malware connects to its command-and-control server and can capture keystrokes, display phishing overlays, and remotely control the device.

The campaign ran from June 11 to July 3, 2026, and was identified in late July. ThreatFabric also found evidence that StreamRat was promoted on TikTok, though no ad reach figures were provided. The payload originated from a GitHub account linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation. As detailed in Cleafy’s Mirax report, the droppers are hosted using GitHub releases with different backup links and daily package updates.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump $1 coin enters circulation, on sale today

The U.S. Mint has released a commemorative 2026 $1 coin featuring President Donald Trump,...

Norway plans smart glasses crackdown, facial recognition ban

Norway plans to regulate smart glasses more strictly and may ban facial recognition in...

Morgan Stanley Warns Limited Cybercabs May Hurt Tesla Shares

Morgan Stanley reiterated an 'Equal Weight' rating and $400 price target on Tesla, implying...

NYDFS tells X Money to halt interest payments to New Yorkers

NYDFS told X Money it cannot pay bank-like interest on non-bank deposits for New...

Remixpoint sells $5.5M altcoins, nets $736K gain to focus on Bitcoin

Remixpoint sold its entire holdings of ETH, SOL, XRP, and DOGE for approximately $5.5...

Must Read

Sushiswap vs Uniswap, What are the differences between these dex?

It's no secret that the world of decentralized exchanges has exploded in recent years. Many of you are probably wondering what the difference is...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading