BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

StreamRat Android trojan from fake TV-streaming Meta ads reaches 571K EU accounts via sideloaded APK.

  • Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake TV-streaming ads on Meta that reached nearly 571,000 EU accounts.
  • The malware requires victims to sideload an APK and grant multiple permissions, including Accessibility, enabling full device takeover and credential theft.
  • StreamRat’s dropper temporarily disables internet access via a VPN to evade analysis, then fetches the payload from GitHub, linking the campaign to the earlier Mirax operation.

Security researchers have disclosed details of a new Android banking trojan called StreamRat, promoted to Spanish-speaking users through a fake television-streaming campaign on Meta that reached an estimated 570,950 accounts in the European Union. ThreatFabric, which analyzed the malware, stated that “there is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem.”

- Advertisement -

Device takeover begins when a victim downloads a sideloaded APK from a specially crafted website after clicking a social-media ad. The dropper first requests to become the default Home application, then asks for VPN permission to route all traffic through a nonfunctional interface, cutting off internet for other apps. Once the victim grants Accessibility access, the malware connects to its command-and-control server and can capture keystrokes, display phishing overlays, and remotely control the device.

The campaign ran from June 11 to July 3, 2026, and was identified in late July. ThreatFabric also found evidence that StreamRat was promoted on TikTok, though no ad reach figures were provided. The payload originated from a GitHub account linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation. As detailed in Cleafy’s Mirax report, the droppers are hosted using GitHub releases with different backup links and daily package updates.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

UN Security Council to Hear AI CEOs on Risks Before Trump-Xi Meet

Anthropic, OpenAI, DeepSeek, and Moonshot will brief the UN Security Council on AI risks...

OpenAI launches cheaper GPT-6 Sol and Luna for coding and work tasks

OpenAI launched GPT-6 Sol at $2 per million input tokens and $10 per million...

Kalshi bot stops uniform trades amid wash trade claims

A trading bot repeatedly buying and selling $1 contracts on Kalshi's Zohran Mamdani prediction...

Six Canadian banks explore tokenized CAD deposits

Canada’s six largest banks jointly explore tokenized Canadian dollar deposits to enable digital bank...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of...

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading