BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

StreamRat Android Trojan Hits 570K Meta Users via Fake Ads

StreamRat Android trojan from fake TV-streaming Meta ads reaches 571K EU accounts via sideloaded APK.

  • Cybersecurity firm ThreatFabric uncovered a new Android banking trojan called StreamRat, spread via fake TV-streaming ads on Meta that reached nearly 571,000 EU accounts.
  • The malware requires victims to sideload an APK and grant multiple permissions, including Accessibility, enabling full device takeover and credential theft.
  • StreamRat’s dropper temporarily disables internet access via a VPN to evade analysis, then fetches the payload from GitHub, linking the campaign to the earlier Mirax operation.

Security researchers have disclosed details of a new Android banking trojan called StreamRat, promoted to Spanish-speaking users through a fake television-streaming campaign on Meta that reached an estimated 570,950 accounts in the European Union. ThreatFabric, which analyzed the malware, stated that “there is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem.”

- Advertisement -

Device takeover begins when a victim downloads a sideloaded APK from a specially crafted website after clicking a social-media ad. The dropper first requests to become the default Home application, then asks for VPN permission to route all traffic through a nonfunctional interface, cutting off internet for other apps. Once the victim grants Accessibility access, the malware connects to its command-and-control server and can capture keystrokes, display phishing overlays, and remotely control the device.

The campaign ran from June 11 to July 3, 2026, and was identified in late July. ThreatFabric also found evidence that StreamRat was promoted on TikTok, though no ad reach figures were provided. The payload originated from a GitHub account linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation. As detailed in Cleafy’s Mirax report, the droppers are hosted using GitHub releases with different backup links and daily package updates.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron stock all-time high talk grows pre Sept. 30 earnings

Micron shares trade near $980, over 20% below the June 2026 closing record of...

Pencil Finance completes $1M on-chain student loan cycle

Pencil Finance completed a $1 million student-loan cycle fully on-chain, from investor capital to...

Bitcoin Trades More Like Gold, Bolstering Digital Gold Case

Bitcoin's 90-day correlation with Gold climbed to its highest level since 2020, while its...

Orionx shuts after $7M custody loss, blames co-founders

Chilean crypto exchange Orionx is shutting down after a forensic audit discovered over $7...

MikroTik SSH exploit grants full admin control without auth

Attackers are exploiting a critical vulnerability in MikroTik RouterOS that grants full administrative control...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading